Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
duschno.exe

Overview

General Information

Sample name:duschno.exe
Analysis ID:1574589
MD5:c6813da66eba357d0deaa48c2f7032b8
SHA1:6812e46c51f823ff0b0ee17bfce0af72f857af66
SHA256:1420f60f053c3ea5605239ee431e5f487245108b1c01be75d16b5246156fa178
Tags:exeuser-lontze7
Infos:

Detection

CredGrabber, Meduza Stealer
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected CredGrabber
Yara detected Meduza Stealer
AI detected suspicious sample
Found many strings related to Crypto-Wallets (likely being stolen)
Machine Learning detection for sample
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to record screenshots
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found evasive API chain checking for process token information
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
Queries the volume information (name, serial number etc) of a device
Queries time zone information
Terminates after testing mutex exists (may check infected machine status)
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • duschno.exe (PID: 6856 cmdline: "C:\Users\user\Desktop\duschno.exe" MD5: C6813DA66EBA357D0DEAA48C2F7032B8)
  • cleanup
{"C2 url": "193.3.19.151", "grabber_max_size": 4194304, "anti_vm": true, "anti_dbg": true, "self_destruct": false, "extensions": ".txt", "build_name": "hdont", "links": "", "port": 15666}
SourceRuleDescriptionAuthorStrings
duschno.exeJoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
    SourceRuleDescriptionAuthorStrings
    00000000.00000002.2420918904.000001F3F07AC000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
      Process Memory Space: duschno.exe PID: 6856JoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
        Process Memory Space: duschno.exe PID: 6856JoeSecurity_CredGrabberYara detected CredGrabberJoe Security
          SourceRuleDescriptionAuthorStrings
          0.2.duschno.exe.7ff6b5320000.0.unpackJoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
            0.0.duschno.exe.7ff6b5320000.0.unpackJoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
              No Sigma rule has matched
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2024-12-13T12:41:07.303709+010020494411A Network Trojan was detected192.168.2.1249711193.3.19.15115666TCP

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: duschno.exeMalware Configuration Extractor: Meduza Stealer {"C2 url": "193.3.19.151", "grabber_max_size": 4194304, "anti_vm": true, "anti_dbg": true, "self_destruct": false, "extensions": ".txt", "build_name": "hdont", "links": "", "port": 15666}
              Source: duschno.exeReversingLabs: Detection: 63%
              Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.7% probability
              Source: duschno.exeJoe Sandbox ML: detected
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5397BA0 CryptUnprotectData,LocalFree,0_2_00007FF6B5397BA0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5398440 BCryptOpenAlgorithmProvider,BCryptSetProperty,BCryptGenerateSymmetricKey,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,Concurrency::cancel_current_task,0_2_00007FF6B5398440
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53983C0 BCryptCloseAlgorithmProvider,_invalid_parameter_noinfo_noreturn,0_2_00007FF6B53983C0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5397EC0 CryptProtectData,LocalFree,0_2_00007FF6B5397EC0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5398020 BCryptDecrypt,BCryptDecrypt,_invalid_parameter_noinfo_noreturn,0_2_00007FF6B5398020
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5353A30 BCryptDestroyKey,0_2_00007FF6B5353A30
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5357C20 CryptUnprotectData,LocalFree,_invalid_parameter_noinfo_noreturn,0_2_00007FF6B5357C20
              Source: unknownHTTPS traffic detected: 172.67.74.152:443 -> 192.168.2.12:49712 version: TLS 1.2
              Source: duschno.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53DB5B0 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,__std_fs_open_handle,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,CloseHandle,CloseHandle,0_2_00007FF6B53DB5B0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53DB500 FindClose,FindFirstFileExW,GetLastError,0_2_00007FF6B53DB500
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53A73F0 GetLogicalDriveStringsW,_invalid_parameter_noinfo_noreturn,0_2_00007FF6B53A73F0
              Source: C:\Users\user\Desktop\duschno.exeFile opened: D:\sources\migration\Jump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: D:\sources\replacementmanifests\Jump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: D:\sources\migration\wtr\Jump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: D:\sources\replacementmanifests\microsoft-activedirectory-webservices\Jump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: D:\sources\replacementmanifests\microsoft-client-license-platform-service-migration\Jump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: D:\sources\replacementmanifests\hwvid-migration-2\Jump to behavior

              Networking

              barindex
              Source: Network trafficSuricata IDS: 2049441 - Severity 1 - ET MALWARE Win32/Unknown Grabber Base64 Data Exfiltration Attempt : 192.168.2.12:49711 -> 193.3.19.151:15666
              Source: global trafficTCP traffic: 192.168.2.12:49711 -> 193.3.19.151:15666
              Source: global trafficHTTP traffic detected: GET / HTTP/1.1Accept: text/html; text/plain; */*Host: api.ipify.orgCache-Control: no-cache
              Source: Joe Sandbox ViewIP Address: 193.3.19.151 193.3.19.151
              Source: Joe Sandbox ViewIP Address: 172.67.74.152 172.67.74.152
              Source: Joe Sandbox ViewIP Address: 172.67.74.152 172.67.74.152
              Source: Joe Sandbox ViewASN Name: ARNES-NETAcademicandResearchNetworkofSloveniaSI ARNES-NETAcademicandResearchNetworkofSloveniaSI
              Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
              Source: unknownDNS query: name: api.ipify.org
              Source: unknownDNS query: name: api.ipify.org
              Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
              Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
              Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
              Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
              Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53A5240 InternetOpenA,InternetOpenUrlA,HttpQueryInfoW,HttpQueryInfoW,InternetQueryDataAvailable,InternetReadFile,InternetQueryDataAvailable,InternetCloseHandle,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,Concurrency::cancel_current_task,0_2_00007FF6B53A5240
              Source: global trafficHTTP traffic detected: GET / HTTP/1.1Accept: text/html; text/plain; */*Host: api.ipify.orgCache-Control: no-cache
              Source: global trafficDNS traffic detected: DNS query: api.ipify.org
              Source: duschno.exe, 00000000.00000003.2420291452.000001F3F3040000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420399094.000001F3F3045000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2353152740.000001F3F3031000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420324106.000001F3F3044000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ns.a.0/sTy
              Source: duschno.exe, 00000000.00000003.2420291452.000001F3F3040000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420399094.000001F3F3045000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2353152740.000001F3F3031000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420324106.000001F3F3044000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ns.adobe.c.0/ti
              Source: duschno.exe, 00000000.00000003.2420291452.000001F3F3040000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420399094.000001F3F3045000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2353152740.000001F3F3031000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420324106.000001F3F3044000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ns.adobe.hotosh
              Source: duschno.exe, 00000000.00000003.2420291452.000001F3F3040000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420399094.000001F3F3045000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2353152740.000001F3F3031000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420324106.000001F3F3044000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ns.adoraw-se
              Source: duschno.exe, 00000000.00000003.2420291452.000001F3F3040000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420399094.000001F3F3045000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2353152740.000001F3F3031000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420324106.000001F3F3044000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ns.photo/
              Source: duschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
              Source: duschno.exe, 00000000.00000002.2420918904.000001F3F07AC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.org/
              Source: duschno.exe, 00000000.00000002.2420918904.000001F3F07AC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.org/a
              Source: duschno.exe, 00000000.00000003.2381064141.000001F3F33BC000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380320290.000001F3F32D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696506299400400001.2&ci=1696506299033.
              Source: duschno.exe, 00000000.00000003.2380962493.000001F3F33E5000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2381237342.000001F3F3285000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380817799.000001F3F3281000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2381064141.000001F3F33BC000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380320290.000001F3F32D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bridge.sfo1.ap01.net/ctp?version=16.0.0&key=1696506299400400001.1&ci=1696506299033.12791&cta
              Source: duschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
              Source: duschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
              Source: duschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
              Source: duschno.exe, 00000000.00000003.2381064141.000001F3F33BC000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380320290.000001F3F32D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://contile-images.services.mozilla.com/CuERQnIs4CzqjKBh9os6_h9d4CUDCHO3oiqmAQO6VLM.25122.jpg
              Source: duschno.exe, 00000000.00000003.2381064141.000001F3F33BC000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380320290.000001F3F32D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg
              Source: duschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/ac/?q=
              Source: duschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/chrome_newtab
              Source: duschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
              Source: duschno.exe, 00000000.00000003.2380320290.000001F3F32D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4CbmfQq%2B4pbW4pbWfpbX7ReNxR3UIG8zInwYIFIVs9e
              Source: duschno.exe, 00000000.00000003.2376253271.000001F3F360C000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379802179.000001F3F2436000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380020573.000001F3F2570000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2374619093.000001F3F26C6000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380020573.000001F3F2578000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380320290.000001F3F32D5000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379802179.000001F3F243E000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379802179.000001F3F2463000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379475898.000001F3F25D8000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379802179.000001F3F245B000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379475898.000001F3F25D0000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2374619093.000001F3F26BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org
              Source: duschno.exe, 00000000.00000003.2379802179.000001F3F246B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
              Source: duschno.exe, 00000000.00000003.2379802179.000001F3F246B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/products/firefoxgro.allizom.troppus.P9ZDdyXKOWl2
              Source: duschno.exe, 00000000.00000003.2380962493.000001F3F33E5000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2381237342.000001F3F3285000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380817799.000001F3F3281000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2381064141.000001F3F33BC000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380320290.000001F3F32D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_cd61a4703a8613be887576f2bd084bcc6f4756dccdbe5062
              Source: duschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ecosia.org/newtab/
              Source: duschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
              Source: duschno.exe, 00000000.00000003.2381064141.000001F3F33BC000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380320290.000001F3F32D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.invisalign.com/?utm_source=admarketplace&utm_medium=paidsearch&utm_campaign=Invisalign&u
              Source: duschno.exe, 00000000.00000003.2376253271.000001F3F360C000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379802179.000001F3F2436000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380020573.000001F3F2570000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2374619093.000001F3F26C6000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380020573.000001F3F2578000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380320290.000001F3F32D5000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379802179.000001F3F243E000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379802179.000001F3F2463000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379475898.000001F3F25D8000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379802179.000001F3F245B000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379475898.000001F3F25D0000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2374619093.000001F3F26BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org
              Source: duschno.exe, 00000000.00000003.2379802179.000001F3F246B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.5iSPD7jwkDnW
              Source: duschno.exe, 00000000.00000003.2379802179.000001F3F246B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.3UfcDFx2ZSAZ
              Source: duschno.exe, 00000000.00000003.2379802179.000001F3F246B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig
              Source: duschno.exe, 00000000.00000003.2374619093.000001F3F26CE000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2378121440.000001F3F3C86000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379802179.000001F3F2446000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379475898.000001F3F25DF000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379802179.000001F3F246B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/privacy/firefox/gro.allizom.www.
              Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
              Source: unknownHTTPS traffic detected: 172.67.74.152:443 -> 192.168.2.12:49712 version: TLS 1.2
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53A5B70 GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetDC,GetDeviceCaps,GetDeviceCaps,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,SHCreateMemStream,SelectObject,DeleteDC,ReleaseDC,DeleteObject,EnterCriticalSection,LeaveCriticalSection,IStream_Size,IStream_Reset,IStream_Read,SelectObject,DeleteDC,ReleaseDC,DeleteObject,0_2_00007FF6B53A5B70
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53AA430 RtlAcquirePebLock,NtAllocateVirtualMemory,lstrcpyW,lstrcatW,NtAllocateVirtualMemory,lstrcpyW,RtlInitUnicodeString,RtlInitUnicodeString,LdrEnumerateLoadedModules,RtlReleasePebLock,_invalid_parameter_noinfo_noreturn,CoInitializeEx,lstrcpyW,lstrcatW,CoGetObject,lstrcpyW,lstrcatW,CoGetObject,CoUninitialize,0_2_00007FF6B53AA430
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53A9D30 GetModuleHandleA,GetProcAddress,OpenProcess,NtQuerySystemInformation,NtQuerySystemInformation,GetCurrentProcess,NtQueryObject,GetFinalPathNameByHandleA,CloseHandle,CloseHandle,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6B53A9D30
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53A76A00_2_00007FF6B53A76A0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53E06580_2_00007FF6B53E0658
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B534F7300_2_00007FF6B534F730
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53DB5B00_2_00007FF6B53DB5B0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B535D5700_2_00007FF6B535D570
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B535E6100_2_00007FF6B535E610
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53AC5CB0_2_00007FF6B53AC5CB
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53A68600_2_00007FF6B53A6860
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53A52400_2_00007FF6B53A5240
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53653100_2_00007FF6B5365310
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53A83300_2_00007FF6B53A8330
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53B918C0_2_00007FF6B53B918C
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53504500_2_00007FF6B5350450
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53863500_2_00007FF6B5386350
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53C2E3C0_2_00007FF6B53C2E3C
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B534FE200_2_00007FF6B534FE20
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B538D0800_2_00007FF6B538D080
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53520B00_2_00007FF6B53520B0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53AD0500_2_00007FF6B53AD050
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53720F60_2_00007FF6B53720F6
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5369F800_2_00007FF6B5369F80
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B539F0200_2_00007FF6B539F020
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53859700_2_00007FF6B5385970
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B535CA100_2_00007FF6B535CA10
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5352CA00_2_00007FF6B5352CA0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B535ECB00_2_00007FF6B535ECB0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5351B900_2_00007FF6B5351B90
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53A5B700_2_00007FF6B53A5B70
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5354B700_2_00007FF6B5354B70
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53C36A80_2_00007FF6B53C36A8
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53C86740_2_00007FF6B53C8674
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53B666C0_2_00007FF6B53B666C
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53747200_2_00007FF6B5374720
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53C46E40_2_00007FF6B53C46E4
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53B55980_2_00007FF6B53B5598
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53A65400_2_00007FF6B53A6540
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53266100_2_00007FF6B5326610
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53BA9240_2_00007FF6B53BA924
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53598CD0_2_00007FF6B53598CD
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B539C8E00_2_00007FF6B539C8E0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53AA7800_2_00007FF6B53AA780
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B537B7800_2_00007FF6B537B780
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53B579C0_2_00007FF6B53B579C
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53827500_2_00007FF6B5382750
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53BF7E60_2_00007FF6B53BF7E6
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53902C00_2_00007FF6B53902C0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B539E2F00_2_00007FF6B539E2F0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53261800_2_00007FF6B5326180
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53B31500_2_00007FF6B53B3150
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53B61640_2_00007FF6B53B6164
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53D71600_2_00007FF6B53D7160
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53B12200_2_00007FF6B53B1220
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53C71D80_2_00007FF6B53C71D8
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B537B4800_2_00007FF6B537B480
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53CA44F0_2_00007FF6B53CA44F
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53465100_2_00007FF6B5346510
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53455200_2_00007FF6B5345520
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53C14E40_2_00007FF6B53C14E4
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53B53940_2_00007FF6B53B5394
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53963A60_2_00007FF6B53963A6
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B539B4200_2_00007FF6B539B420
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B537C4200_2_00007FF6B537C420
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53AA4300_2_00007FF6B53AA430
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53483D00_2_00007FF6B53483D0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53CA3C80_2_00007FF6B53CA3C8
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5350E800_2_00007FF6B5350E80
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53A0E900_2_00007FF6B53A0E90
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5357E700_2_00007FF6B5357E70
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5395EF00_2_00007FF6B5395EF0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5325DB00_2_00007FF6B5325DB0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5394D400_2_00007FF6B5394D40
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53B8D500_2_00007FF6B53B8D50
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53D4E300_2_00007FF6B53D4E30
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B537BDD00_2_00007FF6B537BDD0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B535ADD00_2_00007FF6B535ADD0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53D50700_2_00007FF6B53D5070
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53CC1280_2_00007FF6B53CC128
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53C30B80_2_00007FF6B53C30B8
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53BF0D80_2_00007FF6B53BF0D8
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53270E00_2_00007FF6B53270E0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B537C0F00_2_00007FF6B537C0F0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B535BF400_2_00007FF6B535BF40
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53DFFBC0_2_00007FF6B53DFFBC
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5350A800_2_00007FF6B5350A80
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5395AB00_2_00007FF6B5395AB0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B537BAB00_2_00007FF6B537BAB0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53C6A680_2_00007FF6B53C6A68
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5398B000_2_00007FF6B5398B00
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5380AC00_2_00007FF6B5380AC0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5371AF00_2_00007FF6B5371AF0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5353A300_2_00007FF6B5353A30
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53D5C500_2_00007FF6B53D5C50
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53B0D140_2_00007FF6B53B0D14
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5377CEB0_2_00007FF6B5377CEB
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53CBB900_2_00007FF6B53CBB90
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53D6C300_2_00007FF6B53D6C30
              Source: C:\Users\user\Desktop\duschno.exeCode function: String function: 00007FF6B5356940 appears 41 times
              Source: C:\Users\user\Desktop\duschno.exeCode function: String function: 00007FF6B534E1D0 appears 33 times
              Source: C:\Users\user\Desktop\duschno.exeCode function: String function: 00007FF6B53B8254 appears 34 times
              Source: C:\Users\user\Desktop\duschno.exeCode function: String function: 00007FF6B534BA80 appears 32 times
              Source: C:\Users\user\Desktop\duschno.exeCode function: String function: 00007FF6B53686B0 appears 59 times
              Source: classification engineClassification label: mal100.troj.spyw.winEXE@1/0@1/2
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53AB9B0 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,CloseHandle,0_2_00007FF6B53AB9B0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B535E610 CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CloseHandle,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6B535E610
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B5394EA3 CoCreateInstance,0_2_00007FF6B5394EA3
              Source: C:\Users\user\Desktop\duschno.exeMutant created: \Sessions\1\BaseNamedObjects\Mmm-A33C734061CA11EE8C18806E6F6E6963671A6A1E
              Source: duschno.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              Source: C:\Users\user\Desktop\duschno.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
              Source: duschno.exe, 00000000.00000003.2356709912.000001F3F33DC000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2357309036.000001F3F33DD000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
              Source: duschno.exeReversingLabs: Detection: 63%
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: wininet.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: rstrtmgr.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: ncrypt.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: ntasn1.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: iertutil.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: winhttp.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: winnsi.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: urlmon.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: srvcli.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: netutils.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: dnsapi.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: rasadhlp.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: fwpuclnt.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: schannel.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: mskeyprotect.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: msasn1.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: dpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: cryptsp.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: rsaenh.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: cryptbase.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: gpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: ncryptsslp.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: uxtheme.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: windowscodecs.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: vaultcli.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeSection loaded: wintypes.dllJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior
              Source: C:\Users\user\Desktop\duschno.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
              Source: duschno.exeStatic PE information: Image base 0x140000000 > 0x60000000
              Source: duschno.exeStatic file information: File size 1292800 > 1048576
              Source: duschno.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
              Source: duschno.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
              Source: duschno.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
              Source: duschno.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
              Source: duschno.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
              Source: duschno.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
              Source: duschno.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
              Source: duschno.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
              Source: duschno.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
              Source: duschno.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
              Source: duschno.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
              Source: duschno.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
              Source: duschno.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B535D570 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6B535D570
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B536CAB2 push rdi; retf 0004h0_2_00007FF6B536CAB5
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B539C600 ExitProcess,OpenMutexA,ExitProcess,CreateMutexExA,ExitProcess,ReleaseMutex,CloseHandle,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6B539C600
              Source: C:\Users\user\Desktop\duschno.exeCheck user administrative privileges: GetTokenInformation,DecisionNodesgraph_0-70596
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53DB5B0 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,__std_fs_open_handle,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,CloseHandle,CloseHandle,0_2_00007FF6B53DB5B0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53DB500 FindClose,FindFirstFileExW,GetLastError,0_2_00007FF6B53DB500
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53A73F0 GetLogicalDriveStringsW,_invalid_parameter_noinfo_noreturn,0_2_00007FF6B53A73F0
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53B9038 VirtualQuery,GetSystemInfo,VirtualAlloc,VirtualProtect,0_2_00007FF6B53B9038
              Source: C:\Users\user\Desktop\duschno.exeFile opened: D:\sources\migration\Jump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: D:\sources\replacementmanifests\Jump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: D:\sources\migration\wtr\Jump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: D:\sources\replacementmanifests\microsoft-activedirectory-webservices\Jump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: D:\sources\replacementmanifests\microsoft-client-license-platform-service-migration\Jump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: D:\sources\replacementmanifests\hwvid-migration-2\Jump to behavior
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: interactivebrokers.comVMware20,11696508427
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696508427
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: outlook.office.comVMware20,11696508427s
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: discord.comVMware20,11696508427f
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: netportal.hdfcbank.comVMware20,11696508427
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696508427x
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ms.portal.azure.comVMware20,11696508427
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696508427}
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: account.microsoft.com/profileVMware20,11696508427u
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: interactivebrokers.co.inVMware20,11696508427d
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: outlook.office365.comVMware20,11696508427t
              Source: duschno.exe, 00000000.00000002.2420918904.000001F3F07AC000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000002.2420918904.000001F3F0856000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2353764997.000001F3F0856000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: secure.bankofamerica.comVMware20,11696508427|UE
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Test URL for global passwords blocklistVMware20,11696508427
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - GDCDYNVMware20,11696508427p
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU WestVMware20,11696508427n
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: microsoft.visualstudio.comVMware20,11696508427x
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.co.inVMware20,11696508427~
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696508427^
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.comVMware20,11696508427}
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: trackpan.utiitsl.comVMware20,11696508427h
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: tasks.office.comVMware20,11696508427o
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - NDCDYNVMware20,11696508427z
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: global block list test formVMware20,11696508427
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU East & CentralVMware20,11696508427
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: dev.azure.comVMware20,11696508427j
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: bankofamerica.comVMware20,11696508427x
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - COM.HKVMware20,11696508427
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - HKVMware20,11696508427]
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696508427
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: turbotax.intuit.comVMware20,11696508427t
              Source: duschno.exe, 00000000.00000003.2360684559.000001F3F26A7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: AMC password management pageVMware20,11696508427
              Source: C:\Users\user\Desktop\duschno.exeAPI call chain: ExitProcess graph end nodegraph_0-70444
              Source: C:\Users\user\Desktop\duschno.exeProcess information queried: ProcessInformationJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53AA430 RtlAcquirePebLock,NtAllocateVirtualMemory,lstrcpyW,lstrcatW,NtAllocateVirtualMemory,lstrcpyW,RtlInitUnicodeString,RtlInitUnicodeString,LdrEnumerateLoadedModules,RtlReleasePebLock,_invalid_parameter_noinfo_noreturn,CoInitializeEx,lstrcpyW,lstrcatW,CoGetObject,lstrcpyW,lstrcatW,CoGetObject,CoUninitialize,0_2_00007FF6B53AA430
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53DD804 GetLastError,IsDebuggerPresent,OutputDebugStringW,0_2_00007FF6B53DD804
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53DD804 GetLastError,IsDebuggerPresent,OutputDebugStringW,0_2_00007FF6B53DD804
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B535D570 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6B535D570
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53C9EEC GetProcessHeap,0_2_00007FF6B53C9EEC
              Source: C:\Users\user\Desktop\duschno.exeProcess token adjusted: DebugJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53CF2B8 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF6B53CF2B8
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53CF498 SetUnhandledExceptionFilter,0_2_00007FF6B53CF498
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53B7F68 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF6B53B7F68
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53CEC08 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF6B53CEC08
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B539B420 ShellExecuteW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6B539B420
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53CDF10 cpuid 0_2_00007FF6B53CDF10
              Source: C:\Users\user\Desktop\duschno.exeCode function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF6B53C964C
              Source: C:\Users\user\Desktop\duschno.exeCode function: GetLocaleInfoW,0_2_00007FF6B53C9310
              Source: C:\Users\user\Desktop\duschno.exeCode function: GetLocaleInfoEx,FormatMessageA,0_2_00007FF6B53DB170
              Source: C:\Users\user\Desktop\duschno.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_00007FF6B53C9468
              Source: C:\Users\user\Desktop\duschno.exeCode function: GetLocaleInfoW,0_2_00007FF6B53C9518
              Source: C:\Users\user\Desktop\duschno.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF6B53C90C8
              Source: C:\Users\user\Desktop\duschno.exeCode function: EnumSystemLocalesW,0_2_00007FF6B53C8F60
              Source: C:\Users\user\Desktop\duschno.exeCode function: GetLocaleInfoW,0_2_00007FF6B53BE020
              Source: C:\Users\user\Desktop\duschno.exeCode function: EnumSystemLocalesW,0_2_00007FF6B53C9030
              Source: C:\Users\user\Desktop\duschno.exeCode function: EnumSystemLocalesW,0_2_00007FF6B53BDAE0
              Source: C:\Users\user\Desktop\duschno.exeCode function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW,0_2_00007FF6B53C8C04
              Source: C:\Users\user\Desktop\duschno.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeKey value queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation TimeZoneKeyNameJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53CF908 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF6B53CF908
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53A6150 GetUserNameW,0_2_00007FF6B53A6150
              Source: C:\Users\user\Desktop\duschno.exeCode function: 0_2_00007FF6B53A76A0 GetTimeZoneInformation,0_2_00007FF6B53A76A0

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: Process Memory Space: duschno.exe PID: 6856, type: MEMORYSTR
              Source: Yara matchFile source: duschno.exe, type: SAMPLE
              Source: Yara matchFile source: 0.2.duschno.exe.7ff6b5320000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 0.0.duschno.exe.7ff6b5320000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000000.00000002.2420918904.000001F3F07AC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: duschno.exe PID: 6856, type: MEMORYSTR
              Source: duschno.exe, 00000000.00000002.2420918904.000001F3F07AC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Electrum-LTC\config
              Source: duschno.exe, 00000000.00000002.2420918904.000001F3F07AC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: ElectronCash\config
              Source: duschno.exe, 00000000.00000002.2420918904.000001F3F07AC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb
              Source: duschno.exe, 00000000.00000002.2420918904.000001F3F07AC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Exodus\exodus.wallet
              Source: duschno.exe, 00000000.00000002.2420918904.000001F3F07AC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Ethereum\keystore
              Source: duschno.exe, 00000000.00000002.2420918904.000001F3F07AC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Ethereum\keystore
              Source: C:\Users\user\Desktop\duschno.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\monero-project\monero-coreJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\13pckee1.default-release\prefs.jsJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\CookiesJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\CookiesJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\MANIFEST-000001Jump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.oldJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\HistoryJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\13pckee1.default-release\places.sqliteJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\13pckee1.default-release\cookies.sqliteJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOGJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\13pckee1.default-release\key4.dbJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data For AccountJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOCKJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\CURRENTJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension CookiesJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\HistoryJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.logJump to behavior
              Source: C:\Users\user\Desktop\duschno.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: Process Memory Space: duschno.exe PID: 6856, type: MEMORYSTR
              Source: Yara matchFile source: duschno.exe, type: SAMPLE
              Source: Yara matchFile source: 0.2.duschno.exe.7ff6b5320000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 0.0.duschno.exe.7ff6b5320000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000000.00000002.2420918904.000001F3F07AC000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: duschno.exe PID: 6856, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
              Native API
              1
              DLL Side-Loading
              1
              Exploitation for Privilege Escalation
              1
              Access Token Manipulation
              1
              OS Credential Dumping
              12
              System Time Discovery
              Remote Services1
              Screen Capture
              21
              Encrypted Channel
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
              Access Token Manipulation
              1
              Deobfuscate/Decode Files or Information
              LSASS Memory31
              Security Software Discovery
              Remote Desktop Protocol1
              Email Collection
              1
              Non-Standard Port
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
              DLL Side-Loading
              2
              Obfuscated Files or Information
              Security Account Manager2
              Process Discovery
              SMB/Windows Admin Shares1
              Archive Collected Data
              2
              Ingress Tool Transfer
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
              DLL Side-Loading
              NTDS1
              Account Discovery
              Distributed Component Object Model2
              Data from Local System
              2
              Non-Application Layer Protocol
              Traffic DuplicationData Destruction
              Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
              System Owner/User Discovery
              SSHKeylogging3
              Application Layer Protocol
              Scheduled TransferData Encrypted for Impact
              Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials1
              System Network Configuration Discovery
              VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
              DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync3
              File and Directory Discovery
              Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
              Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem34
              System Information Discovery
              Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              duschno.exe63%ReversingLabsWin64.Trojan.MeduzaStealer
              duschno.exe100%Joe Sandbox ML
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              SourceDetectionScannerLabelLink
              http://ns.photo/0%Avira URL Cloudsafe
              https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696506299400400001.2&ci=1696506299033.0%Avira URL Cloudsafe
              http://ns.a.0/sTy0%Avira URL Cloudsafe
              http://ns.adoraw-se0%Avira URL Cloudsafe
              http://ns.adobe.hotosh0%Avira URL Cloudsafe
              NameIPActiveMaliciousAntivirus DetectionReputation
              api.ipify.org
              172.67.74.152
              truefalse
                high
                NameMaliciousAntivirus DetectionReputation
                https://api.ipify.org/false
                  high
                  NameSourceMaliciousAntivirus DetectionReputation
                  http://ns.adobe.hotoshduschno.exe, 00000000.00000003.2420291452.000001F3F3040000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420399094.000001F3F3045000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2353152740.000001F3F3031000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420324106.000001F3F3044000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://duckduckgo.com/chrome_newtabduschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpfalse
                    high
                    https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696506299400400001.2&ci=1696506299033.duschno.exe, 00000000.00000003.2381064141.000001F3F33BC000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380320290.000001F3F32D9000.00000004.00000020.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://duckduckgo.com/ac/?q=duschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpfalse
                      high
                      http://ns.adobe.c.0/tiduschno.exe, 00000000.00000003.2420291452.000001F3F3040000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420399094.000001F3F3045000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2353152740.000001F3F3031000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420324106.000001F3F3044000.00000004.00000020.00020000.00000000.sdmpfalse
                        high
                        http://ns.adoraw-seduschno.exe, 00000000.00000003.2420291452.000001F3F3040000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420399094.000001F3F3045000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2353152740.000001F3F3031000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420324106.000001F3F3044000.00000004.00000020.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://bridge.sfo1.ap01.net/ctp?version=16.0.0&key=1696506299400400001.1&ci=1696506299033.12791&ctaduschno.exe, 00000000.00000003.2380962493.000001F3F33E5000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2381237342.000001F3F3285000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380817799.000001F3F3281000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2381064141.000001F3F33BC000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380320290.000001F3F32D9000.00000004.00000020.00020000.00000000.sdmpfalse
                          high
                          http://ns.photo/duschno.exe, 00000000.00000003.2420291452.000001F3F3040000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420399094.000001F3F3045000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2353152740.000001F3F3031000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420324106.000001F3F3044000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://www.google.com/images/branding/product/ico/googleg_lodp.icoduschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            http://ns.a.0/sTyduschno.exe, 00000000.00000003.2420291452.000001F3F3040000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420399094.000001F3F3045000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2353152740.000001F3F3031000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2420324106.000001F3F3044000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_cd61a4703a8613be887576f2bd084bcc6f4756dccdbe5062duschno.exe, 00000000.00000003.2380962493.000001F3F33E5000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2381237342.000001F3F3285000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380817799.000001F3F3281000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2381064141.000001F3F33BC000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380320290.000001F3F32D9000.00000004.00000020.00020000.00000000.sdmpfalse
                              high
                              https://support.mozilla.org/products/firefoxgro.allizom.troppus.P9ZDdyXKOWl2duschno.exe, 00000000.00000003.2379802179.000001F3F246B000.00000004.00000020.00020000.00000000.sdmpfalse
                                high
                                https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=duschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=duschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpfalse
                                    high
                                    https://www.ecosia.org/newtab/duschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpfalse
                                      high
                                      https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-brduschno.exe, 00000000.00000003.2379802179.000001F3F246B000.00000004.00000020.00020000.00000000.sdmpfalse
                                        high
                                        https://ac.ecosia.org/autocomplete?q=duschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpfalse
                                          high
                                          https://api.ipify.org/aduschno.exe, 00000000.00000002.2420918904.000001F3F07AC000.00000004.00000020.00020000.00000000.sdmpfalse
                                            high
                                            https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpgduschno.exe, 00000000.00000003.2381064141.000001F3F33BC000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380320290.000001F3F32D9000.00000004.00000020.00020000.00000000.sdmpfalse
                                              high
                                              https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/searchduschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpfalse
                                                high
                                                https://www.invisalign.com/?utm_source=admarketplace&utm_medium=paidsearch&utm_campaign=Invisalign&uduschno.exe, 00000000.00000003.2381064141.000001F3F33BC000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380320290.000001F3F32D9000.00000004.00000020.00020000.00000000.sdmpfalse
                                                  high
                                                  https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4CbmfQq%2B4pbW4pbWfpbX7ReNxR3UIG8zInwYIFIVs9eduschno.exe, 00000000.00000003.2380320290.000001F3F32D9000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    high
                                                    https://contile-images.services.mozilla.com/CuERQnIs4CzqjKBh9os6_h9d4CUDCHO3oiqmAQO6VLM.25122.jpgduschno.exe, 00000000.00000003.2381064141.000001F3F33BC000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380320290.000001F3F32D9000.00000004.00000020.00020000.00000000.sdmpfalse
                                                      high
                                                      https://support.mozilla.orgduschno.exe, 00000000.00000003.2376253271.000001F3F360C000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379802179.000001F3F2436000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380020573.000001F3F2570000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2374619093.000001F3F26C6000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380020573.000001F3F2578000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2380320290.000001F3F32D5000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379802179.000001F3F243E000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379802179.000001F3F2463000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379475898.000001F3F25D8000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379802179.000001F3F245B000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2379475898.000001F3F25D0000.00000004.00000020.00020000.00000000.sdmp, duschno.exe, 00000000.00000003.2374619093.000001F3F26BE000.00000004.00000020.00020000.00000000.sdmpfalse
                                                        high
                                                        https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=duschno.exe, 00000000.00000003.2354946016.000001F3F3261000.00000004.00000020.00020000.00000000.sdmpfalse
                                                          high
                                                          • No. of IPs < 25%
                                                          • 25% < No. of IPs < 50%
                                                          • 50% < No. of IPs < 75%
                                                          • 75% < No. of IPs
                                                          IPDomainCountryFlagASNASN NameMalicious
                                                          193.3.19.151
                                                          unknownDenmark
                                                          2107ARNES-NETAcademicandResearchNetworkofSloveniaSItrue
                                                          172.67.74.152
                                                          api.ipify.orgUnited States
                                                          13335CLOUDFLARENETUSfalse
                                                          Joe Sandbox version:41.0.0 Charoite
                                                          Analysis ID:1574589
                                                          Start date and time:2024-12-13 12:40:01 +01:00
                                                          Joe Sandbox product:CloudBasic
                                                          Overall analysis duration:0h 5m 27s
                                                          Hypervisor based Inspection enabled:false
                                                          Report type:full
                                                          Cookbook file name:default.jbs
                                                          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                          Number of analysed new started processes analysed:5
                                                          Number of new started drivers analysed:0
                                                          Number of existing processes analysed:0
                                                          Number of existing drivers analysed:0
                                                          Number of injected processes analysed:0
                                                          Technologies:
                                                          • HCA enabled
                                                          • EGA enabled
                                                          • AMSI enabled
                                                          Analysis Mode:default
                                                          Analysis stop reason:Timeout
                                                          Sample name:duschno.exe
                                                          Detection:MAL
                                                          Classification:mal100.troj.spyw.winEXE@1/0@1/2
                                                          EGA Information:
                                                          • Successful, ratio: 100%
                                                          HCA Information:
                                                          • Successful, ratio: 99%
                                                          • Number of executed functions: 99
                                                          • Number of non-executed functions: 98
                                                          Cookbook Comments:
                                                          • Found application associated with file extension: .exe
                                                          • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                                                          • Excluded IPs from analysis (whitelisted): 20.12.23.50
                                                          • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                                          • Report size exceeded maximum capacity and may have missing disassembly code.
                                                          • Report size getting too big, too many NtOpenKeyEx calls found.
                                                          • Report size getting too big, too many NtQueryValueKey calls found.
                                                          • VT rate limit hit for: duschno.exe
                                                          No simulations
                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                          193.3.19.1511Sj5F6P4nv.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                                            5LEXIucyEP.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                                              44qLDKzsfO.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                                                gP5rh6fa0S.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                                                  urkOkB0BdX.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                                                    8F0oMWUhg7.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                                                      172.67.74.152jgbC220X2U.exeGet hashmaliciousUnknownBrowse
                                                                      • api.ipify.org/?format=text
                                                                      malware.exeGet hashmaliciousTargeted Ransomware, TrojanRansomBrowse
                                                                      • api.ipify.org/
                                                                      Simple1.exeGet hashmaliciousUnknownBrowse
                                                                      • api.ipify.org/
                                                                      Simple2.exeGet hashmaliciousUnknownBrowse
                                                                      • api.ipify.org/
                                                                      systemConfigChecker.exeGet hashmaliciousUnknownBrowse
                                                                      • api.ipify.org/
                                                                      systemConfigChecker.exeGet hashmaliciousUnknownBrowse
                                                                      • api.ipify.org/
                                                                      2b7cu0KwZl.exeGet hashmaliciousUnknownBrowse
                                                                      • api.ipify.org/
                                                                      Zc9eO57fgF.elfGet hashmaliciousUnknownBrowse
                                                                      • api.ipify.org/
                                                                      67065b4c84713_Javiles.exeGet hashmaliciousRDPWrap ToolBrowse
                                                                      • api.ipify.org/
                                                                      Yc9hcFC1ux.exeGet hashmaliciousUnknownBrowse
                                                                      • api.ipify.org/
                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                      api.ipify.orgchos.exeGet hashmaliciousUnknownBrowse
                                                                      • 104.26.12.205
                                                                      http://ap2vxmyqxf.ballyentoe.shopGet hashmaliciousEvilProxy, HTMLPhisherBrowse
                                                                      • 104.26.12.205
                                                                      installer.exeGet hashmaliciousUnknownBrowse
                                                                      • 104.26.12.205
                                                                      installer.exeGet hashmaliciousUnknownBrowse
                                                                      • 172.67.74.152
                                                                      zapret.exeGet hashmaliciousUnknownBrowse
                                                                      • 104.26.12.205
                                                                      Rockwool-Msg-S9039587897.pdfGet hashmaliciousEvilProxy, HTMLPhisherBrowse
                                                                      • 104.26.12.205
                                                                      RFQ-004282A.Teknolojileri A.S.exeGet hashmaliciousAgentTeslaBrowse
                                                                      • 172.67.74.152
                                                                      Employee_Letter.pdfGet hashmaliciousHTMLPhisherBrowse
                                                                      • 104.26.12.205
                                                                      discord.exeGet hashmaliciousUnknownBrowse
                                                                      • 172.67.74.152
                                                                      jgbC220X2U.exeGet hashmaliciousUnknownBrowse
                                                                      • 172.67.74.152
                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                      ARNES-NETAcademicandResearchNetworkofSloveniaSIjade.arm.elfGet hashmaliciousMiraiBrowse
                                                                      • 95.87.151.72
                                                                      https://u48551708.ct.sendgrid.net/ls/click?upn=u001.ztPEaTmy8WofhPYJ48HDSCunUq5pm5yTGRhe-2B0bVSngC8hMYiy6PgMy1xJOG8JJZaOsK-2FG9SE7UmhEzeQSXDmEf7Z3nlXZDH-2BW1HSMP6c8uYUvXDTaJRyLbPDV6bI3nnDyIlM0OJKevMwAF04rpfLmQEYS641NQTMU227kkOtBQgQK-2FNlHeN6DpPMLDgH6kuMS3X_2vbC1nrAFjePip8HYuHYOlkYXiy7Z-2FrO9MQN7lNoEgxRkovUJGAEvKvTFyRmFsa9AQlcDpFhpJzgHajMOC0yWTZOc2DdmxhrlyPvteyXbl8nlhAtf2p-2FHw4RnlZ8cxDY-2BWJeBsszGnsrXuNOI8LpL5ZYI3ad04OdxC8tHHA5tO-2Be1xS3Z9Z3VrOTM-2FT5ptoYnx5N-2FTYKQ13RZ-2FookVMhAtJ6OV43Zayd1qOmHGLwUI8-3DGet hashmaliciousPhisherBrowse
                                                                      • 193.3.19.55
                                                                      https://santa-secret.ru/api/verify?a=NjgyODEwNCw1bWluOHE2MHpuX3J1LC9hY2NvdW50L2JveGVzLHZsYWRpbWlyLmdsdXNoZW5rb0Bob2NobGFuZC5ydSwyNDE0MTYzMg==Get hashmaliciousUnknownBrowse
                                                                      • 193.3.184.46
                                                                      la.bot.sparc.elfGet hashmaliciousMiraiBrowse
                                                                      • 95.87.175.59
                                                                      file.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                                                      • 193.3.168.50
                                                                      file.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                                                      • 193.3.168.50
                                                                      file.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                                                      • 193.3.168.50
                                                                      botnet.spc.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 193.2.192.103
                                                                      loligang.spc.elfGet hashmaliciousMiraiBrowse
                                                                      • 88.200.25.137
                                                                      arm.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      • 178.172.103.122
                                                                      CLOUDFLARENETUSBloxflip Predictor.exeGet hashmaliciousNjratBrowse
                                                                      • 162.159.137.232
                                                                      file.exeGet hashmaliciousAmadey, LummaC Stealer, XmrigBrowse
                                                                      • 172.67.139.78
                                                                      file.exeGet hashmaliciousUnknownBrowse
                                                                      • 172.67.192.146
                                                                      https://grizzled-overjoyed-bag.glitch.me/#comercial.portugal@eurofred.comGet hashmaliciousHTMLPhisherBrowse
                                                                      • 104.17.25.14
                                                                      https://aggttt.z4.web.core.windows.net/?bcda=00-1-234-294-2156Get hashmaliciousTechSupportScamBrowse
                                                                      • 1.1.1.1
                                                                      https://idw.soundestlink.com/ce/c/675b7a96903a5335b119c33f/675b7ae33d33226215120f66/675b7afd057112d43b49094d?signature=7e9e7eead1b3f32bbe3709a667795cd47f753f0f46ed5e056831680ea81aa102Get hashmaliciousUnknownBrowse
                                                                      • 172.64.145.78
                                                                      https://opof.utackhepr.com/WE76L1u/Get hashmaliciousUnknownBrowse
                                                                      • 104.18.95.41
                                                                      taskhost.exeGet hashmaliciousXWormBrowse
                                                                      • 104.26.2.16
                                                                      https://e.trustifi.com/#/fff2a6/34074b/38c75f/bf3fbd/0d1c47/12c665/f3cdcd/c1be48/e8666a/ef542d/85972d/627493/9a11d6/1f4096/1d247f/d08b7b/9066d9/86c9f0/b1ff53/224fc1/c5dff5/a64e02/f00a15/3cdbea/a78615/4ddb76/30d9f7/98e1a2/9412cb/8e2651/8d4e63/9d313b/2f0213/ae3252/642e4a/6f0b2e/306b49/fd8e03/84bfef/0da4e6/6224c1/902b5e/e0d84c/badeba/3e52c1/94282a/975221/7a2e92/514659/ae5bab/957b7b/eb9e61/6942c6/d917d9/44a5ae/e58297/02048a/55f177/dca75c/c46e68/ac781c/5b787b/abcd53/568132/1d514a/5290de/d0b524/7d0cb6/e4e8bf/2ff215/1ddb69/add914/7674bb/dc5d9b/8fc829/561052/f5a816/40ee64/a0bcf5/b0cc13/8e70a5/255ef2/b24b8d/81e09f/4c70dd/5bbaa4/7ff26c/f1999b/4a2515/4a3a04/0a188eGet hashmaliciousUnknownBrowse
                                                                      • 104.17.25.14
                                                                      smb.ps1Get hashmaliciousXmrigBrowse
                                                                      • 104.16.231.132
                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                      37f463bf4616ecd445d4a1937da06e19AzureConnect.exeGet hashmaliciousCobaltStrikeBrowse
                                                                      • 172.67.74.152
                                                                      file.exeGet hashmaliciousAmadey, Credential Flusher, LummaC Stealer, Stealc, VidarBrowse
                                                                      • 172.67.74.152
                                                                      x295IO8kqM.exeGet hashmaliciousRemcosBrowse
                                                                      • 172.67.74.152
                                                                      file.exeGet hashmaliciousAmadey, Credential Flusher, LummaC Stealer, Stealc, Vidar, XmrigBrowse
                                                                      • 172.67.74.152
                                                                      PO_11171111221.Vbs.vbsGet hashmaliciousFormBookBrowse
                                                                      • 172.67.74.152
                                                                      file.exeGet hashmaliciousAmadey, LummaC Stealer, Stealc, Vidar, XmrigBrowse
                                                                      • 172.67.74.152
                                                                      CMR ART009.docxGet hashmaliciousUnknownBrowse
                                                                      • 172.67.74.152
                                                                      file.exeGet hashmaliciousAmadey, Credential Flusher, LummaC Stealer, Stealc, Vidar, XmrigBrowse
                                                                      • 172.67.74.152
                                                                      file.exeGet hashmaliciousAmadey, LummaC Stealer, Stealc, Vidar, XmrigBrowse
                                                                      • 172.67.74.152
                                                                      WO-663071 Sabiya Power Station Project.vbsGet hashmaliciousRemcosBrowse
                                                                      • 172.67.74.152
                                                                      No context
                                                                      No created / dropped files found
                                                                      File type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                      Entropy (8bit):6.519533062327776
                                                                      TrID:
                                                                      • Win64 Executable GUI (202006/5) 92.65%
                                                                      • Win64 Executable (generic) (12005/4) 5.51%
                                                                      • Generic Win/DOS Executable (2004/3) 0.92%
                                                                      • DOS Executable Generic (2002/1) 0.92%
                                                                      • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                      File name:duschno.exe
                                                                      File size:1'292'800 bytes
                                                                      MD5:c6813da66eba357d0deaa48c2f7032b8
                                                                      SHA1:6812e46c51f823ff0b0ee17bfce0af72f857af66
                                                                      SHA256:1420f60f053c3ea5605239ee431e5f487245108b1c01be75d16b5246156fa178
                                                                      SHA512:19391c6b12ba8f34a5faf326f8986ef8de4729d614d72bf438c6efa569b3505159ca55f580fe2a02642e5e7a0f1b38a7a9db9f0d66d67ba548d84c230183159e
                                                                      SSDEEP:24576:IgAMXnXkciEIMJQZe8Us9Mjemp5wx1wach0lhSMXl5xT+d:x3Xn0ciEIp3Us+egSx+ahpxTK
                                                                      TLSH:82555B65195C03E9D8BE9138DEAB8A12F575380903B1E7EB1AD147921FE37E09E3E350
                                                                      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........N.7./.d./.d./.d.W.e./.d.W.e./.d...e./.d...e./.d...e./.d...e./.d.W.e8/.d.W.e./.d.W.e./.d./.d...d.W.e./.d...e./.d..>d./.d...e./.
                                                                      Icon Hash:00928e8e8686b000
                                                                      Entrypoint:0x1400af220
                                                                      Entrypoint Section:.text
                                                                      Digitally signed:false
                                                                      Imagebase:0x140000000
                                                                      Subsystem:windows gui
                                                                      Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                                                      DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                                                      Time Stamp:0x673B379D [Mon Nov 18 12:48:29 2024 UTC]
                                                                      TLS Callbacks:
                                                                      CLR (.Net) Version:
                                                                      OS Version Major:6
                                                                      OS Version Minor:0
                                                                      File Version Major:6
                                                                      File Version Minor:0
                                                                      Subsystem Version Major:6
                                                                      Subsystem Version Minor:0
                                                                      Import Hash:0095cfee1cdfcef936c4c086b6b4fe85
                                                                      Instruction
                                                                      dec eax
                                                                      sub esp, 28h
                                                                      call 00007F01BCB29FB4h
                                                                      dec eax
                                                                      add esp, 28h
                                                                      jmp 00007F01BCB2974Fh
                                                                      int3
                                                                      int3
                                                                      dec eax
                                                                      sub esp, 28h
                                                                      dec ebp
                                                                      mov eax, dword ptr [ecx+38h]
                                                                      dec eax
                                                                      mov ecx, edx
                                                                      dec ecx
                                                                      mov edx, ecx
                                                                      call 00007F01BCB298E2h
                                                                      mov eax, 00000001h
                                                                      dec eax
                                                                      add esp, 28h
                                                                      ret
                                                                      int3
                                                                      int3
                                                                      int3
                                                                      inc eax
                                                                      push ebx
                                                                      inc ebp
                                                                      mov ebx, dword ptr [eax]
                                                                      dec eax
                                                                      mov ebx, edx
                                                                      inc ecx
                                                                      and ebx, FFFFFFF8h
                                                                      dec esp
                                                                      mov ecx, ecx
                                                                      inc ecx
                                                                      test byte ptr [eax], 00000004h
                                                                      dec esp
                                                                      mov edx, ecx
                                                                      je 00007F01BCB298E5h
                                                                      inc ecx
                                                                      mov eax, dword ptr [eax+08h]
                                                                      dec ebp
                                                                      arpl word ptr [eax+04h], dx
                                                                      neg eax
                                                                      dec esp
                                                                      add edx, ecx
                                                                      dec eax
                                                                      arpl ax, cx
                                                                      dec esp
                                                                      and edx, ecx
                                                                      dec ecx
                                                                      arpl bx, ax
                                                                      dec edx
                                                                      mov edx, dword ptr [eax+edx]
                                                                      dec eax
                                                                      mov eax, dword ptr [ebx+10h]
                                                                      mov ecx, dword ptr [eax+08h]
                                                                      dec eax
                                                                      mov eax, dword ptr [ebx+08h]
                                                                      test byte ptr [ecx+eax+03h], 0000000Fh
                                                                      je 00007F01BCB298DDh
                                                                      movzx eax, byte ptr [ecx+eax+03h]
                                                                      and eax, FFFFFFF0h
                                                                      dec esp
                                                                      add ecx, eax
                                                                      dec esp
                                                                      xor ecx, edx
                                                                      dec ecx
                                                                      mov ecx, ecx
                                                                      pop ebx
                                                                      jmp 00007F01BCB28E86h
                                                                      int3
                                                                      and dword ptr [00087639h], 00000000h
                                                                      ret
                                                                      dec eax
                                                                      mov dword ptr [esp+08h], ebx
                                                                      push ebp
                                                                      dec eax
                                                                      lea ebp, dword ptr [esp-000004C0h]
                                                                      dec eax
                                                                      sub esp, 000005C0h
                                                                      mov ebx, ecx
                                                                      mov ecx, 00000017h
                                                                      call dword ptr [0002600Eh]
                                                                      test eax, eax
                                                                      je 00007F01BCB298D6h
                                                                      mov ecx, ebx
                                                                      int 29h
                                                                      mov ecx, 00000003h
                                                                      NameVirtual AddressVirtual Size Is in Section
                                                                      IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                      IMAGE_DIRECTORY_ENTRY_IMPORT0x12df680x140.rdata
                                                                      IMAGE_DIRECTORY_ENTRY_RESOURCE0x13f0000x1e0.rsrc
                                                                      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x1380000x6c18.pdata
                                                                      IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                      IMAGE_DIRECTORY_ENTRY_BASERELOC0x1400000xd3c.reloc
                                                                      IMAGE_DIRECTORY_ENTRY_DEBUG0x1183d00x38.rdata
                                                                      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                      IMAGE_DIRECTORY_ENTRY_TLS0x1185800x28.rdata
                                                                      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x1182900x140.rdata
                                                                      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                      IMAGE_DIRECTORY_ENTRY_IAT0xd50000x778.rdata
                                                                      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                      .text0x10000xd32900xd34005dbe528542b2f69c830f0ddd1160738fFalse0.41695636094674554zlib compressed data6.322034703392791IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                      .rdata0xd50000x5a8780x5aa0070e76c24e7297aac36ad0a296a4df642False0.4009401939655172data6.3070531311223075IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                      .data0x1300000x7ce40x5a006bc2f26b443764d2872d13f9d896878bFalse0.08211805555555556data4.536476287471787IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                      .pdata0x1380000x6c180x6e00c6eecc837e87b0c200a192a62ab8b009False0.4799715909090909data5.967062390694732IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                      .rsrc0x13f0000x1e00x2003bdf73d69c827b52e4eecca5ab7e253dFalse0.533203125data4.7176788329467545IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                      .reloc0x1400000xd3c0xe0004965a7aa6d79975008713ed9311fed1False0.48604910714285715data5.341340137514453IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                      NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                      RT_MANIFEST0x13f0600x17dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5931758530183727
                                                                      DLLImport
                                                                      WS2_32.dllclosesocket, inet_pton, WSAStartup, send, socket, connect, recv, WSACleanup, htons
                                                                      CRYPT32.dllCryptUnprotectData, CryptProtectData
                                                                      WININET.dllInternetOpenW, InternetCloseHandle, InternetReadFile, InternetQueryDataAvailable, HttpQueryInfoW, InternetOpenUrlA, InternetOpenA
                                                                      ntdll.dllNtQuerySystemInformation, RtlInitUnicodeString, LdrEnumerateLoadedModules, RtlAcquirePebLock, RtlReleasePebLock, NtQueryObject, NtAllocateVirtualMemory
                                                                      RstrtMgr.DLLRmGetList, RmStartSession, RmEndSession, RmRegisterResources
                                                                      bcrypt.dllBCryptCloseAlgorithmProvider, BCryptOpenAlgorithmProvider, BCryptDecrypt, BCryptDestroyKey, BCryptGenerateSymmetricKey, BCryptSetProperty
                                                                      KERNEL32.dllGetFileInformationByHandleEx, AreFileApisANSI, FindFirstFileW, FindNextFileW, FindClose, OpenProcess, CreateToolhelp32Snapshot, Process32NextW, LoadLibraryA, Process32FirstW, CloseHandle, GetSystemInfo, GetProcAddress, LocalFree, FreeLibrary, GetLastError, ExitProcess, MultiByteToWideChar, WideCharToMultiByte, VirtualAlloc, ReadFile, WriteFile, CreateFileW, GetFileSize, GetCurrentProcess, VirtualQuery, GetStdHandle, TerminateProcess, CreateMutexA, ReleaseMutex, OpenMutexA, GetModuleFileNameA, GetVolumeInformationW, GetGeoInfoA, HeapFree, EnterCriticalSection, GetModuleFileNameW, GetProcessId, LeaveCriticalSection, SetFilePointer, InitializeCriticalSectionEx, FreeEnvironmentStringsW, GetModuleHandleA, HeapSize, GetLogicalDriveStringsW, GetFinalPathNameByHandleA, GetTimeZoneInformation, lstrcatW, HeapReAlloc, HeapAlloc, GetComputerNameW, GetProcessHeap, GlobalMemoryStatusEx, GetModuleHandleW, lstrcpyW, GetEnvironmentStringsW, SetLastError, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, IsDebuggerPresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsProcessorFeaturePresent, GetCurrentProcessId, GetSystemTimeAsFileTime, VirtualProtect, GetFileSizeEx, SetFilePointerEx, GetCurrentThreadId, GetFileType, GetStartupInfoW, FlushFileBuffers, GetConsoleOutputCP, GetConsoleMode, GetTempPathW, FlsAlloc, FlsGetValue, FlsSetValue, FlsFree, InitializeCriticalSectionAndSpinCount, LoadLibraryExW, GetDateFormatW, GetTimeFormatW, CompareStringW, LCMapStringW, GetLocaleInfoW, IsValidLocale, SetEndOfFile, EnumSystemLocalesW, ReadConsoleW, RaiseException, GetModuleHandleExW, SetStdHandle, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, GetStringTypeW, WriteConsoleW, OutputDebugStringW, SetEnvironmentVariableW, ReleaseSRWLockExclusive, AcquireSRWLockExclusive, WakeAllConditionVariable, SleepConditionVariableSRW, QueryPerformanceCounter, InitializeSListHead, RtlUnwindEx, RtlUnwind, RtlPcToFileHeader, EncodePointer, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, GetFileAttributesExW, GetFileAttributesW, FindFirstFileExW, GetCurrentDirectoryW, GetNativeSystemInfo, LCMapStringEx, CompareStringEx, DecodePointer, DeleteCriticalSection, GetCommandLineA, GetCommandLineW, GetUserGeoID, GetUserDefaultLCID, GetLocaleInfoEx, FormatMessageA
                                                                      USER32.dllGetWindowRect, ReleaseDC, GetDesktopWindow, EnumDisplayDevicesW, GetSystemMetrics, GetDC
                                                                      GDI32.dllBitBlt, CreateCompatibleBitmap, SelectObject, CreateCompatibleDC, GetDeviceCaps, DeleteDC, GetObjectW, DeleteObject
                                                                      ADVAPI32.dllLookupPrivilegeValueW, AdjustTokenPrivileges, GetCurrentHwProfileW, RegCloseKey, RegGetValueA, RegQueryValueExA, RegOpenKeyExA, GetUserNameW, RegEnumKeyExA, RevertToSelf, ConvertSidToStringSidA, ImpersonateLoggedOnUser, OpenProcessToken, DuplicateTokenEx, GetTokenInformation, CredEnumerateA, CredFree
                                                                      SHELL32.dllSHGetKnownFolderPath, ShellExecuteW
                                                                      ole32.dllCoTaskMemFree, CoGetObject, CoCreateInstance, CoUninitialize, CoSetProxyBlanket, CoInitializeSecurity, CoInitializeEx
                                                                      OLEAUT32.dllSysStringByteLen, SysAllocStringByteLen, SysFreeString
                                                                      SHLWAPI.dll
                                                                      gdiplus.dllGdipGetImageEncodersSize, GdipFree, GdipDisposeImage, GdiplusShutdown, GdiplusStartup, GdipCloneImage, GdipAlloc, GdipCreateBitmapFromScan0, GdipCreateBitmapFromHBITMAP, GdipSaveImageToStream, GdipGetImageEncoders
                                                                      Language of compilation systemCountry where language is spokenMap
                                                                      EnglishUnited States
                                                                      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                      2024-12-13T12:41:07.303709+01002049441ET MALWARE Win32/Unknown Grabber Base64 Data Exfiltration Attempt1192.168.2.1249711193.3.19.15115666TCP
                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                      Dec 13, 2024 12:40:59.076744080 CET4971115666192.168.2.12193.3.19.151
                                                                      Dec 13, 2024 12:40:59.196599007 CET1566649711193.3.19.151192.168.2.12
                                                                      Dec 13, 2024 12:40:59.196712971 CET4971115666192.168.2.12193.3.19.151
                                                                      Dec 13, 2024 12:40:59.988456011 CET49712443192.168.2.12172.67.74.152
                                                                      Dec 13, 2024 12:40:59.988502979 CET44349712172.67.74.152192.168.2.12
                                                                      Dec 13, 2024 12:40:59.988567114 CET49712443192.168.2.12172.67.74.152
                                                                      Dec 13, 2024 12:41:00.101619959 CET49712443192.168.2.12172.67.74.152
                                                                      Dec 13, 2024 12:41:00.101634026 CET44349712172.67.74.152192.168.2.12
                                                                      Dec 13, 2024 12:41:01.316545963 CET44349712172.67.74.152192.168.2.12
                                                                      Dec 13, 2024 12:41:01.316622972 CET49712443192.168.2.12172.67.74.152
                                                                      Dec 13, 2024 12:41:01.372128010 CET49712443192.168.2.12172.67.74.152
                                                                      Dec 13, 2024 12:41:01.372153044 CET44349712172.67.74.152192.168.2.12
                                                                      Dec 13, 2024 12:41:01.372509956 CET44349712172.67.74.152192.168.2.12
                                                                      Dec 13, 2024 12:41:01.372562885 CET49712443192.168.2.12172.67.74.152
                                                                      Dec 13, 2024 12:41:01.373819113 CET49712443192.168.2.12172.67.74.152
                                                                      Dec 13, 2024 12:41:01.419336081 CET44349712172.67.74.152192.168.2.12
                                                                      Dec 13, 2024 12:41:01.463155985 CET1566649711193.3.19.151192.168.2.12
                                                                      Dec 13, 2024 12:41:01.463339090 CET4971115666192.168.2.12193.3.19.151
                                                                      Dec 13, 2024 12:41:01.756383896 CET44349712172.67.74.152192.168.2.12
                                                                      Dec 13, 2024 12:41:01.756453037 CET49712443192.168.2.12172.67.74.152
                                                                      Dec 13, 2024 12:41:01.756454945 CET44349712172.67.74.152192.168.2.12
                                                                      Dec 13, 2024 12:41:01.756494045 CET49712443192.168.2.12172.67.74.152
                                                                      Dec 13, 2024 12:41:01.756822109 CET49712443192.168.2.12172.67.74.152
                                                                      Dec 13, 2024 12:41:01.756839037 CET44349712172.67.74.152192.168.2.12
                                                                      Dec 13, 2024 12:41:07.303709030 CET4971115666192.168.2.12193.3.19.151
                                                                      Dec 13, 2024 12:41:07.540303946 CET4971115666192.168.2.12193.3.19.151
                                                                      Dec 13, 2024 12:41:07.599028111 CET1566649711193.3.19.151192.168.2.12
                                                                      Dec 13, 2024 12:41:07.599040031 CET1566649711193.3.19.151192.168.2.12
                                                                      Dec 13, 2024 12:41:07.599047899 CET1566649711193.3.19.151192.168.2.12
                                                                      Dec 13, 2024 12:41:07.599056959 CET1566649711193.3.19.151192.168.2.12
                                                                      Dec 13, 2024 12:41:07.599061012 CET1566649711193.3.19.151192.168.2.12
                                                                      Dec 13, 2024 12:41:07.599069118 CET1566649711193.3.19.151192.168.2.12
                                                                      Dec 13, 2024 12:41:07.599078894 CET1566649711193.3.19.151192.168.2.12
                                                                      Dec 13, 2024 12:41:07.600037098 CET1566649711193.3.19.151192.168.2.12
                                                                      Dec 13, 2024 12:41:07.600050926 CET1566649711193.3.19.151192.168.2.12
                                                                      Dec 13, 2024 12:41:07.600059986 CET1566649711193.3.19.151192.168.2.12
                                                                      Dec 13, 2024 12:41:07.661385059 CET1566649711193.3.19.151192.168.2.12
                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                      Dec 13, 2024 12:40:59.810297966 CET6405553192.168.2.121.1.1.1
                                                                      Dec 13, 2024 12:40:59.950579882 CET53640551.1.1.1192.168.2.12
                                                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                      Dec 13, 2024 12:40:59.810297966 CET192.168.2.121.1.1.10x75a5Standard query (0)api.ipify.orgA (IP address)IN (0x0001)false
                                                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                      Dec 13, 2024 12:40:59.950579882 CET1.1.1.1192.168.2.120x75a5No error (0)api.ipify.org172.67.74.152A (IP address)IN (0x0001)false
                                                                      Dec 13, 2024 12:40:59.950579882 CET1.1.1.1192.168.2.120x75a5No error (0)api.ipify.org104.26.13.205A (IP address)IN (0x0001)false
                                                                      Dec 13, 2024 12:40:59.950579882 CET1.1.1.1192.168.2.120x75a5No error (0)api.ipify.org104.26.12.205A (IP address)IN (0x0001)false
                                                                      • api.ipify.org
                                                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                      0192.168.2.1249712172.67.74.1524436856C:\Users\user\Desktop\duschno.exe
                                                                      TimestampBytes transferredDirectionData
                                                                      2024-12-13 11:41:01 UTC100OUTGET / HTTP/1.1
                                                                      Accept: text/html; text/plain; */*
                                                                      Host: api.ipify.org
                                                                      Cache-Control: no-cache
                                                                      2024-12-13 11:41:01 UTC424INHTTP/1.1 200 OK
                                                                      Date: Fri, 13 Dec 2024 11:41:01 GMT
                                                                      Content-Type: text/plain
                                                                      Content-Length: 12
                                                                      Connection: close
                                                                      Vary: Origin
                                                                      CF-Cache-Status: DYNAMIC
                                                                      Server: cloudflare
                                                                      CF-RAY: 8f15aec4f9e3438c-EWR
                                                                      server-timing: cfL4;desc="?proto=TCP&rtt=1852&min_rtt=1773&rtt_var=823&sent=5&recv=6&lost=0&retrans=0&sent_bytes=2819&recv_bytes=738&delivery_rate=1213128&cwnd=245&unsent_bytes=0&cid=0103bcabd923c7d8&ts=449&x=0"
                                                                      2024-12-13 11:41:01 UTC12INData Raw: 38 2e 34 36 2e 31 32 33 2e 31 38 39
                                                                      Data Ascii: 8.46.123.189


                                                                      Click to jump to process

                                                                      Click to jump to process

                                                                      Click to dive into process behavior distribution

                                                                      Target ID:0
                                                                      Start time:06:40:57
                                                                      Start date:13/12/2024
                                                                      Path:C:\Users\user\Desktop\duschno.exe
                                                                      Wow64 process (32bit):false
                                                                      Commandline:"C:\Users\user\Desktop\duschno.exe"
                                                                      Imagebase:0x7ff6b5320000
                                                                      File size:1'292'800 bytes
                                                                      MD5 hash:C6813DA66EBA357D0DEAA48C2F7032B8
                                                                      Has elevated privileges:true
                                                                      Has administrator privileges:true
                                                                      Programmed in:C, C++ or other language
                                                                      Yara matches:
                                                                      • Rule: JoeSecurity_MeduzaStealer, Description: Yara detected Meduza Stealer, Source: 00000000.00000002.2420918904.000001F3F07AC000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                      Reputation:low
                                                                      Has exited:true

                                                                      Reset < >

                                                                        Execution Graph

                                                                        Execution Coverage:7.1%
                                                                        Dynamic/Decrypted Code Coverage:0%
                                                                        Signature Coverage:17.8%
                                                                        Total number of Nodes:1947
                                                                        Total number of Limit Nodes:95
                                                                        execution_graph 68124 7ff6b538d080 68225 7ff6b534eaf0 68124->68225 68127 7ff6b534eaf0 97 API calls 68128 7ff6b538d954 68127->68128 68141 7ff6b538dd76 _Receive_impl 68128->68141 68231 7ff6b534d4e0 68128->68231 68140 7ff6b538dd3d 68140->68141 68142 7ff6b538ddbd 68140->68142 68275 7ff6b53ce860 68141->68275 68270 7ff6b53b8254 68142->68270 68226 7ff6b534eb21 68225->68226 68284 7ff6b53db5b0 68226->68284 68229 7ff6b53ce860 _Strcoll 8 API calls 68230 7ff6b534ebc2 68229->68230 68230->68127 68232 7ff6b534d509 68231->68232 68332 7ff6b5356940 68232->68332 68234 7ff6b534d59a 68235 7ff6b534d370 68234->68235 68236 7ff6b534d3a0 68235->68236 68369 7ff6b53db260 68236->68369 68239 7ff6b534d43a 68252 7ff6b538fdd0 68239->68252 68240 7ff6b534d489 68383 7ff6b534c160 82 API calls 2 library calls 68240->68383 68243 7ff6b534d48f 68384 7ff6b534c530 82 API calls Concurrency::cancel_current_task 68243->68384 68244 7ff6b534d3f3 68244->68243 68375 7ff6b53627e0 68244->68375 68248 7ff6b534d410 68381 7ff6b53db2d0 WideCharToMultiByte WideCharToMultiByte GetLastError WideCharToMultiByte GetLastError 68248->68381 68250 7ff6b534d42f 68250->68239 68382 7ff6b534c530 82 API calls Concurrency::cancel_current_task 68250->68382 68253 7ff6b538fdf6 68252->68253 68445 7ff6b5390920 68253->68445 68255 7ff6b538d9ab 68256 7ff6b539f8f0 68255->68256 68451 7ff6b539f020 68256->68451 68259 7ff6b539f94a 68261 7ff6b534f380 78 API calls 68259->68261 68262 7ff6b539f9bd 68261->68262 68263 7ff6b53ce860 _Strcoll 8 API calls 68262->68263 68264 7ff6b538da5d 68263->68264 68265 7ff6b534f380 68264->68265 68266 7ff6b534f3c2 _Receive_impl 68265->68266 68267 7ff6b534f394 68265->68267 68266->68140 68267->68266 68268 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 68267->68268 68269 7ff6b534f3e8 68268->68269 68269->68140 69088 7ff6b53b80cc 78 API calls 2 library calls 68270->69088 68272 7ff6b53b826d 69089 7ff6b53b8284 IsProcessorFeaturePresent 68272->69089 68276 7ff6b53ce869 68275->68276 68277 7ff6b538dda1 68276->68277 68278 7ff6b53cec3c IsProcessorFeaturePresent 68276->68278 68279 7ff6b53cec54 68278->68279 69094 7ff6b53cee34 RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind 68279->69094 68281 7ff6b53cec67 69095 7ff6b53cec08 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 68281->69095 68286 7ff6b53db5f2 68284->68286 68285 7ff6b53db5fb 68288 7ff6b53ce860 _Strcoll 8 API calls 68285->68288 68286->68285 68287 7ff6b53db70d 68286->68287 68291 7ff6b53db653 GetFileAttributesExW 68286->68291 68327 7ff6b53db984 CreateFileW GetLastError 68287->68327 68289 7ff6b534eb3d 68288->68289 68289->68229 68293 7ff6b53db667 GetLastError 68291->68293 68294 7ff6b53db6b8 68291->68294 68292 7ff6b53db730 68295 7ff6b53db756 68292->68295 68296 7ff6b53db736 68292->68296 68293->68285 68297 7ff6b53db676 FindFirstFileW 68293->68297 68294->68285 68294->68287 68299 7ff6b53db803 68295->68299 68300 7ff6b53db765 GetFileInformationByHandleEx 68295->68300 68298 7ff6b53db741 CloseHandle 68296->68298 68319 7ff6b53db74f 68296->68319 68301 7ff6b53db695 FindClose 68297->68301 68302 7ff6b53db68a GetLastError 68297->68302 68303 7ff6b53db8c5 68298->68303 68298->68319 68304 7ff6b53db81e GetFileInformationByHandleEx 68299->68304 68305 7ff6b53db858 68299->68305 68306 7ff6b53db7a5 68300->68306 68307 7ff6b53db77f GetLastError 68300->68307 68301->68294 68302->68285 68328 7ff6b53b98b4 78 API calls BuildCatchObjectHelperInternal 68303->68328 68304->68305 68309 7ff6b53db834 GetLastError 68304->68309 68311 7ff6b53db86f 68305->68311 68312 7ff6b53db8ab 68305->68312 68306->68299 68318 7ff6b53db7c6 GetFileInformationByHandleEx 68306->68318 68310 7ff6b53db78d CloseHandle 68307->68310 68307->68319 68315 7ff6b53db846 CloseHandle 68309->68315 68309->68319 68316 7ff6b53db8d6 68310->68316 68310->68319 68311->68285 68317 7ff6b53db875 CloseHandle 68311->68317 68313 7ff6b53db8b1 CloseHandle 68312->68313 68312->68319 68313->68303 68313->68319 68314 7ff6b53db8ca 68329 7ff6b53b98b4 78 API calls BuildCatchObjectHelperInternal 68314->68329 68315->68319 68320 7ff6b53db8d0 68315->68320 68331 7ff6b53b98b4 78 API calls BuildCatchObjectHelperInternal 68316->68331 68317->68285 68317->68303 68318->68299 68322 7ff6b53db7e2 GetLastError 68318->68322 68319->68285 68330 7ff6b53b98b4 78 API calls BuildCatchObjectHelperInternal 68320->68330 68322->68319 68326 7ff6b53db7f0 CloseHandle 68322->68326 68326->68314 68326->68319 68327->68292 68334 7ff6b5356966 68332->68334 68344 7ff6b5356a64 68332->68344 68336 7ff6b5356a5f 68334->68336 68339 7ff6b53569ca 68334->68339 68340 7ff6b5356a22 68334->68340 68346 7ff6b5356971 BuildCatchObjectHelperInternal 68334->68346 68356 7ff6b534b820 82 API calls 2 library calls 68336->68356 68337 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 68342 7ff6b5356a70 68337->68342 68339->68336 68341 7ff6b53569d7 68339->68341 68343 7ff6b53ce888 std::_Facet_Register 82 API calls 68340->68343 68347 7ff6b53ce888 68341->68347 68343->68346 68357 7ff6b534b8e0 82 API calls 68344->68357 68346->68234 68348 7ff6b53ce893 68347->68348 68349 7ff6b53569df 68348->68349 68351 7ff6b53ce8b2 68348->68351 68358 7ff6b53c9f1c 68348->68358 68349->68337 68349->68346 68352 7ff6b53ce8bd 68351->68352 68361 7ff6b53cf8dc RtlPcToFileHeader RaiseException Concurrency::cancel_current_task std::bad_alloc::bad_alloc 68351->68361 68362 7ff6b534b820 82 API calls 2 library calls 68352->68362 68355 7ff6b53ce8c3 68356->68344 68363 7ff6b53c9f5c 68358->68363 68362->68355 68368 7ff6b53bc3bc EnterCriticalSection 68363->68368 68385 7ff6b53c69a4 68369->68385 68372 7ff6b53db272 AreFileApisANSI 68373 7ff6b534d3ac 68372->68373 68373->68239 68373->68240 68374 7ff6b53db2d0 WideCharToMultiByte WideCharToMultiByte GetLastError WideCharToMultiByte GetLastError 68373->68374 68374->68244 68376 7ff6b53627ed 68375->68376 68377 7ff6b5362804 68375->68377 68376->68248 68379 7ff6b536281e memcpy_s 68377->68379 68428 7ff6b5368e80 68377->68428 68379->68248 68380 7ff6b536286c 68380->68248 68381->68250 68383->68243 68390 7ff6b53b9eec GetLastError 68385->68390 68391 7ff6b53b9f10 FlsGetValue 68390->68391 68392 7ff6b53b9f2d FlsSetValue 68390->68392 68393 7ff6b53b9f27 68391->68393 68394 7ff6b53b9f1d 68391->68394 68392->68394 68395 7ff6b53b9f3f 68392->68395 68393->68392 68396 7ff6b53b9f99 SetLastError 68394->68396 68417 7ff6b53bda30 11 API calls 3 library calls 68395->68417 68398 7ff6b53b9fb9 68396->68398 68399 7ff6b53b9fa6 68396->68399 68425 7ff6b53b98b4 78 API calls BuildCatchObjectHelperInternal 68398->68425 68413 7ff6b53bc178 68399->68413 68400 7ff6b53b9f4e 68402 7ff6b53b9f6c FlsSetValue 68400->68402 68403 7ff6b53b9f5c FlsSetValue 68400->68403 68406 7ff6b53b9f78 FlsSetValue 68402->68406 68407 7ff6b53b9f8a 68402->68407 68405 7ff6b53b9f65 68403->68405 68418 7ff6b53bd3c8 68405->68418 68406->68405 68424 7ff6b53b9c9c 11 API calls _Getctype 68407->68424 68410 7ff6b53b9f92 68412 7ff6b53bd3c8 __free_lconv_mon 11 API calls 68410->68412 68412->68396 68414 7ff6b53bc1a0 68413->68414 68415 7ff6b53bc18d 68413->68415 68414->68372 68414->68373 68415->68414 68427 7ff6b53c5c14 78 API calls 3 library calls 68415->68427 68417->68400 68419 7ff6b53bd3cd RtlFreeHeap 68418->68419 68420 7ff6b53b9f6a 68418->68420 68419->68420 68421 7ff6b53bd3e8 GetLastError 68419->68421 68420->68394 68422 7ff6b53bd3f5 __free_lconv_mon 68421->68422 68426 7ff6b53b4e68 11 API calls memcpy_s 68422->68426 68424->68410 68426->68420 68427->68414 68429 7ff6b536900f 68428->68429 68433 7ff6b5368eaf 68428->68433 68443 7ff6b534b8e0 82 API calls 68429->68443 68431 7ff6b5368f19 68434 7ff6b53ce888 std::_Facet_Register 82 API calls 68431->68434 68432 7ff6b5369014 68444 7ff6b534b820 82 API calls 2 library calls 68432->68444 68433->68431 68436 7ff6b5368f0c 68433->68436 68437 7ff6b5368f48 68433->68437 68439 7ff6b5368eff memcpy_s BuildCatchObjectHelperInternal 68433->68439 68434->68439 68436->68431 68436->68432 68438 7ff6b53ce888 std::_Facet_Register 82 API calls 68437->68438 68438->68439 68440 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 68439->68440 68442 7ff6b5368fbe memcpy_s _Receive_impl BuildCatchObjectHelperInternal 68439->68442 68441 7ff6b5369020 68440->68441 68442->68380 68444->68439 68446 7ff6b53909e5 68445->68446 68449 7ff6b5390950 BuildCatchObjectHelperInternal 68445->68449 68450 7ff6b53945c0 83 API calls 5 library calls 68446->68450 68448 7ff6b53909fa 68448->68255 68449->68255 68450->68448 68452 7ff6b534eaf0 97 API calls 68451->68452 68455 7ff6b539f06f memcpy_s 68452->68455 68453 7ff6b539f0a7 68454 7ff6b539f7bf 68453->68454 68494 7ff6b539f0af 68453->68494 68608 7ff6b534e240 87 API calls Concurrency::cancel_current_task 68454->68608 68455->68453 68455->68494 68514 7ff6b536a910 68455->68514 68457 7ff6b539f7d6 68461 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 68457->68461 68458 7ff6b53ce860 _Strcoll 8 API calls 68459 7ff6b539f751 68458->68459 68459->68259 68509 7ff6b5365310 68459->68509 68467 7ff6b539f7dc 68461->68467 68462 7ff6b539f0ee 68463 7ff6b539f151 68462->68463 68464 7ff6b539f545 68462->68464 68596 7ff6b53a9b70 30 API calls 2 library calls 68463->68596 68531 7ff6b537fdb0 68464->68531 68609 7ff6b534cdc0 82 API calls 68467->68609 68472 7ff6b539f163 68597 7ff6b53a9d30 98 API calls 6 library calls 68472->68597 68473 7ff6b539f800 68476 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 68473->68476 68481 7ff6b539f811 68476->68481 68477 7ff6b539f597 68483 7ff6b537fdb0 84 API calls 68477->68483 68478 7ff6b539f174 68479 7ff6b539f187 68478->68479 68480 7ff6b539f25c GetFileSize 68478->68480 68479->68457 68484 7ff6b539f1ce _Receive_impl 68479->68484 68485 7ff6b539f29d 68480->68485 68490 7ff6b539f278 memcpy_s 68480->68490 68486 7ff6b539f5aa 68483->68486 68598 7ff6b53612f0 82 API calls 68484->68598 68485->68490 68493 7ff6b5368e80 82 API calls 68485->68493 68576 7ff6b53ad640 68486->68576 68489 7ff6b539f302 SetFilePointer ReadFile 68501 7ff6b539f351 68489->68501 68503 7ff6b539f462 68489->68503 68490->68489 68492 7ff6b539f21f 68492->68494 68493->68489 68494->68458 68497 7ff6b539f3d4 _Receive_impl 68599 7ff6b53612f0 82 API calls 68497->68599 68498 7ff6b539f4b7 _Receive_impl 68600 7ff6b53612f0 82 API calls 68498->68600 68500 7ff6b539f66d 68601 7ff6b53612f0 82 API calls 68500->68601 68501->68457 68501->68497 68503->68457 68503->68498 68505 7ff6b539f76c 68602 7ff6b534cdc0 82 API calls 68505->68602 68507 7ff6b539f7ae 68603 7ff6b53d0e88 68507->68603 68510 7ff6b53627e0 82 API calls 68509->68510 68511 7ff6b536537a 68510->68511 68512 7ff6b53627e0 82 API calls 68511->68512 68513 7ff6b536548d 68512->68513 68513->68259 68610 7ff6b5364ab0 68514->68610 68521 7ff6b536aa1f 68636 7ff6b5363520 78 API calls _Strcoll 68521->68636 68522 7ff6b536aaa8 68530 7ff6b536aa58 68522->68530 68638 7ff6b534cdc0 82 API calls 68522->68638 68524 7ff6b536aa31 68637 7ff6b53678a0 115 API calls 4 library calls 68524->68637 68526 7ff6b536ab12 68528 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 68526->68528 68529 7ff6b536ab23 68528->68529 68530->68462 68532 7ff6b537fef3 68531->68532 68534 7ff6b537fe0d 68531->68534 68886 7ff6b534cdc0 82 API calls 68532->68886 68862 7ff6b5380bd0 68534->68862 68535 7ff6b537fe32 68540 7ff6b537fe69 68535->68540 68876 7ff6b53608a0 68535->68876 68536 7ff6b537fec0 68546 7ff6b537fcd0 68536->68546 68538 7ff6b537ff35 68539 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 68538->68539 68539->68540 68540->68536 68887 7ff6b534cdc0 82 API calls 68540->68887 68542 7ff6b537ff8e 68543 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 68542->68543 68544 7ff6b537ffa2 68543->68544 68547 7ff6b537fd00 68546->68547 68548 7ff6b5380bd0 82 API calls 68547->68548 68549 7ff6b537fd0f 68548->68549 68549->68477 68550 7ff6b5368560 68549->68550 68551 7ff6b536869a 68550->68551 68555 7ff6b5368589 68550->68555 68986 7ff6b534b8e0 82 API calls 68551->68986 68553 7ff6b53685ee 68556 7ff6b53ce888 std::_Facet_Register 82 API calls 68553->68556 68554 7ff6b536869f 68987 7ff6b534b820 82 API calls 2 library calls 68554->68987 68555->68553 68558 7ff6b536861d 68555->68558 68559 7ff6b53685e1 68555->68559 68562 7ff6b53685d4 BuildCatchObjectHelperInternal 68555->68562 68556->68562 68560 7ff6b53ce888 std::_Facet_Register 82 API calls 68558->68560 68559->68553 68559->68554 68560->68562 68561 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 68564 7ff6b53686ab 68561->68564 68562->68561 68563 7ff6b5368667 _Receive_impl BuildCatchObjectHelperInternal 68562->68563 68563->68477 68565 7ff6b536870c 68564->68565 68567 7ff6b536875a 68564->68567 68568 7ff6b5368765 68564->68568 68572 7ff6b53686dc BuildCatchObjectHelperInternal 68564->68572 68566 7ff6b53ce888 std::_Facet_Register 82 API calls 68565->68566 68569 7ff6b5368722 68566->68569 68567->68565 68570 7ff6b536879f 68567->68570 68571 7ff6b53ce888 std::_Facet_Register 82 API calls 68568->68571 68569->68572 68574 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 68569->68574 68988 7ff6b534b820 82 API calls 2 library calls 68570->68988 68571->68572 68572->68477 68575 7ff6b53687aa 68574->68575 68575->68477 68577 7ff6b53ad69d 68576->68577 68579 7ff6b53ad6b7 68576->68579 68577->68579 68989 7ff6b5360ca0 68577->68989 68578 7ff6b53ad75a 68584 7ff6b53ad765 68578->68584 69023 7ff6b5364600 68578->69023 68579->68578 69010 7ff6b53af150 68579->69010 68582 7ff6b53ad7ea _Receive_impl 68583 7ff6b53ce860 _Strcoll 8 API calls 68582->68583 68585 7ff6b539f60d 68583->68585 68584->68582 68586 7ff6b53ad829 68584->68586 68585->68467 68590 7ff6b5363620 68585->68590 68587 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 68586->68587 68588 7ff6b53ad82e 68587->68588 68591 7ff6b536368a 68590->68591 68592 7ff6b536363a 68590->68592 68591->68500 68591->68505 68593 7ff6b5363430 79 API calls 68592->68593 68594 7ff6b5363674 68593->68594 68595 7ff6b53b3818 81 API calls 68594->68595 68595->68591 68596->68472 68597->68478 68598->68492 68599->68492 68600->68492 68601->68494 68602->68507 68604 7ff6b53d0ea7 68603->68604 68605 7ff6b53d0ef2 RaiseException 68604->68605 68606 7ff6b53d0ed0 RtlPcToFileHeader 68604->68606 68605->68454 68607 7ff6b53d0ee8 68606->68607 68607->68605 68609->68473 68611 7ff6b53ce888 std::_Facet_Register 82 API calls 68610->68611 68612 7ff6b5364b11 68611->68612 68639 7ff6b53dc5ec 68612->68639 68614 7ff6b5364b21 68648 7ff6b5364e10 68614->68648 68617 7ff6b5364bae 68618 7ff6b5364bbb 68617->68618 68663 7ff6b53dc8b8 6 API calls std::_Lockit::_Lockit 68617->68663 68625 7ff6b536c3b0 68618->68625 68620 7ff6b5364bd6 68664 7ff6b534cdc0 82 API calls 68620->68664 68622 7ff6b5364c16 68623 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 68622->68623 68624 7ff6b5364c27 68623->68624 68676 7ff6b5364500 68625->68676 68628 7ff6b53dcb28 68629 7ff6b53dcb6e 68628->68629 68631 7ff6b536aa16 68629->68631 68681 7ff6b53de200 68629->68681 68631->68521 68631->68522 68634 7ff6b53dcbbc 68634->68631 68701 7ff6b53b3818 68634->68701 68636->68524 68637->68530 68638->68526 68665 7ff6b53dbf8c 68639->68665 68641 7ff6b53dc60e 68647 7ff6b53dc652 BuildCatchObjectHelperInternal 68641->68647 68669 7ff6b53dc7e4 82 API calls std::_Facet_Register 68641->68669 68643 7ff6b53dc626 68670 7ff6b53dc814 79 API calls std::locale::_Setgloballocale 68643->68670 68645 7ff6b53dc631 68645->68647 68671 7ff6b53b7620 13 API calls 2 library calls 68645->68671 68647->68614 68649 7ff6b53dbf8c std::_Lockit::_Lockit 6 API calls 68648->68649 68650 7ff6b5364e40 68649->68650 68651 7ff6b53dbf8c std::_Lockit::_Lockit 6 API calls 68650->68651 68653 7ff6b5364e65 68650->68653 68651->68653 68652 7ff6b5364edd 68654 7ff6b53ce860 _Strcoll 8 API calls 68652->68654 68653->68652 68673 7ff6b534ca60 121 API calls 5 library calls 68653->68673 68655 7ff6b5364b52 68654->68655 68655->68617 68655->68620 68657 7ff6b5364eef 68658 7ff6b5364f56 68657->68658 68659 7ff6b5364ef5 68657->68659 68675 7ff6b534c5a0 82 API calls 2 library calls 68658->68675 68674 7ff6b53dc5ac 82 API calls std::_Facet_Register 68659->68674 68662 7ff6b5364f5b 68663->68618 68664->68622 68666 7ff6b53dbfa0 68665->68666 68667 7ff6b53dbf9b 68665->68667 68666->68641 68672 7ff6b53bc42c 6 API calls std::_Locinfo::_Locinfo_ctor 68667->68672 68669->68643 68670->68645 68671->68647 68673->68657 68674->68652 68675->68662 68677 7ff6b53ce888 std::_Facet_Register 82 API calls 68676->68677 68678 7ff6b5364577 68677->68678 68679 7ff6b53dc5ec 89 API calls 68678->68679 68680 7ff6b5364587 68679->68680 68680->68522 68680->68628 68682 7ff6b53de12c 68681->68682 68683 7ff6b53de152 68682->68683 68686 7ff6b53de185 68682->68686 68721 7ff6b53b4e68 11 API calls memcpy_s 68683->68721 68685 7ff6b53de157 68722 7ff6b53b8234 78 API calls _invalid_parameter_noinfo 68685->68722 68688 7ff6b53de18b 68686->68688 68689 7ff6b53de198 68686->68689 68723 7ff6b53b4e68 11 API calls memcpy_s 68688->68723 68709 7ff6b53bd6a8 68689->68709 68693 7ff6b53dcba1 68693->68631 68700 7ff6b53b7e14 78 API calls ProcessCodePage 68693->68700 68700->68634 68702 7ff6b53b3848 68701->68702 68848 7ff6b53b36f4 68702->68848 68704 7ff6b53b3861 68705 7ff6b53b3886 68704->68705 68858 7ff6b53af864 78 API calls 2 library calls 68704->68858 68707 7ff6b53b389b 68705->68707 68859 7ff6b53af864 78 API calls 2 library calls 68705->68859 68707->68631 68726 7ff6b53bc3bc EnterCriticalSection 68709->68726 68721->68685 68722->68693 68723->68693 68849 7ff6b53b370f 68848->68849 68850 7ff6b53b373d 68848->68850 68861 7ff6b53b8168 78 API calls 2 library calls 68849->68861 68853 7ff6b53b372f 68850->68853 68860 7ff6b53b4934 EnterCriticalSection 68850->68860 68853->68704 68858->68705 68859->68707 68861->68853 68863 7ff6b5380c10 68862->68863 68867 7ff6b5380bed 68862->68867 68865 7ff6b5380c1e 68863->68865 68888 7ff6b536af10 68863->68888 68864 7ff6b5380c0a 68864->68535 68865->68535 68867->68864 68912 7ff6b534cdc0 82 API calls 68867->68912 68869 7ff6b5380c73 68870 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 68869->68870 68875 7ff6b5380c84 _Receive_impl 68870->68875 68871 7ff6b5380de5 68871->68535 68872 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 68873 7ff6b5380f37 68872->68873 68913 7ff6b537f640 82 API calls BuildCatchObjectHelperInternal 68873->68913 68875->68871 68875->68872 68877 7ff6b53608d3 68876->68877 68885 7ff6b536092b 68877->68885 68919 7ff6b5363430 68877->68919 68879 7ff6b53ce860 _Strcoll 8 API calls 68881 7ff6b5360999 68879->68881 68880 7ff6b53608f6 68883 7ff6b5360916 68880->68883 68880->68885 68929 7ff6b53b7d7c 68880->68929 68881->68540 68883->68885 68937 7ff6b53b7374 68883->68937 68885->68879 68886->68538 68887->68542 68889 7ff6b536afd0 68888->68889 68890 7ff6b536af4e 68888->68890 68891 7ff6b53ce860 _Strcoll 8 API calls 68889->68891 68914 7ff6b5369f00 82 API calls 68890->68914 68893 7ff6b536affd 68891->68893 68893->68865 68894 7ff6b536af5b 68895 7ff6b536afbd 68894->68895 68897 7ff6b536b012 68894->68897 68895->68889 68915 7ff6b536c530 82 API calls 2 library calls 68895->68915 68916 7ff6b534cdc0 82 API calls 68897->68916 68899 7ff6b536b054 68900 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 68899->68900 68901 7ff6b536b065 68900->68901 68902 7ff6b536af10 82 API calls 68901->68902 68903 7ff6b536b0bb 68901->68903 68902->68903 68904 7ff6b536b1c8 68903->68904 68906 7ff6b536b18a 68903->68906 68918 7ff6b534cdc0 82 API calls 68904->68918 68905 7ff6b536b19b 68905->68865 68906->68905 68917 7ff6b536c530 82 API calls 2 library calls 68906->68917 68909 7ff6b536b20a 68910 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 68909->68910 68911 7ff6b536b21b 68910->68911 68912->68869 68914->68894 68915->68889 68916->68899 68917->68905 68918->68909 68920 7ff6b5363453 68919->68920 68921 7ff6b5363502 68919->68921 68920->68921 68927 7ff6b536345d 68920->68927 68922 7ff6b53ce860 _Strcoll 8 API calls 68921->68922 68923 7ff6b5363511 68922->68923 68923->68880 68924 7ff6b53634a1 68925 7ff6b53ce860 _Strcoll 8 API calls 68924->68925 68926 7ff6b53634be 68925->68926 68926->68880 68927->68924 68946 7ff6b53b4cf0 79 API calls ProcessCodePage 68927->68946 68930 7ff6b53b7dac 68929->68930 68947 7ff6b53b7b0c 68930->68947 68933 7ff6b53b7dea 68935 7ff6b53b7dff 68933->68935 68959 7ff6b53af864 78 API calls 2 library calls 68933->68959 68935->68883 68938 7ff6b53b7388 68937->68938 68939 7ff6b53b739d 68937->68939 68970 7ff6b53b4e68 11 API calls memcpy_s 68938->68970 68939->68938 68941 7ff6b53b73a2 68939->68941 68962 7ff6b53c0274 68941->68962 68942 7ff6b53b738d 68971 7ff6b53b8234 78 API calls _invalid_parameter_noinfo 68942->68971 68945 7ff6b53b7398 68945->68885 68946->68924 68948 7ff6b53b7b76 68947->68948 68949 7ff6b53b7b36 68947->68949 68948->68949 68951 7ff6b53b7b82 68948->68951 68961 7ff6b53b8168 78 API calls 2 library calls 68949->68961 68960 7ff6b53b4934 EnterCriticalSection 68951->68960 68953 7ff6b53b7b5d 68953->68933 68958 7ff6b53af864 78 API calls 2 library calls 68953->68958 68958->68933 68959->68935 68961->68953 68963 7ff6b53c02a4 68962->68963 68972 7ff6b53bfd80 68963->68972 68966 7ff6b53c02e3 68967 7ff6b53c02f8 68966->68967 68983 7ff6b53af864 78 API calls 2 library calls 68966->68983 68967->68945 68970->68942 68971->68945 68973 7ff6b53bfd9b 68972->68973 68974 7ff6b53bfdca 68972->68974 68985 7ff6b53b8168 78 API calls 2 library calls 68973->68985 68984 7ff6b53b4934 EnterCriticalSection 68974->68984 68977 7ff6b53bfdbb 68977->68966 68982 7ff6b53af864 78 API calls 2 library calls 68977->68982 68982->68966 68983->68967 68985->68977 68987->68562 68988->68569 68990 7ff6b5360cdd 68989->68990 68992 7ff6b5360d73 68990->68992 68993 7ff6b5360d51 68990->68993 68997 7ff6b5360ced _Receive_impl 68990->68997 68991 7ff6b53ce860 _Strcoll 8 API calls 68995 7ff6b5360f1f 68991->68995 68994 7ff6b53b4648 78 API calls 68992->68994 69038 7ff6b53b4648 68993->69038 69004 7ff6b5360da1 BuildCatchObjectHelperInternal 68994->69004 68995->68579 68997->68991 68998 7ff6b5360ec1 68998->68997 69000 7ff6b5360fa7 68998->69000 69001 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69000->69001 69002 7ff6b5360fac 69001->69002 69003 7ff6b5360fd4 69002->69003 69009 7ff6b5360ca0 82 API calls 69002->69009 69003->68579 69004->68998 69006 7ff6b53b4648 78 API calls 69004->69006 69008 7ff6b5360f57 69004->69008 69059 7ff6b5368d10 69004->69059 69005 7ff6b5360feb 69005->68579 69006->69004 69008->68998 69074 7ff6b53b7754 78 API calls 3 library calls 69008->69074 69009->69005 69080 7ff6b53af080 69010->69080 69012 7ff6b53af362 69012->68578 69013 7ff6b53af399 69084 7ff6b534b8e0 82 API calls 69013->69084 69015 7ff6b53af39f 69085 7ff6b534b820 82 API calls 2 library calls 69015->69085 69017 7ff6b53af080 82 API calls 69022 7ff6b53af18c _Receive_impl BuildCatchObjectHelperInternal 69017->69022 69018 7ff6b53af3a5 69019 7ff6b53af394 69021 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69019->69021 69020 7ff6b53ce888 82 API calls std::_Facet_Register 69020->69022 69021->69013 69022->69012 69022->69013 69022->69015 69022->69017 69022->69019 69022->69020 69026 7ff6b536461d BuildCatchObjectHelperInternal 69023->69026 69027 7ff6b5364647 69023->69027 69025 7ff6b5364750 69087 7ff6b534b820 82 API calls 2 library calls 69025->69087 69026->68584 69030 7ff6b53646d9 69027->69030 69033 7ff6b53646a1 69027->69033 69034 7ff6b5364693 BuildCatchObjectHelperInternal 69027->69034 69036 7ff6b536474a 69027->69036 69028 7ff6b53ce888 std::_Facet_Register 82 API calls 69028->69034 69031 7ff6b53ce888 std::_Facet_Register 82 API calls 69030->69031 69031->69034 69032 7ff6b5364756 69033->69025 69033->69028 69035 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69034->69035 69037 7ff6b5364727 _Receive_impl 69034->69037 69035->69036 69086 7ff6b534b8e0 82 API calls 69036->69086 69037->68584 69039 7ff6b53b4664 69038->69039 69040 7ff6b53b4682 69038->69040 69076 7ff6b53b4e68 11 API calls memcpy_s 69039->69076 69075 7ff6b53b4934 EnterCriticalSection 69040->69075 69043 7ff6b53b4669 69077 7ff6b53b8234 78 API calls _invalid_parameter_noinfo 69043->69077 69046 7ff6b53b4674 69046->68997 69060 7ff6b5368e65 69059->69060 69064 7ff6b5368d3f 69059->69064 69078 7ff6b534b8e0 82 API calls 69060->69078 69062 7ff6b5368da4 69065 7ff6b53ce888 std::_Facet_Register 82 API calls 69062->69065 69063 7ff6b5368e6a 69079 7ff6b534b820 82 API calls 2 library calls 69063->69079 69064->69062 69067 7ff6b5368d97 69064->69067 69068 7ff6b5368dd3 69064->69068 69071 7ff6b5368d8a BuildCatchObjectHelperInternal 69064->69071 69065->69071 69067->69062 69067->69063 69069 7ff6b53ce888 std::_Facet_Register 82 API calls 69068->69069 69069->69071 69070 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69072 7ff6b5368e76 69070->69072 69071->69070 69073 7ff6b5368e26 _Receive_impl BuildCatchObjectHelperInternal 69071->69073 69073->69004 69074->69008 69076->69043 69077->69046 69079->69071 69081 7ff6b53af096 69080->69081 69082 7ff6b53af0b3 69080->69082 69081->69082 69083 7ff6b5360ca0 82 API calls 69081->69083 69082->69022 69083->69082 69085->69018 69087->69032 69088->68272 69090 7ff6b53b8297 69089->69090 69093 7ff6b53b7f68 14 API calls 3 library calls 69090->69093 69092 7ff6b53b82b2 GetCurrentProcess TerminateProcess 69093->69092 69094->68281 69096 7ff6b537213a 69234 7ff6b537a490 69096->69234 69098 7ff6b537265d 69444 7ff6b536c4d0 69098->69444 69100 7ff6b5372b14 69101 7ff6b53ce860 _Strcoll 8 API calls 69100->69101 69102 7ff6b5372b26 69101->69102 69103 7ff6b536c600 82 API calls 69118 7ff6b5372149 69103->69118 69104 7ff6b5372388 69252 7ff6b536c600 69104->69252 69105 7ff6b5371fae 69109 7ff6b536c600 82 API calls 69105->69109 69107 7ff6b53723d4 69115 7ff6b536b780 84 API calls 69107->69115 69108 7ff6b5372662 69113 7ff6b536b780 84 API calls 69108->69113 69122 7ff6b5371fb6 69109->69122 69110 7ff6b5372390 69111 7ff6b53727cc 69110->69111 69112 7ff6b537239c 69110->69112 69123 7ff6b536b780 84 API calls 69111->69123 69270 7ff6b5374580 69112->69270 69116 7ff6b53726a2 69113->69116 69119 7ff6b53725ed 69115->69119 69121 7ff6b5371af0 84 API calls 69116->69121 69117 7ff6b53723b4 69124 7ff6b536c600 82 API calls 69117->69124 69118->69098 69118->69103 69118->69104 69118->69105 69118->69107 69118->69108 69125 7ff6b53749c0 82 API calls 69118->69125 69120 7ff6b5371af0 84 API calls 69119->69120 69126 7ff6b5372613 69120->69126 69127 7ff6b53726c8 69121->69127 69282 7ff6b536b780 69122->69282 69129 7ff6b537280c 69123->69129 69130 7ff6b53723c0 69124->69130 69125->69118 69131 7ff6b536bd00 84 API calls 69126->69131 69132 7ff6b536bd00 84 API calls 69127->69132 69134 7ff6b5371af0 84 API calls 69129->69134 69135 7ff6b53723cc 69130->69135 69136 7ff6b5372717 69130->69136 69137 7ff6b5372623 69131->69137 69138 7ff6b53726d8 69132->69138 69133 7ff6b537241c 69338 7ff6b5371af0 69133->69338 69140 7ff6b5372832 69134->69140 69141 7ff6b536c600 82 API calls 69135->69141 69149 7ff6b536b780 84 API calls 69136->69149 69142 7ff6b5372632 69137->69142 69143 7ff6b5372bb0 69137->69143 69144 7ff6b53726e7 69138->69144 69145 7ff6b5372bcd 69138->69145 69147 7ff6b536bd00 84 API calls 69140->69147 69141->69107 69150 7ff6b5362880 78 API calls 69142->69150 69452 7ff6b5363e90 80 API calls 69143->69452 69152 7ff6b5362880 78 API calls 69144->69152 69453 7ff6b5363e90 80 API calls 69145->69453 69146 7ff6b5372442 69426 7ff6b536bd00 69146->69426 69154 7ff6b5372842 69147->69154 69156 7ff6b5372757 69149->69156 69157 7ff6b537263e 69150->69157 69159 7ff6b53726f3 69152->69159 69161 7ff6b5372c07 69154->69161 69162 7ff6b5372851 69154->69162 69155 7ff6b5372bbd 69163 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69155->69163 69164 7ff6b5371af0 84 API calls 69156->69164 69165 7ff6b534eec0 13 API calls 69157->69165 69158 7ff6b5372bda 69166 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69158->69166 69167 7ff6b534eec0 13 API calls 69159->69167 69455 7ff6b5363e90 80 API calls 69161->69455 69170 7ff6b5362880 78 API calls 69162->69170 69163->69145 69174 7ff6b537277d 69164->69174 69175 7ff6b5372648 69165->69175 69176 7ff6b5372bea 69166->69176 69177 7ff6b53726fd 69167->69177 69168 7ff6b5372b5a 69449 7ff6b5363e90 80 API calls 69168->69449 69169 7ff6b5372461 69434 7ff6b5362880 69169->69434 69179 7ff6b537285d 69170->69179 69172 7ff6b5372c14 69180 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69172->69180 69182 7ff6b536bd00 84 API calls 69174->69182 69183 7ff6b5362880 78 API calls 69175->69183 69454 7ff6b5363e90 80 API calls 69176->69454 69184 7ff6b5362880 78 API calls 69177->69184 69186 7ff6b534eec0 13 API calls 69179->69186 69187 7ff6b5372c24 69180->69187 69181 7ff6b5372b66 69188 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69181->69188 69189 7ff6b537278d 69182->69189 69190 7ff6b5372652 69183->69190 69192 7ff6b5372707 69184->69192 69185 7ff6b537246b 69439 7ff6b534eec0 69185->69439 69194 7ff6b5372867 69186->69194 69456 7ff6b5363e90 80 API calls 69187->69456 69196 7ff6b5372b76 69188->69196 69189->69176 69197 7ff6b537279c 69189->69197 69198 7ff6b5362880 78 API calls 69190->69198 69200 7ff6b5362880 78 API calls 69192->69200 69202 7ff6b5362880 78 API calls 69194->69202 69450 7ff6b5363e90 80 API calls 69196->69450 69207 7ff6b5362880 78 API calls 69197->69207 69198->69098 69199 7ff6b5372bf7 69208 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69199->69208 69200->69098 69204 7ff6b5372871 69202->69204 69203 7ff6b5362880 78 API calls 69209 7ff6b537247f 69203->69209 69210 7ff6b5362880 78 API calls 69204->69210 69205 7ff6b5372c31 69211 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69205->69211 69213 7ff6b53727a8 69207->69213 69208->69161 69220 7ff6b5362880 78 API calls 69209->69220 69210->69098 69214 7ff6b5372c41 69211->69214 69212 7ff6b5372b83 69215 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69212->69215 69216 7ff6b534eec0 13 API calls 69213->69216 69457 7ff6b5363e90 80 API calls 69214->69457 69218 7ff6b5372b93 69215->69218 69219 7ff6b53727b2 69216->69219 69451 7ff6b5374430 80 API calls 69218->69451 69223 7ff6b5362880 78 API calls 69219->69223 69220->69098 69221 7ff6b5372c4e 69224 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69221->69224 69226 7ff6b53727bc 69223->69226 69227 7ff6b5372c5e 69224->69227 69225 7ff6b5372ba0 69228 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69225->69228 69229 7ff6b5362880 78 API calls 69226->69229 69458 7ff6b5363e90 80 API calls 69227->69458 69228->69143 69229->69098 69231 7ff6b5372c6b 69232 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69231->69232 69233 7ff6b5372c7b 69232->69233 69235 7ff6b537a515 69234->69235 69236 7ff6b537a4af 69234->69236 69238 7ff6b537a581 69235->69238 69239 7ff6b537a51e 69235->69239 69237 7ff6b537d590 82 API calls 69236->69237 69241 7ff6b537a4cd 69237->69241 69459 7ff6b537d590 69238->69459 69242 7ff6b537a52c 69239->69242 69243 7ff6b537a54f 69239->69243 69468 7ff6b5363ff0 69241->69468 69246 7ff6b537d590 82 API calls 69242->69246 69500 7ff6b5381d30 82 API calls 3 library calls 69243->69500 69250 7ff6b537a547 69246->69250 69248 7ff6b5363ff0 82 API calls 69251 7ff6b537a5d5 69248->69251 69250->69118 69251->69118 69253 7ff6b536c623 69252->69253 69257 7ff6b536c670 69252->69257 69527 7ff6b536e200 69253->69527 69255 7ff6b536e200 82 API calls 69255->69257 69256 7ff6b536c628 69256->69257 69258 7ff6b536e200 82 API calls 69256->69258 69257->69255 69269 7ff6b536c6c3 69257->69269 69259 7ff6b536c637 69258->69259 69260 7ff6b536c64d 69259->69260 69261 7ff6b536e200 82 API calls 69259->69261 69262 7ff6b53ce860 _Strcoll 8 API calls 69260->69262 69263 7ff6b536c646 69261->69263 69264 7ff6b536c66a 69262->69264 69263->69257 69263->69260 69264->69110 69265 7ff6b536c7c8 69266 7ff6b53ce860 _Strcoll 8 API calls 69265->69266 69267 7ff6b536c91b 69266->69267 69267->69110 69268 7ff6b536e200 82 API calls 69268->69269 69269->69265 69269->69268 69273 7ff6b53745a5 69270->69273 69271 7ff6b53745d8 69274 7ff6b53ce888 std::_Facet_Register 82 API calls 69271->69274 69272 7ff6b5374681 69571 7ff6b534b9e0 82 API calls 69272->69571 69273->69271 69273->69272 69281 7ff6b5374630 69273->69281 69276 7ff6b53745fc 69274->69276 69278 7ff6b53629b0 82 API calls 69276->69278 69279 7ff6b5374618 69278->69279 69561 7ff6b53637f0 69279->69561 69281->69117 69283 7ff6b536b7ce 69282->69283 69284 7ff6b536b81e 69283->69284 69286 7ff6b5368560 82 API calls 69283->69286 69305 7ff6b536b8ac _Receive_impl 69283->69305 69287 7ff6b5363d70 82 API calls 69284->69287 69286->69284 69289 7ff6b536b838 69287->69289 69288 7ff6b536b912 69290 7ff6b536b91e 69288->69290 69293 7ff6b536bad1 69288->69293 69292 7ff6b5363d70 82 API calls 69289->69292 69291 7ff6b536bd00 84 API calls 69290->69291 69298 7ff6b536b92b 69291->69298 69294 7ff6b536b852 69292->69294 69293->69293 69299 7ff6b536bb2d 69293->69299 69302 7ff6b5368560 82 API calls 69293->69302 69295 7ff6b536b85f 69294->69295 69296 7ff6b5368d10 82 API calls 69294->69296 69300 7ff6b5363d70 82 API calls 69295->69300 69296->69295 69297 7ff6b536b987 69306 7ff6b5363d70 82 API calls 69297->69306 69298->69297 69301 7ff6b5368560 82 API calls 69298->69301 69303 7ff6b5363d70 82 API calls 69299->69303 69300->69305 69301->69297 69302->69299 69304 7ff6b536bb47 69303->69304 69309 7ff6b5363d70 82 API calls 69304->69309 69337 7ff6b536bcdf 69305->69337 69573 7ff6b5363d70 69305->69573 69307 7ff6b536b9a6 69306->69307 69308 7ff6b5363d70 82 API calls 69307->69308 69311 7ff6b536b9bc 69308->69311 69312 7ff6b536bb66 69309->69312 69310 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69314 7ff6b536bce5 69310->69314 69315 7ff6b5363d70 82 API calls 69311->69315 69313 7ff6b5363d70 82 API calls 69312->69313 69326 7ff6b536ba30 _Receive_impl 69313->69326 69317 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69314->69317 69316 7ff6b536b9d6 69315->69316 69318 7ff6b536b9e3 69316->69318 69320 7ff6b5368d10 82 API calls 69316->69320 69319 7ff6b536bceb 69317->69319 69322 7ff6b5363d70 82 API calls 69318->69322 69323 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69319->69323 69320->69318 69321 7ff6b536bcf1 69324 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69321->69324 69322->69326 69323->69321 69325 7ff6b536bcf7 69324->69325 69326->69314 69326->69319 69326->69321 69326->69326 69327 7ff6b536bc2d 69326->69327 69329 7ff6b5368560 82 API calls 69326->69329 69334 7ff6b536bcb1 _Receive_impl 69326->69334 69328 7ff6b5363d70 82 API calls 69327->69328 69330 7ff6b536bc47 69328->69330 69329->69327 69330->69330 69331 7ff6b5363d70 82 API calls 69330->69331 69332 7ff6b536bc5f 69331->69332 69333 7ff6b5363d70 82 API calls 69332->69333 69335 7ff6b536bc79 69333->69335 69334->69133 69335->69334 69336 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69335->69336 69336->69337 69337->69310 69339 7ff6b5371b4f 69338->69339 69595 7ff6b534ef10 82 API calls 3 library calls 69339->69595 69341 7ff6b5371b66 69596 7ff6b534ebf0 69341->69596 69343 7ff6b5371ba2 69620 7ff6b53704d0 82 API calls 69343->69620 69345 7ff6b5371de8 69347 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69345->69347 69346 7ff6b5371dee 69348 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69346->69348 69347->69346 69350 7ff6b5371df4 69348->69350 69353 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69350->69353 69351 7ff6b5371bc1 _Receive_impl 69351->69345 69351->69346 69351->69350 69354 7ff6b5371dfa 69351->69354 69621 7ff6b53d0740 69351->69621 69353->69354 69356 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69354->69356 69355 7ff6b5371da7 _Receive_impl 69357 7ff6b53ce860 _Strcoll 8 API calls 69355->69357 69361 7ff6b5371e00 69356->69361 69359 7ff6b5371dcc 69357->69359 69358 7ff6b5371de3 69360 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69358->69360 69359->69146 69360->69345 69362 7ff6b536b780 84 API calls 69361->69362 69363 7ff6b5372a9c 69362->69363 69364 7ff6b5371af0 84 API calls 69363->69364 69365 7ff6b5372ac2 69364->69365 69366 7ff6b536bd00 84 API calls 69365->69366 69367 7ff6b5372ad2 69366->69367 69368 7ff6b5372b3d 69367->69368 69369 7ff6b5372add 69367->69369 69627 7ff6b5363e90 80 API calls 69368->69627 69370 7ff6b5362880 78 API calls 69369->69370 69372 7ff6b5372ae7 69370->69372 69375 7ff6b534eec0 13 API calls 69372->69375 69373 7ff6b5372b49 69374 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69373->69374 69376 7ff6b5372b59 69374->69376 69377 7ff6b5372af1 69375->69377 69628 7ff6b5363e90 80 API calls 69376->69628 69378 7ff6b5362880 78 API calls 69377->69378 69380 7ff6b5372afb 69378->69380 69383 7ff6b5362880 78 API calls 69380->69383 69381 7ff6b5372b66 69382 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69381->69382 69384 7ff6b5372b76 69382->69384 69385 7ff6b5372b06 69383->69385 69629 7ff6b5363e90 80 API calls 69384->69629 69388 7ff6b536c4d0 78 API calls 69385->69388 69387 7ff6b5372b83 69389 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69387->69389 69390 7ff6b5372b14 69388->69390 69391 7ff6b5372b93 69389->69391 69392 7ff6b53ce860 _Strcoll 8 API calls 69390->69392 69630 7ff6b5374430 80 API calls 69391->69630 69394 7ff6b5372b26 69392->69394 69394->69146 69395 7ff6b5372ba0 69396 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69395->69396 69397 7ff6b5372bb0 69396->69397 69631 7ff6b5363e90 80 API calls 69397->69631 69399 7ff6b5372bbd 69400 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69399->69400 69401 7ff6b5372bcd 69400->69401 69632 7ff6b5363e90 80 API calls 69401->69632 69403 7ff6b5372bda 69404 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69403->69404 69405 7ff6b5372bea 69404->69405 69633 7ff6b5363e90 80 API calls 69405->69633 69407 7ff6b5372bf7 69408 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69407->69408 69409 7ff6b5372c07 69408->69409 69634 7ff6b5363e90 80 API calls 69409->69634 69411 7ff6b5372c14 69412 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69411->69412 69413 7ff6b5372c24 69412->69413 69635 7ff6b5363e90 80 API calls 69413->69635 69415 7ff6b5372c31 69416 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69415->69416 69417 7ff6b5372c41 69416->69417 69636 7ff6b5363e90 80 API calls 69417->69636 69419 7ff6b5372c4e 69420 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69419->69420 69421 7ff6b5372c5e 69420->69421 69637 7ff6b5363e90 80 API calls 69421->69637 69423 7ff6b5372c6b 69424 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69423->69424 69425 7ff6b5372c7b 69424->69425 69427 7ff6b536be02 69426->69427 69432 7ff6b536bd56 69426->69432 69428 7ff6b53ce860 _Strcoll 8 API calls 69427->69428 69429 7ff6b536be12 69428->69429 69429->69168 69429->69169 69431 7ff6b5368d10 82 API calls 69431->69432 69432->69427 69432->69431 69433 7ff6b5363d70 82 API calls 69432->69433 69645 7ff6b534b5b0 80 API calls 69432->69645 69433->69432 69435 7ff6b53628b7 _Receive_impl 69434->69435 69436 7ff6b5362893 69434->69436 69435->69185 69436->69435 69437 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69436->69437 69438 7ff6b53628dd 69437->69438 69440 7ff6b53d07d0 __std_exception_destroy 13 API calls 69439->69440 69441 7ff6b534eeee 69440->69441 69442 7ff6b53d07d0 __std_exception_destroy 13 API calls 69441->69442 69443 7ff6b534eefb 69442->69443 69443->69203 69445 7ff6b536c4e6 69444->69445 69446 7ff6b536c50f _Receive_impl 69444->69446 69445->69446 69447 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69445->69447 69446->69100 69448 7ff6b536c52f 69447->69448 69449->69181 69450->69212 69451->69225 69452->69155 69453->69158 69454->69199 69455->69172 69456->69205 69457->69221 69458->69231 69460 7ff6b5363ff0 82 API calls 69459->69460 69461 7ff6b537d5c3 69460->69461 69462 7ff6b53ce888 std::_Facet_Register 82 API calls 69461->69462 69463 7ff6b537d5d8 69462->69463 69501 7ff6b53629b0 69463->69501 69465 7ff6b537d5f5 69466 7ff6b53ce860 _Strcoll 8 API calls 69465->69466 69467 7ff6b537a59f 69466->69467 69467->69248 69469 7ff6b536402d 69468->69469 69471 7ff6b5364107 69469->69471 69472 7ff6b5364066 69469->69472 69487 7ff6b5364350 69469->69487 69493 7ff6b53643c2 _Receive_impl 69469->69493 69470 7ff6b53ce860 _Strcoll 8 API calls 69473 7ff6b536445f 69470->69473 69491 7ff6b5364134 69471->69491 69495 7ff6b5364482 69471->69495 69519 7ff6b53692c0 82 API calls 3 library calls 69471->69519 69474 7ff6b53640a6 69472->69474 69472->69495 69517 7ff6b53692c0 82 API calls 3 library calls 69472->69517 69473->69118 69497 7ff6b5364102 _Receive_impl 69474->69497 69518 7ff6b5370610 82 API calls 3 library calls 69474->69518 69475 7ff6b536443a 69525 7ff6b53600f0 82 API calls _Receive_impl 69475->69525 69476 7ff6b5364373 69478 7ff6b536442b 69476->69478 69490 7ff6b536437c 69476->69490 69477 7ff6b5364347 69523 7ff6b5364ca0 82 API calls 2 library calls 69477->69523 69524 7ff6b5364ca0 82 API calls 2 library calls 69478->69524 69487->69475 69487->69476 69487->69493 69489 7ff6b5361a20 82 API calls 69489->69497 69492 7ff6b536447d 69490->69492 69490->69493 69491->69497 69520 7ff6b5370610 82 API calls 3 library calls 69491->69520 69494 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69492->69494 69493->69470 69494->69495 69526 7ff6b5360640 82 API calls 69495->69526 69497->69477 69497->69489 69498 7ff6b5370610 82 API calls 69497->69498 69521 7ff6b5369380 82 API calls _Receive_impl 69497->69521 69522 7ff6b5379810 82 API calls 2 library calls 69497->69522 69498->69497 69500->69250 69503 7ff6b53629de 69501->69503 69506 7ff6b5362a82 69503->69506 69509 7ff6b5362a2a 69503->69509 69512 7ff6b53629fa BuildCatchObjectHelperInternal 69503->69512 69513 7ff6b5362abd 69503->69513 69505 7ff6b53ce888 std::_Facet_Register 82 API calls 69507 7ff6b5362a40 69505->69507 69510 7ff6b53ce888 std::_Facet_Register 82 API calls 69506->69510 69507->69512 69514 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69507->69514 69508 7ff6b5362ab7 69515 7ff6b534b820 82 API calls 2 library calls 69508->69515 69509->69505 69509->69508 69510->69512 69512->69465 69516 7ff6b534b8e0 82 API calls 69513->69516 69514->69508 69515->69513 69518->69474 69520->69491 69521->69497 69522->69497 69523->69487 69524->69493 69528 7ff6b536e223 69527->69528 69531 7ff6b536e21d 69527->69531 69529 7ff6b536e23a 69528->69529 69543 7ff6b5360ca0 82 API calls 69528->69543 69529->69531 69533 7ff6b536e2d4 69529->69533 69530 7ff6b536e2a7 69530->69256 69531->69530 69544 7ff6b5379fb0 69531->69544 69558 7ff6b534cdc0 82 API calls 69533->69558 69535 7ff6b536e316 69536 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69535->69536 69537 7ff6b536e327 69536->69537 69538 7ff6b5368d10 82 API calls 69537->69538 69541 7ff6b536e355 69537->69541 69538->69541 69539 7ff6b536e400 69539->69256 69540 7ff6b536e200 82 API calls 69540->69541 69541->69539 69541->69540 69542 7ff6b5368d10 82 API calls 69541->69542 69542->69541 69543->69529 69548 7ff6b5379ffa 69544->69548 69555 7ff6b537a150 69544->69555 69546 7ff6b537a016 69547 7ff6b537a156 69546->69547 69549 7ff6b53ce888 std::_Facet_Register 82 API calls 69546->69549 69560 7ff6b534b820 82 API calls 2 library calls 69547->69560 69548->69546 69550 7ff6b537a07a 69548->69550 69556 7ff6b537a02a BuildCatchObjectHelperInternal 69548->69556 69549->69556 69552 7ff6b53ce888 std::_Facet_Register 82 API calls 69550->69552 69552->69556 69553 7ff6b537a15c 69554 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69554->69555 69559 7ff6b5360640 82 API calls 69555->69559 69556->69554 69557 7ff6b537a113 _Receive_impl 69556->69557 69557->69530 69558->69535 69560->69553 69562 7ff6b5363946 69561->69562 69563 7ff6b5363823 69561->69563 69562->69563 69564 7ff6b5363953 69562->69564 69565 7ff6b53ce860 _Strcoll 8 API calls 69563->69565 69572 7ff6b53688c0 82 API calls 4 library calls 69564->69572 69566 7ff6b5363852 69565->69566 69566->69281 69568 7ff6b5363974 69569 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69568->69569 69570 7ff6b5363985 69569->69570 69572->69568 69574 7ff6b5363dd2 69573->69574 69575 7ff6b5363d93 BuildCatchObjectHelperInternal 69573->69575 69578 7ff6b5369030 69574->69578 69575->69288 69577 7ff6b5363deb 69577->69288 69579 7ff6b53691a6 69578->69579 69584 7ff6b5369068 69578->69584 69593 7ff6b534b8e0 82 API calls 69579->69593 69580 7ff6b53690cd 69583 7ff6b53ce888 std::_Facet_Register 82 API calls 69580->69583 69582 7ff6b53691ab 69594 7ff6b534b820 82 API calls 2 library calls 69582->69594 69591 7ff6b53690b3 BuildCatchObjectHelperInternal 69583->69591 69584->69580 69586 7ff6b53690fc 69584->69586 69587 7ff6b53690c0 69584->69587 69584->69591 69588 7ff6b53ce888 std::_Facet_Register 82 API calls 69586->69588 69587->69580 69587->69582 69588->69591 69589 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69590 7ff6b53691b7 69589->69590 69591->69589 69592 7ff6b536915c _Receive_impl BuildCatchObjectHelperInternal 69591->69592 69592->69577 69594->69591 69595->69341 69597 7ff6b534ec2b 69596->69597 69598 7ff6b534ed21 69597->69598 69599 7ff6b5368560 82 API calls 69597->69599 69600 7ff6b5363d70 82 API calls 69598->69600 69599->69598 69601 7ff6b534ed3a 69600->69601 69602 7ff6b5363d70 82 API calls 69601->69602 69603 7ff6b534ed53 69602->69603 69604 7ff6b534ed60 69603->69604 69605 7ff6b5368d10 82 API calls 69603->69605 69606 7ff6b5363d70 82 API calls 69604->69606 69605->69604 69607 7ff6b534edaa 69606->69607 69608 7ff6b5363d70 82 API calls 69607->69608 69609 7ff6b534edbf 69608->69609 69610 7ff6b534ee03 _Receive_impl 69609->69610 69612 7ff6b534ee3c 69609->69612 69611 7ff6b53ce860 _Strcoll 8 API calls 69610->69611 69613 7ff6b534ee28 69611->69613 69614 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69612->69614 69613->69343 69615 7ff6b534ee41 69614->69615 69638 7ff6b53d07d0 69615->69638 69618 7ff6b53d07d0 __std_exception_destroy 13 API calls 69619 7ff6b534ee92 _Receive_impl 69618->69619 69619->69343 69620->69351 69623 7ff6b53d0761 69621->69623 69626 7ff6b5371d53 69621->69626 69622 7ff6b53d0796 69644 7ff6b53b7620 13 API calls 2 library calls 69622->69644 69623->69622 69623->69626 69643 7ff6b53b8cb0 78 API calls 2 library calls 69623->69643 69626->69355 69626->69358 69627->69373 69628->69381 69629->69387 69630->69395 69631->69399 69632->69403 69633->69407 69634->69411 69635->69415 69636->69419 69637->69423 69639 7ff6b53d07df 69638->69639 69640 7ff6b534ee85 69638->69640 69642 7ff6b53b7620 13 API calls 2 library calls 69639->69642 69640->69618 69642->69640 69643->69622 69644->69626 69645->69432 69646 7ff6b53acb57 69647 7ff6b53acb61 69646->69647 69652 7ff6b53ad050 69647->69652 69650 7ff6b53ce860 _Strcoll 8 API calls 69651 7ff6b53aceb3 69650->69651 69654 7ff6b53ad08f 69652->69654 69659 7ff6b53acb70 69652->69659 69653 7ff6b53ad308 69673 7ff6b534b900 8 API calls _Strcoll 69653->69673 69654->69653 69656 7ff6b53ad28d 69654->69656 69671 7ff6b5363d70 82 API calls 69654->69671 69672 7ff6b534b5b0 80 API calls 69654->69672 69656->69659 69695 7ff6b53ae840 82 API calls 69656->69695 69658 7ff6b53ad329 69674 7ff6b53ae760 82 API calls 69658->69674 69659->69650 69661 7ff6b53ad33f 69675 7ff6b5367ac0 69661->69675 69664 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69664->69656 69666 7ff6b53ad38a 69667 7ff6b5367ac0 82 API calls 69666->69667 69668 7ff6b53ad39d 69667->69668 69669 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69668->69669 69670 7ff6b53ad3ae 69669->69670 69671->69654 69672->69654 69673->69658 69674->69661 69676 7ff6b5367b17 69675->69676 69677 7ff6b534ebf0 82 API calls 69676->69677 69678 7ff6b5367b55 69677->69678 69696 7ff6b5370400 69678->69696 69680 7ff6b5367d29 69682 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69680->69682 69681 7ff6b5367b69 _Receive_impl 69681->69680 69683 7ff6b53d0740 __std_exception_copy 80 API calls 69681->69683 69684 7ff6b5367d2f 69681->69684 69685 7ff6b5367d35 69681->69685 69682->69684 69687 7ff6b5367ca4 69683->69687 69686 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69684->69686 69689 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69685->69689 69686->69685 69688 7ff6b5367cf1 _Receive_impl 69687->69688 69693 7ff6b5367d24 69687->69693 69690 7ff6b53ce860 _Strcoll 8 API calls 69688->69690 69691 7ff6b5367d3b 69689->69691 69692 7ff6b5367d16 69690->69692 69692->69664 69694 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69693->69694 69694->69680 69695->69666 69697 7ff6b5370458 69696->69697 69699 7ff6b5370464 69696->69699 69698 7ff6b5368560 82 API calls 69697->69698 69698->69699 69700 7ff6b5363d70 82 API calls 69699->69700 69701 7ff6b5370481 69700->69701 69702 7ff6b5363d70 82 API calls 69701->69702 69703 7ff6b537049a 69702->69703 69704 7ff6b5363d70 82 API calls 69703->69704 69705 7ff6b53704b3 69704->69705 69705->69681 69706 7ff6b53a6e1b RegOpenKeyExA 69707 7ff6b53a6e45 RegQueryValueExA 69706->69707 69715 7ff6b53a6ebd _Receive_impl 69706->69715 69712 7ff6b53a6e84 69707->69712 69707->69715 69709 7ff6b53a6f14 RegCloseKey 69710 7ff6b53a6f1a 69709->69710 69711 7ff6b53ce860 _Strcoll 8 API calls 69710->69711 69713 7ff6b53a6f2d 69711->69713 69716 7ff6b53628e0 78 API calls 2 library calls 69712->69716 69715->69709 69715->69710 69716->69715 69717 7ff6b538a41b 69718 7ff6b538a433 69717->69718 69719 7ff6b538a468 _Receive_impl 69717->69719 69718->69719 69721 7ff6b538a8d0 69718->69721 69720 7ff6b538a4c1 _Receive_impl 69719->69720 69723 7ff6b538a8d5 69719->69723 69722 7ff6b538a515 _Receive_impl 69720->69722 69726 7ff6b538a8db 69720->69726 69724 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69721->69724 69725 7ff6b53ce860 _Strcoll 8 API calls 69722->69725 69727 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69723->69727 69724->69723 69728 7ff6b538a543 69725->69728 69729 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69726->69729 69727->69726 69730 7ff6b538a8e1 69729->69730 69787 7ff6b53a0040 69730->69787 69732 7ff6b538a93f memcpy_s 69733 7ff6b538a97e GetModuleFileNameW 69732->69733 69734 7ff6b538a9c0 69733->69734 69734->69734 69735 7ff6b5356940 82 API calls 69734->69735 69736 7ff6b538a9dd 69735->69736 69737 7ff6b5356940 82 API calls 69736->69737 69738 7ff6b538abfe 69737->69738 69861 7ff6b5356bd0 69738->69861 69740 7ff6b538ac0c 69875 7ff6b5365fd0 85 API calls 69740->69875 69742 7ff6b538ac26 69743 7ff6b5356940 82 API calls 69742->69743 69744 7ff6b538ae9d 69743->69744 69745 7ff6b5356bd0 82 API calls 69744->69745 69746 7ff6b538aeab 69745->69746 69876 7ff6b5365fd0 85 API calls 69746->69876 69748 7ff6b538aec6 69749 7ff6b5356940 82 API calls 69748->69749 69750 7ff6b538b13e 69749->69750 69877 7ff6b534d4a0 82 API calls 69750->69877 69752 7ff6b538b15a 69878 7ff6b5365fd0 85 API calls 69752->69878 69754 7ff6b538b16f 69755 7ff6b5356940 82 API calls 69754->69755 69756 7ff6b538b61d 69755->69756 69757 7ff6b5356bd0 82 API calls 69756->69757 69758 7ff6b538b62e 69757->69758 69879 7ff6b5365fd0 85 API calls 69758->69879 69760 7ff6b538b64c 69761 7ff6b5356940 82 API calls 69760->69761 69762 7ff6b538b8dd 69761->69762 69763 7ff6b5356bd0 82 API calls 69762->69763 69764 7ff6b538b8ee 69763->69764 69880 7ff6b5365fd0 85 API calls 69764->69880 69766 7ff6b538b90c 69767 7ff6b5356940 82 API calls 69766->69767 69768 7ff6b538bb90 69767->69768 69769 7ff6b5356bd0 82 API calls 69768->69769 69770 7ff6b538bba1 69769->69770 69881 7ff6b5365fd0 85 API calls 69770->69881 69772 7ff6b538bbbf 69773 7ff6b5356940 82 API calls 69772->69773 69774 7ff6b538bdaa 69773->69774 69775 7ff6b5356bd0 82 API calls 69774->69775 69776 7ff6b538bdbb 69775->69776 69882 7ff6b5365fd0 85 API calls 69776->69882 69778 7ff6b538bdd9 69779 7ff6b5356940 82 API calls 69778->69779 69780 7ff6b538c0ef 69779->69780 69781 7ff6b5356bd0 82 API calls 69780->69781 69782 7ff6b538c100 69781->69782 69883 7ff6b5365fd0 85 API calls 69782->69883 69784 7ff6b538c11e 69884 7ff6b534cf70 69784->69884 69788 7ff6b53a00d3 69787->69788 69888 7ff6b534d810 69788->69888 69790 7ff6b53a00f8 _Receive_impl 69791 7ff6b534eaf0 97 API calls 69790->69791 69805 7ff6b53a064c 69790->69805 69796 7ff6b53a0164 memcpy_s 69791->69796 69792 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69794 7ff6b53a0652 69792->69794 69793 7ff6b53a01a6 69793->69794 69797 7ff6b53a0207 _Receive_impl 69793->69797 69798 7ff6b53a0647 69793->69798 69949 7ff6b534e240 87 API calls Concurrency::cancel_current_task 69794->69949 69796->69793 69801 7ff6b536a910 148 API calls 69796->69801 69799 7ff6b53ce860 _Strcoll 8 API calls 69797->69799 69802 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69798->69802 69803 7ff6b53a0239 69799->69803 69804 7ff6b53a0289 69801->69804 69802->69805 69803->69732 69806 7ff6b53a051e 69804->69806 69897 7ff6b53656a0 69804->69897 69805->69792 69806->69797 69948 7ff6b53612f0 82 API calls 69806->69948 69865 7ff6b5356bfe 69861->69865 69862 7ff6b5356cf3 70177 7ff6b534b8e0 82 API calls 69862->70177 69865->69862 69866 7ff6b5356ced 69865->69866 69868 7ff6b5356c1a BuildCatchObjectHelperInternal 69865->69868 69869 7ff6b5356c8d 69865->69869 69870 7ff6b5356cb4 69865->69870 70176 7ff6b534b820 82 API calls 2 library calls 69866->70176 69868->69740 69869->69866 69872 7ff6b53ce888 std::_Facet_Register 82 API calls 69869->69872 69871 7ff6b53ce888 std::_Facet_Register 82 API calls 69870->69871 69871->69868 69873 7ff6b5356c9e 69872->69873 69873->69868 69874 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69873->69874 69874->69866 69875->69742 69876->69748 69877->69752 69878->69754 69879->69760 69880->69766 69881->69772 69882->69778 69883->69784 69885 7ff6b534cf8d 69884->69885 69886 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 69885->69886 69887 7ff6b534cf9e 69886->69887 69889 7ff6b534d850 69888->69889 69890 7ff6b534d97a 69889->69890 69895 7ff6b534d896 69889->69895 69891 7ff6b5356bd0 82 API calls 69890->69891 69892 7ff6b534d982 69891->69892 69954 7ff6b534d140 69892->69954 69894 7ff6b534d8fa BuildCatchObjectHelperInternal 69894->69790 69895->69894 69953 7ff6b536ec90 82 API calls 5 library calls 69895->69953 69898 7ff6b53637f0 82 API calls 69897->69898 69899 7ff6b53656d6 69898->69899 69972 7ff6b536ee00 69899->69972 69903 7ff6b5365745 70058 7ff6b5369450 69903->70058 69948->69793 69953->69894 69958 7ff6b534d15f 69954->69958 69955 7ff6b534d297 69957 7ff6b534d35e 69955->69957 69963 7ff6b534d2a7 69955->69963 69956 7ff6b534d26b 69956->69955 69961 7ff6b534d2c0 69956->69961 69971 7ff6b53645e0 82 API calls 69957->69971 69958->69956 69964 7ff6b534d24a 69958->69964 69961->69963 69969 7ff6b5367fd0 82 API calls 5 library calls 69961->69969 69970 7ff6b53625d0 82 API calls BuildCatchObjectHelperInternal 69963->69970 69968 7ff6b534d9c0 82 API calls BuildCatchObjectHelperInternal 69964->69968 69967 7ff6b534d255 69967->69894 69968->69967 69969->69963 69970->69967 69973 7ff6b536ee54 69972->69973 70068 7ff6b53b494c 69973->70068 69976 7ff6b536c600 82 API calls 69977 7ff6b536ef61 69976->69977 70073 7ff6b534f1f0 69977->70073 69980 7ff6b53ce860 _Strcoll 8 API calls 69981 7ff6b5365739 69980->69981 69982 7ff6b5369f80 69981->69982 69983 7ff6b536a291 69982->69983 69987 7ff6b5369fcb memcpy_s 69982->69987 70081 7ff6b5371e10 69983->70081 69986 7ff6b536c600 82 API calls 69992 7ff6b536a2d0 69986->69992 70147 7ff6b536b5b0 82 API calls 69987->70147 69989 7ff6b536a01b 70148 7ff6b5370c20 84 API calls 2 library calls 69989->70148 69991 7ff6b53637f0 82 API calls 69996 7ff6b536a48c 69991->69996 69997 7ff6b536b780 84 API calls 69992->69997 70049 7ff6b536a457 _Receive_impl 69992->70049 69993 7ff6b536a28c _Receive_impl 69998 7ff6b53ce860 _Strcoll 8 API calls 69993->69998 69994 7ff6b536a02b 69995 7ff6b536c600 82 API calls 69994->69995 70013 7ff6b536a037 69995->70013 70000 7ff6b5363ff0 82 API calls 69996->70000 70001 7ff6b536a31d 69997->70001 70002 7ff6b536a51c 69998->70002 69999 7ff6b536a575 70004 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 69999->70004 70008 7ff6b536a4c6 70000->70008 70005 7ff6b5371af0 84 API calls 70001->70005 70002->69903 70003 7ff6b536a1c4 _Receive_impl 70006 7ff6b536a1dd 70003->70006 70007 7ff6b536a225 70003->70007 70009 7ff6b536a57b 70004->70009 70010 7ff6b536a343 70005->70010 70011 7ff6b53637f0 82 API calls 70006->70011 70012 7ff6b536a27f 70007->70012 70016 7ff6b53637f0 82 API calls 70007->70016 70008->69993 70008->69999 70150 7ff6b5363e90 80 API calls 70009->70150 70014 7ff6b536bd00 84 API calls 70010->70014 70015 7ff6b536a1f8 70011->70015 70149 7ff6b536b3d0 82 API calls 2 library calls 70012->70149 70013->70003 70017 7ff6b536b780 84 API calls 70013->70017 70031 7ff6b536a352 _Receive_impl 70014->70031 70025 7ff6b5363ff0 82 API calls 70015->70025 70016->70015 70020 7ff6b536a083 70017->70020 70024 7ff6b5371af0 84 API calls 70020->70024 70021 7ff6b536a588 70026 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 70021->70026 70022 7ff6b536a5aa 70151 7ff6b5363e90 80 API calls 70022->70151 70029 7ff6b536a0a9 70024->70029 70025->70012 70030 7ff6b536a598 70026->70030 70027 7ff6b53d07d0 __std_exception_destroy 13 API calls 70032 7ff6b536a3ca 70027->70032 70028 7ff6b536a5b7 70033 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 70028->70033 70034 7ff6b536bd00 84 API calls 70029->70034 70039 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70030->70039 70031->70022 70031->70027 70035 7ff6b536a5c7 70031->70035 70036 7ff6b53d07d0 __std_exception_destroy 13 API calls 70032->70036 70033->70035 70037 7ff6b536a0b9 70034->70037 70038 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70035->70038 70050 7ff6b536a3d8 _Receive_impl 70036->70050 70037->70009 70040 7ff6b536a0ce 70037->70040 70041 7ff6b536a5cd 70038->70041 70042 7ff6b536a59e 70039->70042 70040->70030 70043 7ff6b536a105 _Receive_impl 70040->70043 70046 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70041->70046 70044 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70042->70044 70045 7ff6b53d07d0 __std_exception_destroy 13 API calls 70043->70045 70047 7ff6b536a5a4 70044->70047 70048 7ff6b536a139 70045->70048 70051 7ff6b536a5d3 70046->70051 70055 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70047->70055 70052 7ff6b53d07d0 __std_exception_destroy 13 API calls 70048->70052 70049->69991 70049->70008 70050->70041 70050->70049 70053 7ff6b536a570 70050->70053 70051->69903 70056 7ff6b536a147 70052->70056 70054 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70053->70054 70054->69999 70055->70022 70056->70042 70057 7ff6b536a17e _Receive_impl 70056->70057 70057->70003 70057->70047 70059 7ff6b536946c _Receive_impl 70058->70059 70060 7ff6b5369504 70059->70060 70061 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70059->70061 70062 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70060->70062 70061->70060 70065 7ff6b536950a _Receive_impl 70062->70065 70064 7ff6b536957e 70066 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70064->70066 70065->70064 70163 7ff6b53695a0 78 API calls 2 library calls 70065->70163 70067 7ff6b5369591 70066->70067 70069 7ff6b53b9eec _Getctype 78 API calls 70068->70069 70070 7ff6b53b4955 70069->70070 70071 7ff6b53bc178 _Getctype 78 API calls 70070->70071 70072 7ff6b536ef3a 70071->70072 70072->69976 70074 7ff6b534f227 70073->70074 70075 7ff6b534f1fe 70073->70075 70074->69980 70075->70074 70080 7ff6b534cdc0 82 API calls 70075->70080 70077 7ff6b534f25e 70078 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 70077->70078 70079 7ff6b534f26f 70078->70079 70080->70077 70082 7ff6b5371e8d 70081->70082 70083 7ff6b536b780 84 API calls 70082->70083 70084 7ff6b5372a9c 70083->70084 70085 7ff6b5371af0 84 API calls 70084->70085 70086 7ff6b5372ac2 70085->70086 70087 7ff6b536bd00 84 API calls 70086->70087 70088 7ff6b5372ad2 70087->70088 70089 7ff6b5372b3d 70088->70089 70090 7ff6b5372add 70088->70090 70152 7ff6b5363e90 80 API calls 70089->70152 70091 7ff6b5362880 78 API calls 70090->70091 70093 7ff6b5372ae7 70091->70093 70096 7ff6b534eec0 13 API calls 70093->70096 70094 7ff6b5372b49 70095 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 70094->70095 70097 7ff6b5372b59 70095->70097 70098 7ff6b5372af1 70096->70098 70153 7ff6b5363e90 80 API calls 70097->70153 70099 7ff6b5362880 78 API calls 70098->70099 70101 7ff6b5372afb 70099->70101 70104 7ff6b5362880 78 API calls 70101->70104 70102 7ff6b5372b66 70103 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 70102->70103 70105 7ff6b5372b76 70103->70105 70106 7ff6b5372b06 70104->70106 70154 7ff6b5363e90 80 API calls 70105->70154 70109 7ff6b536c4d0 78 API calls 70106->70109 70108 7ff6b5372b83 70110 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 70108->70110 70111 7ff6b5372b14 70109->70111 70112 7ff6b5372b93 70110->70112 70113 7ff6b53ce860 _Strcoll 8 API calls 70111->70113 70155 7ff6b5374430 80 API calls 70112->70155 70115 7ff6b536a2c4 70113->70115 70115->69986 70116 7ff6b5372ba0 70117 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 70116->70117 70118 7ff6b5372bb0 70117->70118 70156 7ff6b5363e90 80 API calls 70118->70156 70120 7ff6b5372bbd 70121 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 70120->70121 70122 7ff6b5372bcd 70121->70122 70157 7ff6b5363e90 80 API calls 70122->70157 70124 7ff6b5372bda 70125 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 70124->70125 70126 7ff6b5372bea 70125->70126 70158 7ff6b5363e90 80 API calls 70126->70158 70128 7ff6b5372bf7 70129 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 70128->70129 70130 7ff6b5372c07 70129->70130 70159 7ff6b5363e90 80 API calls 70130->70159 70132 7ff6b5372c14 70133 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 70132->70133 70134 7ff6b5372c24 70133->70134 70160 7ff6b5363e90 80 API calls 70134->70160 70136 7ff6b5372c31 70137 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 70136->70137 70138 7ff6b5372c41 70137->70138 70161 7ff6b5363e90 80 API calls 70138->70161 70140 7ff6b5372c4e 70141 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 70140->70141 70142 7ff6b5372c5e 70141->70142 70162 7ff6b5363e90 80 API calls 70142->70162 70144 7ff6b5372c6b 70145 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 70144->70145 70146 7ff6b5372c7b 70145->70146 70147->69989 70148->69994 70149->69993 70150->70021 70151->70028 70152->70094 70153->70102 70154->70108 70155->70116 70156->70120 70157->70124 70158->70128 70159->70132 70160->70136 70161->70140 70162->70144 70176->69862 70178 7ff6b536c8de 70183 7ff6b536d4b0 70178->70183 70181 7ff6b53ce860 _Strcoll 8 API calls 70182 7ff6b536c91b 70181->70182 70184 7ff6b536d4d6 70183->70184 70185 7ff6b536d502 70184->70185 70186 7ff6b5379fb0 82 API calls 70184->70186 70187 7ff6b536e200 82 API calls 70185->70187 70186->70185 70189 7ff6b536d567 70187->70189 70188 7ff6b536c8e6 70188->70181 70189->70188 70190 7ff6b5368d10 82 API calls 70189->70190 70191 7ff6b536e200 82 API calls 70189->70191 70190->70189 70191->70189 70192 7ff6b53c4e91 70204 7ff6b53cbf24 70192->70204 70205 7ff6b53b9eec _Getctype 78 API calls 70204->70205 70206 7ff6b53cbf2d 70205->70206 70209 7ff6b53b98b4 78 API calls BuildCatchObjectHelperInternal 70206->70209 70210 7ff6b53a6290 70229 7ff6b539f9e0 70210->70229 70214 7ff6b53a6333 70216 7ff6b53a6457 70214->70216 70219 7ff6b53a6365 memcpy_s _Receive_impl 70214->70219 70215 7ff6b53a6381 70217 7ff6b53ce860 _Strcoll 8 API calls 70215->70217 70218 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70216->70218 70220 7ff6b53a643e 70217->70220 70221 7ff6b53a645c 70218->70221 70219->70215 70242 7ff6b53986d0 122 API calls 70219->70242 70223 7ff6b53a63bd 70243 7ff6b5398830 121 API calls 2 library calls 70223->70243 70225 7ff6b53a63e4 70244 7ff6b535fe50 70225->70244 70251 7ff6b539dec0 70229->70251 70232 7ff6b539fa2d 70234 7ff6b5356940 82 API calls 70232->70234 70241 7ff6b539fb47 70232->70241 70235 7ff6b539fa9e 70234->70235 70236 7ff6b539fb07 _Receive_impl 70235->70236 70238 7ff6b539fb42 70235->70238 70237 7ff6b53ce860 _Strcoll 8 API calls 70236->70237 70239 7ff6b539fb2c GetVolumeInformationW 70237->70239 70240 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70238->70240 70239->70214 70239->70219 70240->70241 70258 7ff6b539dcd0 82 API calls Concurrency::cancel_current_task 70241->70258 70242->70223 70243->70225 70245 7ff6b535fe98 70244->70245 70246 7ff6b535fefc 70245->70246 70247 7ff6b5364600 82 API calls 70245->70247 70248 7ff6b535ebc0 70246->70248 70247->70246 70265 7ff6b53620b0 70248->70265 70250 7ff6b535ec0d 70250->70215 70252 7ff6b539df3f 70251->70252 70255 7ff6b539df20 70251->70255 70252->70255 70263 7ff6b5368b50 82 API calls 5 library calls 70252->70263 70257 7ff6b539e055 70255->70257 70259 7ff6b53db574 GetCurrentDirectoryW 70255->70259 70264 7ff6b5368b50 82 API calls 5 library calls 70255->70264 70257->70232 70260 7ff6b53db595 GetLastError 70259->70260 70261 7ff6b53db586 70259->70261 70262 7ff6b53db58a 70260->70262 70261->70260 70261->70262 70262->70255 70263->70255 70264->70255 70266 7ff6b53620ce 70265->70266 70267 7ff6b5362120 _Receive_impl 70265->70267 70266->70267 70268 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70266->70268 70267->70250 70269 7ff6b53621ac 70268->70269 70270 7ff6b53a6c70 GetCurrentHwProfileW 70271 7ff6b53a6cba 70270->70271 70274 7ff6b53a6d19 70270->70274 70278 7ff6b53978f0 70271->70278 70273 7ff6b53a6cc9 70273->70274 70290 7ff6b53afb34 85 API calls 70273->70290 70275 7ff6b53ce860 _Strcoll 8 API calls 70274->70275 70276 7ff6b53a6d91 70275->70276 70279 7ff6b539793e 70278->70279 70286 7ff6b539791f _Receive_impl 70278->70286 70282 7ff6b5356940 82 API calls 70279->70282 70280 7ff6b53ce860 _Strcoll 8 API calls 70281 7ff6b53979de 70280->70281 70281->70273 70283 7ff6b5397967 70282->70283 70291 7ff6b5397a00 10 API calls _Strcoll 70283->70291 70285 7ff6b5397975 70285->70286 70287 7ff6b53979ec 70285->70287 70286->70280 70288 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70287->70288 70289 7ff6b53979f1 70288->70289 70290->70273 70291->70285 70292 7ff6b539fc10 70293 7ff6b539fc40 70292->70293 70294 7ff6b53db5b0 97 API calls 70293->70294 70295 7ff6b539fc59 70294->70295 70296 7ff6b53ce860 _Strcoll 8 API calls 70295->70296 70297 7ff6b539fc96 70296->70297 70298 7ff6b53b9aa8 70309 7ff6b53b990c 70298->70309 70301 7ff6b53b9b08 70302 7ff6b53b9b49 70301->70302 70303 7ff6b53b9acf 70301->70303 70327 7ff6b53be768 78 API calls 2 library calls 70301->70327 70315 7ff6b53b9934 70302->70315 70307 7ff6b53b9b3d 70307->70302 70328 7ff6b53c0318 11 API calls 2 library calls 70307->70328 70310 7ff6b53b9915 70309->70310 70314 7ff6b53b9925 70309->70314 70329 7ff6b53b4e68 11 API calls memcpy_s 70310->70329 70312 7ff6b53b991a 70330 7ff6b53b8234 78 API calls _invalid_parameter_noinfo 70312->70330 70314->70301 70314->70303 70326 7ff6b53b9a2c 78 API calls ProcessCodePage 70314->70326 70316 7ff6b53b990c _fread_nolock 78 API calls 70315->70316 70317 7ff6b53b9959 70316->70317 70318 7ff6b53b9969 70317->70318 70319 7ff6b53b99fa 70317->70319 70321 7ff6b53b99a5 70318->70321 70322 7ff6b53b9987 70318->70322 70340 7ff6b53bce18 78 API calls 3 library calls 70319->70340 70324 7ff6b53b9995 70321->70324 70331 7ff6b53c0f48 70321->70331 70339 7ff6b53bce18 78 API calls 3 library calls 70322->70339 70324->70303 70326->70301 70327->70307 70328->70302 70329->70312 70330->70314 70332 7ff6b53c0f78 70331->70332 70341 7ff6b53c0d7c 70332->70341 70335 7ff6b53c0fb7 70337 7ff6b53c0fcc 70335->70337 70353 7ff6b53af864 78 API calls 2 library calls 70335->70353 70337->70324 70339->70324 70340->70324 70342 7ff6b53c0dd3 70341->70342 70351 7ff6b53c0da5 70341->70351 70343 7ff6b53c0dec 70342->70343 70345 7ff6b53c0e43 70342->70345 70355 7ff6b53b8168 78 API calls 2 library calls 70343->70355 70354 7ff6b53c555c EnterCriticalSection 70345->70354 70351->70335 70352 7ff6b53af864 78 API calls 2 library calls 70351->70352 70352->70335 70353->70337 70355->70351 70356 7ff6b53ac8c9 70357 7ff6b53ac8f4 70356->70357 70370 7ff6b53ac8df 70356->70370 70361 7ff6b53ac8fd 70357->70361 70365 7ff6b53acac0 70357->70365 70358 7ff6b53acb29 70360 7ff6b53ac570 8 API calls 70358->70360 70359 7ff6b53ce860 _Strcoll 8 API calls 70362 7ff6b53aceb3 70359->70362 70360->70370 70364 7ff6b5368e80 82 API calls 70361->70364 70369 7ff6b53ac95a memcpy_s 70361->70369 70363 7ff6b53ac570 8 API calls 70363->70365 70364->70369 70365->70358 70365->70363 70366 7ff6b53aca4a 70367 7ff6b53ac570 8 API calls 70366->70367 70367->70370 70369->70366 70371 7ff6b53ac570 70369->70371 70370->70359 70372 7ff6b53ac5a0 70371->70372 70373 7ff6b53ce860 _Strcoll 8 API calls 70372->70373 70374 7ff6b53aceb3 70373->70374 70374->70369 70375 7ff6b5357633 70376 7ff6b534da40 78 API calls 70375->70376 70377 7ff6b5357666 FindNextFileW 70376->70377 70378 7ff6b5357684 70377->70378 70379 7ff6b53ce860 _Strcoll 8 API calls 70378->70379 70380 7ff6b53576ab 70379->70380 70381 7ff6b53cf0ac 70406 7ff6b53ce9d0 70381->70406 70384 7ff6b53cf1f8 70501 7ff6b53cf2b8 7 API calls 2 library calls 70384->70501 70385 7ff6b53cf0c8 __scrt_acquire_startup_lock 70387 7ff6b53cf202 70385->70387 70388 7ff6b53cf0e6 70385->70388 70502 7ff6b53cf2b8 7 API calls 2 library calls 70387->70502 70397 7ff6b53cf107 __scrt_release_startup_lock 70388->70397 70412 7ff6b53cbad0 70388->70412 70391 7ff6b53cf10b 70392 7ff6b53cf20d BuildCatchObjectHelperInternal 70393 7ff6b53cf191 70416 7ff6b53cf400 70393->70416 70395 7ff6b53cf196 70419 7ff6b53dde08 70395->70419 70397->70391 70397->70393 70498 7ff6b53c505c 78 API calls 70397->70498 70407 7ff6b53ce9d8 70406->70407 70408 7ff6b53ce9e4 __scrt_dllmain_crt_thread_attach 70407->70408 70409 7ff6b53ce9f1 70408->70409 70411 7ff6b53ce9ed 70408->70411 70409->70411 70503 7ff6b53d0e6c 7 API calls 2 library calls 70409->70503 70411->70384 70411->70385 70413 7ff6b53cbae3 70412->70413 70414 7ff6b53cbb0a 70413->70414 70504 7ff6b53cefc8 70413->70504 70414->70397 70592 7ff6b53e1650 70416->70592 70420 7ff6b53c64e4 96 API calls 70419->70420 70421 7ff6b53dde17 70420->70421 70422 7ff6b53cf19e 70421->70422 70594 7ff6b53dec70 78 API calls wcsftime 70421->70594 70424 7ff6b539c600 70422->70424 70595 7ff6b539f820 GetCurrentProcess OpenProcessToken 70424->70595 70427 7ff6b539c64e 70602 7ff6b53ab9b0 GetCurrentProcess OpenProcessToken 70427->70602 70428 7ff6b539c624 71468 7ff6b539fb60 83 API calls 2 library calls 70428->71468 70431 7ff6b539c62e 71469 7ff6b53aa780 110 API calls _Strcoll 70431->71469 70434 7ff6b53ab9b0 13 API calls 70436 7ff6b539c666 70434->70436 70435 7ff6b539c637 71470 7ff6b5362660 78 API calls 2 library calls 70435->71470 70610 7ff6b539d030 70436->70610 70438 7ff6b539c642 ExitProcess 70441 7ff6b539c734 OpenMutexA 70443 7ff6b539c779 CreateMutexExA 70441->70443 70444 7ff6b539c76d ExitProcess 70441->70444 70442 7ff6b539c72f _Receive_impl 70442->70441 70446 7ff6b539c7a9 70443->70446 70445 7ff6b539c8c6 70447 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70445->70447 70614 7ff6b539fca0 70446->70614 70448 7ff6b539c8cb 70447->70448 70451 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70448->70451 70454 7ff6b539c8d1 70451->70454 70452 7ff6b539c7be 70654 7ff6b53a8330 70452->70654 70453 7ff6b539c7b2 ExitProcess 70498->70393 70501->70387 70502->70392 70503->70411 70505 7ff6b53cefd8 70504->70505 70521 7ff6b53ddea8 70505->70521 70507 7ff6b53cefe4 70527 7ff6b53cea0c 70507->70527 70509 7ff6b53cf051 70520 7ff6b53cf06d 70509->70520 70568 7ff6b53cf2b8 7 API calls 2 library calls 70509->70568 70511 7ff6b53ceffc _RTC_Initialize 70511->70509 70532 7ff6b53cebbc 70511->70532 70512 7ff6b53cf07d 70512->70413 70514 7ff6b53cf011 70535 7ff6b53ddb08 70514->70535 70520->70413 70522 7ff6b53ddeb9 70521->70522 70523 7ff6b53ddec1 70522->70523 70569 7ff6b53b4e68 11 API calls memcpy_s 70522->70569 70523->70507 70525 7ff6b53dded0 70570 7ff6b53b8234 78 API calls _invalid_parameter_noinfo 70525->70570 70528 7ff6b53cea1d 70527->70528 70531 7ff6b53cea22 __scrt_acquire_startup_lock 70527->70531 70528->70531 70571 7ff6b53cf2b8 7 API calls 2 library calls 70528->70571 70530 7ff6b53cea96 70531->70511 70572 7ff6b53ceb80 70532->70572 70534 7ff6b53cebc5 70534->70514 70536 7ff6b53ddb28 70535->70536 70545 7ff6b53cf01d 70535->70545 70537 7ff6b53ddb30 70536->70537 70538 7ff6b53ddb46 70536->70538 70577 7ff6b53b4e68 11 API calls memcpy_s 70537->70577 70579 7ff6b53c64e4 70538->70579 70541 7ff6b53ddb35 70578 7ff6b53b8234 78 API calls _invalid_parameter_noinfo 70541->70578 70545->70509 70567 7ff6b53cf9bc InitializeSListHead 70545->70567 70546 7ff6b53ddb62 70586 7ff6b53dd8e0 78 API calls 70546->70586 70548 7ff6b53ddb9f 70587 7ff6b53ddaa8 11 API calls 2 library calls 70548->70587 70550 7ff6b53ddbb5 70551 7ff6b53ddbd5 70550->70551 70552 7ff6b53ddbbd 70550->70552 70589 7ff6b53dd8e0 78 API calls 70551->70589 70588 7ff6b53b4e68 11 API calls memcpy_s 70552->70588 70555 7ff6b53ddbc2 70556 7ff6b53bd3c8 __free_lconv_mon 11 API calls 70555->70556 70558 7ff6b53ddbd0 70556->70558 70557 7ff6b53ddbf7 70559 7ff6b53bd3c8 __free_lconv_mon 11 API calls 70557->70559 70558->70545 70559->70545 70560 7ff6b53ddbf1 70560->70557 70561 7ff6b53ddc23 70560->70561 70562 7ff6b53ddc3c 70560->70562 70563 7ff6b53bd3c8 __free_lconv_mon 11 API calls 70561->70563 70564 7ff6b53bd3c8 __free_lconv_mon 11 API calls 70562->70564 70565 7ff6b53ddc2c 70563->70565 70564->70557 70566 7ff6b53bd3c8 __free_lconv_mon 11 API calls 70565->70566 70566->70558 70568->70512 70569->70525 70570->70523 70571->70530 70573 7ff6b53ceb93 70572->70573 70574 7ff6b53ceb9a 70572->70574 70573->70534 70576 7ff6b53cbedc 81 API calls 70574->70576 70576->70573 70577->70541 70578->70545 70580 7ff6b53c64f1 70579->70580 70581 7ff6b53c6536 70579->70581 70590 7ff6b53b9fc0 83 API calls 3 library calls 70580->70590 70585 7ff6b53deb4c 86 API calls 2 library calls 70581->70585 70583 7ff6b53c6520 70591 7ff6b53c61bc 91 API calls 3 library calls 70583->70591 70585->70546 70586->70548 70587->70550 70588->70555 70589->70560 70590->70583 70591->70581 70593 7ff6b53cf417 GetStartupInfoW 70592->70593 70593->70395 70594->70421 70596 7ff6b539f878 GetTokenInformation 70595->70596 70597 7ff6b539f8b4 70595->70597 70596->70597 70598 7ff6b539f8c1 CloseHandle 70597->70598 70599 7ff6b539f8cd 70597->70599 70598->70599 70600 7ff6b53ce860 _Strcoll 8 API calls 70599->70600 70601 7ff6b539c620 70600->70601 70601->70427 70601->70428 70603 7ff6b53aba86 70602->70603 70604 7ff6b53aba1b LookupPrivilegeValueW 70602->70604 70606 7ff6b53aba8e CloseHandle 70603->70606 70607 7ff6b53aba9a 70603->70607 70604->70603 70605 7ff6b53aba3c AdjustTokenPrivileges 70604->70605 70605->70603 70606->70607 70608 7ff6b53ce860 _Strcoll 8 API calls 70607->70608 70609 7ff6b539c65a 70608->70609 70609->70434 70611 7ff6b539d052 70610->70611 70611->70611 70612 7ff6b5390920 83 API calls 70611->70612 70613 7ff6b539c6f6 70612->70613 70613->70441 70613->70442 70613->70445 71473 7ff6b53a58d0 GetUserGeoID GetGeoInfoA 70614->71473 70617 7ff6b537d590 82 API calls 70618 7ff6b539fd04 70617->70618 71479 7ff6b5361900 70618->71479 70620 7ff6b539fd4b 70621 7ff6b5361900 82 API calls 70620->70621 70622 7ff6b539fd88 70621->70622 70623 7ff6b5363ff0 82 API calls 70622->70623 70624 7ff6b539fdb2 WSAStartup 70623->70624 70625 7ff6b539fdcc socket 70624->70625 70633 7ff6b539fe87 _Receive_impl 70624->70633 70626 7ff6b539fe81 WSACleanup 70625->70626 70627 7ff6b539fdf2 htons 70625->70627 70626->70633 70628 7ff6b539ff28 70627->70628 70637 7ff6b539fe24 70627->70637 71503 7ff6b539eed0 SHGetKnownFolderPath 70628->71503 70629 7ff6b539febf _Receive_impl 70630 7ff6b53ce860 _Strcoll 8 API calls 70629->70630 70634 7ff6b539c7ae 70630->70634 70633->70629 70653 7ff6b53a002a 70633->70653 70634->70452 70634->70453 70636 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70640 7ff6b53a0030 70636->70640 70638 7ff6b539fe39 inet_pton connect 70637->70638 70643 7ff6b539fe74 closesocket 70637->70643 71497 7ff6b53ad830 70637->71497 70638->70637 70641 7ff6b539ff06 70638->70641 70645 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70640->70645 70641->70628 70648 7ff6b5364600 82 API calls 70641->70648 70642 7ff6b539ff4c _Receive_impl 70642->70640 70644 7ff6b539eed0 84 API calls 70642->70644 70643->70626 70646 7ff6b539ffb4 70644->70646 70647 7ff6b53a0036 70645->70647 70649 7ff6b53626d0 78 API calls 70646->70649 70648->70628 70650 7ff6b539ffca 70649->70650 70650->70633 70651 7ff6b53a0025 70650->70651 70652 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 70651->70652 70652->70653 70653->70636 71536 7ff6b53a6540 70654->71536 71468->70431 71469->70435 71470->70438 71474 7ff6b53627e0 82 API calls 71473->71474 71475 7ff6b53a5945 GetGeoInfoA 71474->71475 71477 7ff6b53627e0 82 API calls 71475->71477 71478 7ff6b539fce1 71477->71478 71478->70617 71480 7ff6b5361937 71479->71480 71481 7ff6b536193f 71479->71481 71531 7ff6b5367e80 82 API calls 2 library calls 71480->71531 71484 7ff6b53619d9 71481->71484 71521 7ff6b5367d40 71481->71521 71532 7ff6b5367f10 82 API calls 71484->71532 71486 7ff6b53ce860 _Strcoll 8 API calls 71490 7ff6b53619bf 71486->71490 71487 7ff6b53619f6 71491 7ff6b5367ac0 82 API calls 71487->71491 71488 7ff6b536195d 71489 7ff6b5361990 _Receive_impl 71488->71489 71492 7ff6b53619d4 71488->71492 71489->71486 71490->70620 71494 7ff6b5361a09 71491->71494 71493 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 71492->71493 71493->71484 71495 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 71494->71495 71496 7ff6b5361a1a 71495->71496 71498 7ff6b53ad84c 71497->71498 71500 7ff6b53ad87b BuildCatchObjectHelperInternal 71498->71500 71534 7ff6b53b89b0 80 API calls _Getctype 71498->71534 71502 7ff6b53ad8fa BuildCatchObjectHelperInternal 71500->71502 71535 7ff6b53b89b0 80 API calls _Getctype 71500->71535 71502->70637 71504 7ff6b539efe5 CoTaskMemFree 71503->71504 71505 7ff6b539ef37 71503->71505 71506 7ff6b53ce860 _Strcoll 8 API calls 71504->71506 71508 7ff6b5356940 82 API calls 71505->71508 71507 7ff6b539f000 71506->71507 71516 7ff6b53626d0 71507->71516 71509 7ff6b539ef69 71508->71509 71510 7ff6b53626d0 78 API calls 71509->71510 71511 7ff6b539ef8d 71510->71511 71512 7ff6b539efcd _Receive_impl 71511->71512 71513 7ff6b539f012 71511->71513 71512->71504 71514 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 71513->71514 71515 7ff6b539f017 71514->71515 71517 7ff6b53626e5 71516->71517 71518 7ff6b5362718 _Receive_impl 71516->71518 71517->71518 71519 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 71517->71519 71518->70642 71520 7ff6b5362761 71519->71520 71522 7ff6b5367d66 71521->71522 71523 7ff6b5367dac 71522->71523 71524 7ff6b5367e73 71522->71524 71530 7ff6b5367e1f 71522->71530 71525 7ff6b53ce888 std::_Facet_Register 82 API calls 71523->71525 71533 7ff6b534b9e0 82 API calls 71524->71533 71527 7ff6b5367dca 71525->71527 71529 7ff6b53637f0 82 API calls 71527->71529 71529->71530 71530->71488 71531->71481 71532->71487 71534->71498 71535->71500 71537 7ff6b53a6599 memcpy_s 71536->71537 71538 7ff6b53ce888 std::_Facet_Register 82 API calls 71537->71538 71539 7ff6b53a6603 71538->71539 71680 7ff6b536cad0 71539->71680 71541 7ff6b53a6648 EnumDisplayDevicesW 71547 7ff6b53a6665 _Receive_impl 71541->71547 71551 7ff6b53a6709 71541->71551 71542 7ff6b53978f0 84 API calls 71542->71547 71547->71542 71548 7ff6b53a66d1 EnumDisplayDevicesW 71547->71548 71552 7ff6b53a684f 71547->71552 71704 7ff6b53adbf0 82 API calls 2 library calls 71547->71704 71548->71547 71548->71551 71549 7ff6b5363d70 82 API calls 71549->71551 71551->71549 71553 7ff6b53a6711 71551->71553 71554 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 71552->71554 71698 7ff6b5372ec0 71553->71698 71555 7ff6b53a6854 71554->71555 71681 7ff6b536cafc 71680->71681 71692 7ff6b536cb9b _Receive_impl 71680->71692 71682 7ff6b536cc02 71681->71682 71683 7ff6b536cb21 71681->71683 71685 7ff6b536cb57 71681->71685 71686 7ff6b536cb2e 71681->71686 71705 7ff6b534b820 82 API calls 2 library calls 71682->71705 71690 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 71683->71690 71683->71692 71688 7ff6b53ce888 std::_Facet_Register 82 API calls 71685->71688 71686->71682 71687 7ff6b536cb3b 71686->71687 71689 7ff6b53ce888 std::_Facet_Register 82 API calls 71687->71689 71688->71683 71689->71683 71691 7ff6b536cc0d 71690->71691 71693 7ff6b536cc4a _Receive_impl 71691->71693 71694 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 71691->71694 71692->71541 71693->71541 71695 7ff6b536cc6a 71694->71695 71696 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 71695->71696 71697 7ff6b536ccb1 71696->71697 71702 7ff6b5372ed7 _Receive_impl 71698->71702 71700 7ff6b5372f27 71701 7ff6b53b8254 _invalid_parameter_noinfo_noreturn 78 API calls 71700->71701 71703 7ff6b5372f3f 71701->71703 71702->71700 71706 7ff6b537ca60 78 API calls 2 library calls 71702->71706 71704->71547 71705->71683 71706->71700 72583 7ff6b53cd32c 72584 7ff6b53cd345 72583->72584 72585 7ff6b53cd341 72583->72585 72586 7ff6b53c64e4 96 API calls 72584->72586 72587 7ff6b53cd34a 72586->72587 72598 7ff6b53ce244 GetEnvironmentStringsW 72587->72598 72590 7ff6b53cd363 72618 7ff6b53cd410 78 API calls 5 library calls 72590->72618 72591 7ff6b53cd357 72592 7ff6b53bd3c8 __free_lconv_mon 11 API calls 72591->72592 72592->72585 72594 7ff6b53cd36b 72595 7ff6b53bd3c8 __free_lconv_mon 11 API calls 72594->72595 72596 7ff6b53cd38a 72595->72596 72597 7ff6b53bd3c8 __free_lconv_mon 11 API calls 72596->72597 72597->72585 72599 7ff6b53cd34f 72598->72599 72600 7ff6b53ce274 72598->72600 72599->72590 72599->72591 72600->72600 72619 7ff6b53c34d4 WideCharToMultiByte 72600->72619 72618->72594 72620 7ff6b5371ef2 72621 7ff6b5374580 82 API calls 72620->72621 72622 7ff6b5371f16 72621->72622 72623 7ff6b536c600 82 API calls 72622->72623 72625 7ff6b5371f22 72623->72625 72624 7ff6b5371fb6 72626 7ff6b536b780 84 API calls 72624->72626 72625->72624 72689 7ff6b536e030 82 API calls memcpy_s 72625->72689 72628 7ff6b537241c 72626->72628 72630 7ff6b5371af0 84 API calls 72628->72630 72629 7ff6b5371fae 72631 7ff6b536c600 82 API calls 72629->72631 72632 7ff6b5372442 72630->72632 72631->72624 72633 7ff6b536bd00 84 API calls 72632->72633 72634 7ff6b5372452 72633->72634 72635 7ff6b5372b5a 72634->72635 72636 7ff6b5372461 72634->72636 72690 7ff6b5363e90 80 API calls 72635->72690 72638 7ff6b5362880 78 API calls 72636->72638 72640 7ff6b537246b 72638->72640 72639 7ff6b5372b66 72641 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 72639->72641 72642 7ff6b534eec0 13 API calls 72640->72642 72643 7ff6b5372b76 72641->72643 72644 7ff6b5372475 72642->72644 72691 7ff6b5363e90 80 API calls 72643->72691 72645 7ff6b5362880 78 API calls 72644->72645 72647 7ff6b537247f 72645->72647 72651 7ff6b5362880 78 API calls 72647->72651 72648 7ff6b5372b83 72649 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 72648->72649 72650 7ff6b5372b93 72649->72650 72692 7ff6b5374430 80 API calls 72650->72692 72653 7ff6b5372b06 72651->72653 72656 7ff6b536c4d0 78 API calls 72653->72656 72654 7ff6b5372ba0 72655 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 72654->72655 72657 7ff6b5372bb0 72655->72657 72658 7ff6b5372b14 72656->72658 72693 7ff6b5363e90 80 API calls 72657->72693 72660 7ff6b53ce860 _Strcoll 8 API calls 72658->72660 72662 7ff6b5372b26 72660->72662 72661 7ff6b5372bbd 72663 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 72661->72663 72664 7ff6b5372bcd 72663->72664 72694 7ff6b5363e90 80 API calls 72664->72694 72666 7ff6b5372bda 72667 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 72666->72667 72668 7ff6b5372bea 72667->72668 72695 7ff6b5363e90 80 API calls 72668->72695 72670 7ff6b5372bf7 72671 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 72670->72671 72672 7ff6b5372c07 72671->72672 72696 7ff6b5363e90 80 API calls 72672->72696 72674 7ff6b5372c14 72675 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 72674->72675 72676 7ff6b5372c24 72675->72676 72697 7ff6b5363e90 80 API calls 72676->72697 72678 7ff6b5372c31 72679 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 72678->72679 72680 7ff6b5372c41 72679->72680 72698 7ff6b5363e90 80 API calls 72680->72698 72682 7ff6b5372c4e 72683 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 72682->72683 72684 7ff6b5372c5e 72683->72684 72699 7ff6b5363e90 80 API calls 72684->72699 72686 7ff6b5372c6b 72687 7ff6b53d0e88 Concurrency::cancel_current_task 2 API calls 72686->72687 72688 7ff6b5372c7b 72687->72688 72689->72629 72690->72639 72691->72648 72692->72654 72693->72661 72694->72666 72695->72670 72696->72674 72697->72678 72698->72682 72699->72686 72700 7ff6b53b918c 72701 7ff6b53b91a2 72700->72701 72702 7ff6b53b91bd 72700->72702 72734 7ff6b53b4e68 11 API calls memcpy_s 72701->72734 72702->72701 72703 7ff6b53b91d6 72702->72703 72705 7ff6b53b91dc 72703->72705 72708 7ff6b53b91f9 72703->72708 72736 7ff6b53b4e68 11 API calls memcpy_s 72705->72736 72706 7ff6b53b91a7 72735 7ff6b53b8234 78 API calls _invalid_parameter_noinfo 72706->72735 72727 7ff6b53c33d0 72708->72727 72714 7ff6b53b9473 72715 7ff6b53b8284 _invalid_parameter_noinfo_noreturn 17 API calls 72714->72715 72717 7ff6b53b9488 72715->72717 72721 7ff6b53b923d 72722 7ff6b53b92b6 72721->72722 72723 7ff6b53b9256 72721->72723 72726 7ff6b53b91b3 72722->72726 72756 7ff6b53c3414 78 API calls _isindst 72722->72756 72723->72726 72755 7ff6b53c3414 78 API calls _isindst 72723->72755 72728 7ff6b53c33df 72727->72728 72729 7ff6b53b91fe 72727->72729 72757 7ff6b53bc3bc EnterCriticalSection 72728->72757 72737 7ff6b53c24e8 72729->72737 72734->72706 72735->72726 72736->72726 72738 7ff6b53c24f1 72737->72738 72739 7ff6b53b9213 72737->72739 72758 7ff6b53b4e68 11 API calls memcpy_s 72738->72758 72739->72714 72743 7ff6b53c2518 72739->72743 72741 7ff6b53c24f6 72759 7ff6b53b8234 78 API calls _invalid_parameter_noinfo 72741->72759 72744 7ff6b53c2521 72743->72744 72745 7ff6b53b9224 72743->72745 72760 7ff6b53b4e68 11 API calls memcpy_s 72744->72760 72745->72714 72749 7ff6b53c2548 72745->72749 72747 7ff6b53c2526 72761 7ff6b53b8234 78 API calls _invalid_parameter_noinfo 72747->72761 72750 7ff6b53c2551 72749->72750 72751 7ff6b53b9235 72749->72751 72762 7ff6b53b4e68 11 API calls memcpy_s 72750->72762 72751->72714 72751->72721 72753 7ff6b53c2556 72763 7ff6b53b8234 78 API calls _invalid_parameter_noinfo 72753->72763 72755->72726 72756->72726 72758->72741 72759->72739 72760->72747 72761->72745 72762->72753 72763->72751 72764 7ff6b5360af0 72765 7ff6b5360b08 72764->72765 72769 7ff6b5360b14 BuildCatchObjectHelperInternal 72764->72769 72766 7ff6b5360b25 BuildCatchObjectHelperInternal 72767 7ff6b5360c5e 72767->72766 72770 7ff6b53b7a44 _fread_nolock 87 API calls 72767->72770 72769->72766 72769->72767 72771 7ff6b53b7a44 72769->72771 72770->72766 72774 7ff6b53b7a64 72771->72774 72775 7ff6b53b7a8e 72774->72775 72776 7ff6b53b7a5c 72774->72776 72775->72776 72777 7ff6b53b7a9d memcpy_s 72775->72777 72778 7ff6b53b7ada 72775->72778 72776->72769 72788 7ff6b53b4e68 11 API calls memcpy_s 72777->72788 72787 7ff6b53b4934 EnterCriticalSection 72778->72787 72783 7ff6b53b7ab2 72789 7ff6b53b8234 78 API calls _invalid_parameter_noinfo 72783->72789 72788->72783 72789->72776 72790 7ff6b53ac5cb 72791 7ff6b53ac5f1 72790->72791 72806 7ff6b53ac5dc 72790->72806 72792 7ff6b53ac5fa 72791->72792 72807 7ff6b53ac7bf 72791->72807 72795 7ff6b53627e0 82 API calls 72792->72795 72810 7ff6b53ac652 72792->72810 72793 7ff6b53ac86f 72797 7ff6b53ad050 84 API calls 72793->72797 72794 7ff6b53ce860 _Strcoll 8 API calls 72796 7ff6b53aceb3 72794->72796 72795->72810 72799 7ff6b53ac888 72797->72799 72798 7ff6b53ad050 84 API calls 72798->72807 72804 7ff6b53ac570 8 API calls 72799->72804 72800 7ff6b53ac722 72803 7ff6b53ad050 84 API calls 72800->72803 72801 7ff6b53ac570 8 API calls 72801->72807 72802 7ff6b53ad050 84 API calls 72802->72810 72805 7ff6b53ac75b 72803->72805 72804->72806 72809 7ff6b53ac570 8 API calls 72805->72809 72806->72794 72807->72793 72807->72798 72807->72801 72808 7ff6b53ac570 8 API calls 72808->72810 72809->72806 72810->72800 72810->72802 72810->72808

                                                                        Control-flow Graph

                                                                        • Executed
                                                                        • Not Executed
                                                                        control_flow_graph 0 7ff6b53a8330-7ff6b53a87cc call 7ff6b53a6540 call 7ff6b53a6460 call 7ff6b53a6860 call 7ff6b53a6150 call 7ff6b53a61f0 call 7ff6b53a8030 call 7ff6b53a5fc0 call 7ff6b537d590 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 call 7ff6b537d590 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 call 7ff6b537d590 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 call 7ff6b537d590 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 GlobalMemoryStatusEx 63 7ff6b53a87ce-7ff6b53a87d3 0->63 64 7ff6b53a87d5-7ff6b53a87e6 0->64 65 7ff6b53a87ea-7ff6b53a8af1 call 7ff6b5363ff0 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 call 7ff6b537d590 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 call 7ff6b537d590 call 7ff6b53686b0 call 7ff6b5361900 63->65 64->65 96 7ff6b53a8af4-7ff6b53a8afc 65->96 96->96 97 7ff6b53a8afe-7ff6b53a8b6c call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 call 7ff6b53a5b70 96->97 106 7ff6b53a8b71-7ff6b53a8c6d call 7ff6b5365310 call 7ff6b53655e0 call 7ff6b53686b0 call 7ff6b5361900 97->106 107 7ff6b53a8b6e 97->107 116 7ff6b53a8c70-7ff6b53a8c78 106->116 107->106 116->116 117 7ff6b53a8c7a-7ff6b53a8cd7 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 116->117 124 7ff6b53a8cd9-7ff6b53a8ceb 117->124 125 7ff6b53a8d0b-7ff6b53a8d26 117->125 126 7ff6b53a8d06 call 7ff6b53ce880 124->126 127 7ff6b53a8ced-7ff6b53a8d00 124->127 128 7ff6b53a8d28-7ff6b53a8d39 125->128 129 7ff6b53a8d59-7ff6b53a8edc call 7ff6b53a59a0 call 7ff6b53655e0 call 7ff6b53686b0 call 7ff6b5361900 125->129 126->125 127->126 130 7ff6b53a9b0f-7ff6b53a9b14 call 7ff6b53b8254 127->130 132 7ff6b53a8d54 call 7ff6b53ce880 128->132 133 7ff6b53a8d3b-7ff6b53a8d4e 128->133 152 7ff6b53a8ee0-7ff6b53a8ee8 129->152 135 7ff6b53a9b15-7ff6b53a9b1a call 7ff6b53b8254 130->135 132->129 133->132 133->135 144 7ff6b53a9b1b-7ff6b53a9b20 call 7ff6b53b8254 135->144 151 7ff6b53a9b21-7ff6b53a9b26 call 7ff6b53b8254 144->151 157 7ff6b53a9b27-7ff6b53a9b2c call 7ff6b53b8254 151->157 152->152 154 7ff6b53a8eea-7ff6b53a8f3d call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 152->154 168 7ff6b53a8f70-7ff6b53a8fcd call 7ff6b53b840c call 7ff6b53b948c call 7ff6b53b9898 154->168 169 7ff6b53a8f3f-7ff6b53a8f50 154->169 163 7ff6b53a9b2d-7ff6b53a9b32 call 7ff6b53b8254 157->163 170 7ff6b53a9b33-7ff6b53a9b38 call 7ff6b53b8254 163->170 186 7ff6b53a8fd0-7ff6b53a8fd8 168->186 171 7ff6b53a8f52-7ff6b53a8f65 169->171 172 7ff6b53a8f6b call 7ff6b53ce880 169->172 179 7ff6b53a9b39-7ff6b53a9b3e call 7ff6b53b8254 170->179 171->144 171->172 172->168 185 7ff6b53a9b3f-7ff6b53a9b44 call 7ff6b53b8254 179->185 191 7ff6b53a9b45-7ff6b53a9b4a call 7ff6b53b8254 185->191 186->186 188 7ff6b53a8fda-7ff6b53a90dc call 7ff6b53686b0 call 7ff6b53655e0 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 186->188 218 7ff6b53a90de-7ff6b53a90ef 188->218 219 7ff6b53a910f-7ff6b53a9167 call 7ff6b53e1650 GetModuleFileNameA 188->219 197 7ff6b53a9b4b-7ff6b53a9b50 call 7ff6b53b8254 191->197 203 7ff6b53a9b51-7ff6b53a9b56 call 7ff6b53b8254 197->203 209 7ff6b53a9b57-7ff6b53a9b5c call 7ff6b53b8254 203->209 215 7ff6b53a9b5d-7ff6b53a9b62 call 7ff6b53b8254 209->215 223 7ff6b53a9b63-7ff6b53a9b68 call 7ff6b53b8254 215->223 221 7ff6b53a90f1-7ff6b53a9104 218->221 222 7ff6b53a910a call 7ff6b53ce880 218->222 229 7ff6b53a9170-7ff6b53a9178 219->229 221->151 221->222 222->219 229->229 230 7ff6b53a917a-7ff6b53a92a2 call 7ff6b53686b0 call 7ff6b5365310 call 7ff6b53655e0 call 7ff6b53686b0 call 7ff6b5361900 229->230 241 7ff6b53a92a5-7ff6b53a92ad 230->241 241->241 242 7ff6b53a92af-7ff6b53a930d call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 241->242 249 7ff6b53a9340-7ff6b53a935b 242->249 250 7ff6b53a930f-7ff6b53a9320 242->250 253 7ff6b53a938f-7ff6b53a93b9 call 7ff6b53a76a0 249->253 254 7ff6b53a935d-7ff6b53a936f 249->254 251 7ff6b53a9322-7ff6b53a9335 250->251 252 7ff6b53a933b call 7ff6b53ce880 250->252 251->157 251->252 252->249 261 7ff6b53a93be-7ff6b53a94ae call 7ff6b5365310 call 7ff6b53655e0 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 253->261 262 7ff6b53a93bb 253->262 256 7ff6b53a9371-7ff6b53a9384 254->256 257 7ff6b53a938a call 7ff6b53ce880 254->257 256->163 256->257 257->253 277 7ff6b53a94b0-7ff6b53a94c4 261->277 278 7ff6b53a94e4-7ff6b53a94fb 261->278 262->261 281 7ff6b53a94df call 7ff6b53ce880 277->281 282 7ff6b53a94c6-7ff6b53a94d9 277->282 279 7ff6b53a952e-7ff6b53a964c call 7ff6b5365310 call 7ff6b53655e0 call 7ff6b53686b0 call 7ff6b5361900 278->279 280 7ff6b53a94fd-7ff6b53a950e 278->280 295 7ff6b53a9651-7ff6b53a9658 279->295 283 7ff6b53a9510-7ff6b53a9523 280->283 284 7ff6b53a9529 call 7ff6b53ce880 280->284 281->278 282->170 282->281 283->179 283->284 284->279 295->295 296 7ff6b53a965a-7ff6b53a96b4 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 295->296 303 7ff6b53a96b6-7ff6b53a96ca 296->303 304 7ff6b53a96ea-7ff6b53a970a 296->304 305 7ff6b53a96e5 call 7ff6b53ce880 303->305 306 7ff6b53a96cc-7ff6b53a96df 303->306 307 7ff6b53a9710-7ff6b53a97dd call 7ff6b537d590 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b53686b0 call 7ff6b5361900 304->307 308 7ff6b53a97e2-7ff6b53a989e call 7ff6b53637f0 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b53686b0 call 7ff6b5361900 304->308 305->304 306->185 306->305 330 7ff6b53a98a3-7ff6b53a98bb call 7ff6b5363ff0 307->330 308->330 333 7ff6b53a98ee-7ff6b53a9909 330->333 334 7ff6b53a98bd-7ff6b53a98ce 330->334 337 7ff6b53a993c-7ff6b53a9953 333->337 338 7ff6b53a990b-7ff6b53a991c 333->338 335 7ff6b53a98d0-7ff6b53a98e3 334->335 336 7ff6b53a98e9 call 7ff6b53ce880 334->336 335->191 335->336 336->333 342 7ff6b53a9955-7ff6b53a9969 337->342 343 7ff6b53a9989-7ff6b53a99a3 337->343 340 7ff6b53a991e-7ff6b53a9931 338->340 341 7ff6b53a9937 call 7ff6b53ce880 338->341 340->197 340->341 341->337 347 7ff6b53a9984 call 7ff6b53ce880 342->347 348 7ff6b53a996b-7ff6b53a997e 342->348 344 7ff6b53a99a5-7ff6b53a99b9 343->344 345 7ff6b53a99d9-7ff6b53a99f3 343->345 350 7ff6b53a99d4 call 7ff6b53ce880 344->350 351 7ff6b53a99bb-7ff6b53a99ce 344->351 352 7ff6b53a99f5-7ff6b53a9a09 345->352 353 7ff6b53a9a29-7ff6b53a9a43 345->353 347->343 348->203 348->347 350->345 351->209 351->350 355 7ff6b53a9a24 call 7ff6b53ce880 352->355 356 7ff6b53a9a0b-7ff6b53a9a1e 352->356 357 7ff6b53a9a45-7ff6b53a9a59 353->357 358 7ff6b53a9a79-7ff6b53a9a93 353->358 355->353 356->215 356->355 362 7ff6b53a9a74 call 7ff6b53ce880 357->362 363 7ff6b53a9a5b-7ff6b53a9a6e 357->363 359 7ff6b53a9ac5-7ff6b53a9b08 call 7ff6b53ce860 358->359 360 7ff6b53a9a95-7ff6b53a9aa9 358->360 365 7ff6b53a9ac0 call 7ff6b53ce880 360->365 366 7ff6b53a9aab-7ff6b53a9abe 360->366 362->358 363->223 363->362 365->359 366->365 368 7ff6b53a9b09-7ff6b53a9b0e call 7ff6b53b8254 366->368 368->130
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$Name$DevicesDisplayEnum$ComputerFileGlobalMemoryModuleStatusUserValuewcsftime
                                                                        • String ID: %d-%m-%Y, %H:%M:%S$computer_name$cpu$gpu$ram$system$time$timezone$user_name
                                                                        • API String ID: 4122120932-1182675529
                                                                        • Opcode ID: 47549bb9430f832a63f100b11c70c733584b49f47b6301df7131baf4d82ebe30
                                                                        • Instruction ID: 19ffcfe1acc772a0f08d0f37ca0c2bcd3d568c6ca030d30e7ed34dbe44a3a128
                                                                        • Opcode Fuzzy Hash: 47549bb9430f832a63f100b11c70c733584b49f47b6301df7131baf4d82ebe30
                                                                        • Instruction Fuzzy Hash: 57E24023928BC585DB21CF28D8502ED77A1F789B98F405225EB9D47BAEEF38D654C700
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$CloseOpenQueryValue
                                                                        • String ID: content$directory_iterator::directory_iterator$exists$filename$status
                                                                        • API String ID: 1254564140-3429737954
                                                                        • Opcode ID: 08d93a35235c194d3b1ca12cb93cd232fe58cb5738402f082269f697cbfc0b25
                                                                        • Instruction ID: 41fe40ad7f160554ca144d1844b808fcf29855f35fcb99f6e07443b0fb565409
                                                                        • Opcode Fuzzy Hash: 08d93a35235c194d3b1ca12cb93cd232fe58cb5738402f082269f697cbfc0b25
                                                                        • Instruction Fuzzy Hash: 0EE26272A29BC189EB618F28D8403ED7365FB45B58F505225EB5C4BB9EEF78D684C300

                                                                        Control-flow Graph

                                                                        • Executed
                                                                        • Not Executed
                                                                        control_flow_graph 800 7ff6b5386350-7ff6b53869ee call 7ff6b534d4e0 call 7ff6b534d370 808 7ff6b53869f0-7ff6b53869f7 800->808 808->808 809 7ff6b53869f9-7ff6b538a9b7 call 7ff6b5375c20 call 7ff6b534d810 call 7ff6b534eaf0 call 7ff6b534e240 call 7ff6b53b8254 * 3 call 7ff6b534e1d0 call 7ff6b53b8254 call 7ff6b53639b0 call 7ff6b53679f0 call 7ff6b5367ac0 call 7ff6b53d0e88 call 7ff6b53b8254 * 2 call 7ff6b534cf70 call 7ff6b534e0c0 call 7ff6b534e1d0 call 7ff6b534e240 call 7ff6b53b8254 call 7ff6b534e1d0 * 2 call 7ff6b53b8254 call 7ff6b53639b0 call 7ff6b53679f0 call 7ff6b5367ac0 call 7ff6b53d0e88 call 7ff6b53b8254 call 7ff6b534e0c0 call 7ff6b534cf70 call 7ff6b53b8254 call 7ff6b534e240 call 7ff6b53b8254 * 3 call 7ff6b534e1d0 call 7ff6b53b8254 call 7ff6b53639b0 call 7ff6b53679f0 call 7ff6b5367ac0 call 7ff6b53d0e88 call 7ff6b53b8254 * 2 call 7ff6b534cf70 call 7ff6b534e0c0 call 7ff6b534e1d0 call 7ff6b534e240 call 7ff6b534e1d0 * 4 call 7ff6b534cf70 call 7ff6b534e1d0 * 3 call 7ff6b534cf70 call 7ff6b53b8254 * 3 call 7ff6b53a0040 call 7ff6b53e1650 GetModuleFileNameW 808->809 939 7ff6b538a9c0-7ff6b538a9c9 809->939 939->939 940 7ff6b538a9cb-7ff6b538abde call 7ff6b5356940 939->940 943 7ff6b538abe1-7ff6b538abea 940->943 943->943 944 7ff6b538abec-7ff6b538ae7d call 7ff6b5356940 call 7ff6b5356bd0 call 7ff6b5365fd0 943->944 954 7ff6b538ae80-7ff6b538ae89 944->954 954->954 955 7ff6b538ae8b-7ff6b538b11e call 7ff6b5356940 call 7ff6b5356bd0 call 7ff6b5365fd0 954->955 965 7ff6b538b121-7ff6b538b12a 955->965 965->965 966 7ff6b538b12c-7ff6b538b600 call 7ff6b5356940 call 7ff6b534d4a0 call 7ff6b5365fd0 965->966 979 7ff6b538b603-7ff6b538b60c 966->979 979->979 980 7ff6b538b60e-7ff6b538b8bd call 7ff6b5356940 call 7ff6b5356bd0 call 7ff6b5365fd0 979->980 990 7ff6b538b8c0-7ff6b538b8c9 980->990 990->990 991 7ff6b538b8cb-7ff6b538bb70 call 7ff6b5356940 call 7ff6b5356bd0 call 7ff6b5365fd0 990->991 1001 7ff6b538bb73-7ff6b538bb7c 991->1001 1001->1001 1002 7ff6b538bb7e-7ff6b538bd8b call 7ff6b5356940 call 7ff6b5356bd0 call 7ff6b5365fd0 1001->1002 1012 7ff6b538bd90-7ff6b538bd99 1002->1012 1012->1012 1013 7ff6b538bd9b-7ff6b538c0c7 call 7ff6b5356940 call 7ff6b5356bd0 call 7ff6b5365fd0 1012->1013 1023 7ff6b538c0d0-7ff6b538c0d8 1013->1023 1023->1023 1024 7ff6b538c0da-7ff6b538c326 call 7ff6b5356940 call 7ff6b5356bd0 call 7ff6b5365fd0 call 7ff6b534cf70 call 7ff6b5385d70 1023->1024
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: __std_fs_convert_wide_to_narrow$__std_fs_code_page
                                                                        • String ID: cannot use push_back() with $directory_iterator::directory_iterator$exists$recursive_directory_iterator::operator++$recursive_directory_iterator::recursive_directory_iterator$status
                                                                        • API String ID: 3645842244-1862120484
                                                                        • Opcode ID: de5a621f2f067d1123de94e788919e3c44fbe91b6b887da37095cf4d544f4034
                                                                        • Instruction ID: 6172aeb8a1c4338bb6b32b193b84b34d0632a8be24e38191061d35afe7161019
                                                                        • Opcode Fuzzy Hash: de5a621f2f067d1123de94e788919e3c44fbe91b6b887da37095cf4d544f4034
                                                                        • Instruction Fuzzy Hash: 03D20872919BC585D6708B19F4812EAB3A0FBD8B84F405225EBCC97B5AEF7CD654CB00

                                                                        Control-flow Graph

                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Object$DeleteMetricsSystem$CreateSelectStream_$CapsCompatibleCriticalDeviceReleaseSection$BitmapEnterLeaveReadResetSizeStream
                                                                        • String ID:
                                                                        • API String ID: 3214587331-3916222277
                                                                        • Opcode ID: 7f29424d3ead8c8ab7e32e0c66aef27a74aa28fe3180dede61f6c59901bdf73b
                                                                        • Instruction ID: 88f0cfa4b48d7122112b0073adfaee6b2715bb48a0acc837d2c07eb7fa9394f3
                                                                        • Opcode Fuzzy Hash: 7f29424d3ead8c8ab7e32e0c66aef27a74aa28fe3180dede61f6c59901bdf73b
                                                                        • Instruction Fuzzy Hash: D4B13172618BC186E760DB25E8543EEB7A5FB89B80F405535DB8E83B5AEF3CD4448B40

                                                                        Control-flow Graph

                                                                        • Executed
                                                                        • Not Executed
                                                                        control_flow_graph 1078 7ff6b535d570-7ff6b535d66f LoadLibraryA 1079 7ff6b535d675-7ff6b535da30 GetProcAddress * 6 1078->1079 1080 7ff6b535e530-7ff6b535e53a 1078->1080 1079->1080 1081 7ff6b535da36-7ff6b535da39 1079->1081 1082 7ff6b535e53c-7ff6b535e53e 1080->1082 1083 7ff6b535e549-7ff6b535e54c 1080->1083 1081->1080 1084 7ff6b535da3f-7ff6b535da42 1081->1084 1082->1083 1085 7ff6b535e557-7ff6b535e586 call 7ff6b53ce860 1083->1085 1086 7ff6b535e54e-7ff6b535e551 FreeLibrary 1083->1086 1084->1080 1088 7ff6b535da48-7ff6b535da4b 1084->1088 1086->1085 1088->1080 1091 7ff6b535da51-7ff6b535da54 1088->1091 1091->1080 1092 7ff6b535da5a-7ff6b535da5d 1091->1092 1092->1080 1093 7ff6b535da63-7ff6b535da71 1092->1093 1094 7ff6b535da75-7ff6b535da77 1093->1094 1094->1080 1095 7ff6b535da7d-7ff6b535da89 1094->1095 1095->1080 1096 7ff6b535da8f-7ff6b535da98 1095->1096 1097 7ff6b535daa0-7ff6b535dabb 1096->1097 1099 7ff6b535e517-7ff6b535e523 1097->1099 1100 7ff6b535dac1-7ff6b535dadf 1097->1100 1099->1097 1101 7ff6b535e529 1099->1101 1100->1099 1103 7ff6b535dae5-7ff6b535daf7 1100->1103 1101->1080 1104 7ff6b535dafd 1103->1104 1105 7ff6b535e503-7ff6b535e512 1103->1105 1106 7ff6b535db02-7ff6b535db53 call 7ff6b53ce888 1104->1106 1105->1099 1111 7ff6b535db59-7ff6b535db60 1106->1111 1112 7ff6b535ddd2 1106->1112 1111->1112 1113 7ff6b535db66-7ff6b535dc5f call 7ff6b53978f0 call 7ff6b5365310 call 7ff6b53655e0 1111->1113 1114 7ff6b535ddd4-7ff6b535dddb 1112->1114 1139 7ff6b535dc60-7ff6b535dc68 1113->1139 1116 7ff6b535e051-7ff6b535e08d 1114->1116 1117 7ff6b535dde1-7ff6b535dde8 1114->1117 1125 7ff6b535e327-7ff6b535e329 1116->1125 1126 7ff6b535e093-7ff6b535e0a1 1116->1126 1117->1116 1119 7ff6b535ddee-7ff6b535dedb call 7ff6b53978f0 call 7ff6b5365310 call 7ff6b53655e0 1117->1119 1151 7ff6b535dee2-7ff6b535deea 1119->1151 1129 7ff6b535e4d5-7ff6b535e4eb call 7ff6b53600f0 1125->1129 1130 7ff6b535e32f-7ff6b535e458 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 call 7ff6b53ce888 call 7ff6b53851b0 1125->1130 1127 7ff6b535e0a7-7ff6b535e0ae 1126->1127 1128 7ff6b535e320-7ff6b535e323 1126->1128 1127->1128 1136 7ff6b535e0b4-7ff6b535e1a8 call 7ff6b53978f0 call 7ff6b5365310 call 7ff6b53655e0 1127->1136 1128->1125 1133 7ff6b535e325 1128->1133 1145 7ff6b535e4f1-7ff6b535e4fc 1129->1145 1146 7ff6b535db00 1129->1146 1221 7ff6b535e45a-7ff6b535e45c 1130->1221 1222 7ff6b535e464-7ff6b535e477 call 7ff6b53637f0 1130->1222 1133->1125 1168 7ff6b535e1b0-7ff6b535e1b7 1136->1168 1139->1139 1144 7ff6b535dc6a-7ff6b535dcc4 call 7ff6b53686b0 call 7ff6b5366bc0 call 7ff6b5363ff0 1139->1144 1174 7ff6b535dcf7-7ff6b535dd21 1144->1174 1175 7ff6b535dcc6-7ff6b535dcd7 1144->1175 1145->1105 1146->1106 1151->1151 1155 7ff6b535deec-7ff6b535df45 call 7ff6b53686b0 call 7ff6b5366bc0 call 7ff6b5363ff0 1151->1155 1190 7ff6b535df47-7ff6b535df58 1155->1190 1191 7ff6b535df78-7ff6b535dfa2 1155->1191 1168->1168 1172 7ff6b535e1b9-7ff6b535e212 call 7ff6b53686b0 call 7ff6b5366bc0 call 7ff6b5363ff0 1168->1172 1231 7ff6b535e245-7ff6b535e26e 1172->1231 1232 7ff6b535e214-7ff6b535e225 1172->1232 1183 7ff6b535dd59-7ff6b535dd7f 1174->1183 1184 7ff6b535dd23-7ff6b535dd37 1174->1184 1179 7ff6b535dcd9-7ff6b535dcec 1175->1179 1180 7ff6b535dcf2 call 7ff6b53ce880 1175->1180 1179->1180 1188 7ff6b535e5e1-7ff6b535e5e6 call 7ff6b53b8254 1179->1188 1180->1174 1186 7ff6b535ddb7-7ff6b535ddd0 1183->1186 1187 7ff6b535dd81-7ff6b535dd95 1183->1187 1193 7ff6b535dd39-7ff6b535dd4c 1184->1193 1194 7ff6b535dd52-7ff6b535dd57 call 7ff6b53ce880 1184->1194 1186->1114 1201 7ff6b535dd97-7ff6b535ddaa 1187->1201 1202 7ff6b535ddb0-7ff6b535ddb5 call 7ff6b53ce880 1187->1202 1206 7ff6b535e5e7-7ff6b535e5ec call 7ff6b53b8254 1188->1206 1203 7ff6b535df5a-7ff6b535df6d 1190->1203 1204 7ff6b535df73 call 7ff6b53ce880 1190->1204 1196 7ff6b535dfda-7ff6b535e000 1191->1196 1197 7ff6b535dfa4-7ff6b535dfb8 1191->1197 1193->1194 1193->1206 1194->1183 1213 7ff6b535e038-7ff6b535e04a 1196->1213 1214 7ff6b535e002-7ff6b535e016 1196->1214 1207 7ff6b535dfba-7ff6b535dfcd 1197->1207 1208 7ff6b535dfd3-7ff6b535dfd8 call 7ff6b53ce880 1197->1208 1201->1202 1212 7ff6b535e5ed-7ff6b535e5f2 call 7ff6b53b8254 1201->1212 1202->1186 1203->1204 1217 7ff6b535e5f3-7ff6b535e5f8 call 7ff6b53b8254 1203->1217 1204->1191 1206->1212 1207->1208 1220 7ff6b535e5f9-7ff6b535e5fe call 7ff6b53b8254 1207->1220 1208->1196 1212->1217 1213->1116 1224 7ff6b535e018-7ff6b535e02b 1214->1224 1225 7ff6b535e031-7ff6b535e036 call 7ff6b53ce880 1214->1225 1217->1220 1237 7ff6b535e5ff-7ff6b535e604 call 7ff6b53b8254 1220->1237 1233 7ff6b535e58d-7ff6b535e5da call 7ff6b53639b0 call 7ff6b53679f0 call 7ff6b5367ac0 call 7ff6b53d0e88 1221->1233 1234 7ff6b535e462 1221->1234 1246 7ff6b535e47b-7ff6b535e487 1222->1246 1224->1225 1224->1237 1225->1213 1247 7ff6b535e2a4-7ff6b535e2ca 1231->1247 1248 7ff6b535e270-7ff6b535e284 1231->1248 1243 7ff6b535e227-7ff6b535e23a 1232->1243 1244 7ff6b535e240 call 7ff6b53ce880 1232->1244 1274 7ff6b535e5db-7ff6b535e5e0 call 7ff6b53b8254 1233->1274 1234->1246 1252 7ff6b535e605-7ff6b535e60a call 7ff6b53b8254 1237->1252 1243->1244 1243->1252 1244->1231 1257 7ff6b535e489-7ff6b535e4ac 1246->1257 1258 7ff6b535e4ae-7ff6b535e4b8 call 7ff6b5370610 1246->1258 1260 7ff6b535e2cc-7ff6b535e2e0 1247->1260 1261 7ff6b535e300-7ff6b535e319 1247->1261 1255 7ff6b535e286-7ff6b535e299 1248->1255 1256 7ff6b535e29f call 7ff6b53ce880 1248->1256 1255->1256 1263 7ff6b535e587-7ff6b535e58c call 7ff6b53b8254 1255->1263 1256->1247 1265 7ff6b535e4bd-7ff6b535e4ce call 7ff6b5363ff0 1257->1265 1258->1265 1268 7ff6b535e2fb call 7ff6b53ce880 1260->1268 1269 7ff6b535e2e2-7ff6b535e2f5 1260->1269 1261->1128 1263->1233 1265->1129 1268->1261 1269->1268 1269->1274 1274->1188
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$AddressProc$Library$FreeLoad
                                                                        • String ID: cannot use push_back() with $system$vault
                                                                        • API String ID: 2463004387-1741236777
                                                                        • Opcode ID: 959340eb615a1682f845dd131be92ac56e9c315d7ee255850b7a169114a46494
                                                                        • Instruction ID: fc07bd6d355852bb7866a4a30db16c243fcbfb522eadb6800519546789edd246
                                                                        • Opcode Fuzzy Hash: 959340eb615a1682f845dd131be92ac56e9c315d7ee255850b7a169114a46494
                                                                        • Instruction Fuzzy Hash: 38926072619BC589DB618F29E8843ED77A0F749B98F104225DB9C4BB9DEF78D644C300

                                                                        Control-flow Graph

                                                                        • Executed
                                                                        • Not Executed
                                                                        control_flow_graph 1285 7ff6b5352ca0-7ff6b5352d72 1286 7ff6b5352d75-7ff6b5352d7c 1285->1286 1286->1286 1287 7ff6b5352d7e-7ff6b5352efe call 7ff6b53686b0 1286->1287 1290 7ff6b5352f01-7ff6b5352f09 1287->1290 1290->1290 1291 7ff6b5352f0b-7ff6b5352f93 call 7ff6b53686b0 1290->1291 1294 7ff6b5352f96-7ff6b5352f9e 1291->1294 1294->1294 1295 7ff6b5352fa0-7ff6b535302a call 7ff6b53686b0 RegOpenKeyExA 1294->1295 1298 7ff6b53530ee-7ff6b53530f5 1295->1298 1299 7ff6b5353030-7ff6b5353072 RegQueryValueExA 1295->1299 1300 7ff6b53530fd-7ff6b5353168 call 7ff6b5375c20 1298->1300 1301 7ff6b53530f7 RegCloseKey 1298->1301 1299->1298 1302 7ff6b5353074-7ff6b53530b2 call 7ff6b53686b0 call 7ff6b53628e0 1299->1302 1307 7ff6b535316a-7ff6b535317c 1300->1307 1308 7ff6b535319c-7ff6b53531af 1300->1308 1301->1300 1320 7ff6b53530b4-7ff6b53530c5 1302->1320 1321 7ff6b53530e5-7ff6b53530ea 1302->1321 1310 7ff6b5353197 call 7ff6b53ce880 1307->1310 1311 7ff6b535317e-7ff6b5353191 1307->1311 1312 7ff6b535382b-7ff6b5353836 1308->1312 1313 7ff6b53531b5-7ff6b53531f5 call 7ff6b534eaf0 1308->1313 1310->1308 1311->1310 1317 7ff6b53539d1-7ff6b53539d6 call 7ff6b53b8254 1311->1317 1315 7ff6b5353838-7ff6b535384e 1312->1315 1316 7ff6b535386e-7ff6b5353890 1312->1316 1338 7ff6b53531fb-7ff6b53531fe 1313->1338 1339 7ff6b53539a7-7ff6b53539a9 1313->1339 1322 7ff6b5353869 call 7ff6b53ce880 1315->1322 1323 7ff6b5353850-7ff6b5353863 1315->1323 1325 7ff6b53538c6-7ff6b53538e0 1316->1325 1326 7ff6b5353892-7ff6b53538a6 1316->1326 1345 7ff6b53539d7-7ff6b53539e9 call 7ff6b534e1d0 1317->1345 1328 7ff6b53530c7-7ff6b53530da 1320->1328 1329 7ff6b53530e0 call 7ff6b53ce880 1320->1329 1321->1298 1322->1316 1323->1322 1331 7ff6b53539f0-7ff6b53539f5 call 7ff6b53b8254 1323->1331 1336 7ff6b5353916-7ff6b5353930 1325->1336 1337 7ff6b53538e2-7ff6b53538f6 1325->1337 1334 7ff6b53538a8-7ff6b53538bb 1326->1334 1335 7ff6b53538c1 call 7ff6b53ce880 1326->1335 1328->1329 1340 7ff6b53539cb-7ff6b53539d0 call 7ff6b53b8254 1328->1340 1329->1321 1365 7ff6b53539f6-7ff6b5353a05 call 7ff6b534e1d0 1331->1365 1334->1335 1346 7ff6b5353a1e-7ff6b5353a23 call 7ff6b53b8254 1334->1346 1335->1325 1342 7ff6b5353962-7ff6b53539a6 call 7ff6b53ce860 1336->1342 1343 7ff6b5353932-7ff6b5353946 1336->1343 1351 7ff6b53538f8-7ff6b535390b 1337->1351 1352 7ff6b5353911 call 7ff6b53ce880 1337->1352 1338->1312 1341 7ff6b5353204-7ff6b535322b call 7ff6b534d020 1338->1341 1347 7ff6b53539ab 1339->1347 1348 7ff6b53539b6-7ff6b53539ca call 7ff6b534e240 1339->1348 1340->1317 1374 7ff6b535329c-7ff6b5353305 call 7ff6b5356940 call 7ff6b5365140 1341->1374 1375 7ff6b535322d 1341->1375 1356 7ff6b535395d call 7ff6b53ce880 1343->1356 1357 7ff6b5353948-7ff6b535395b 1343->1357 1377 7ff6b53539ea-7ff6b53539ef call 7ff6b53b8254 1345->1377 1363 7ff6b5353a24-7ff6b5353a29 call 7ff6b53b8254 1346->1363 1347->1312 1348->1340 1351->1352 1351->1363 1352->1336 1356->1342 1357->1356 1369 7ff6b53539b0-7ff6b53539b5 call 7ff6b53b8254 1357->1369 1384 7ff6b5353a06-7ff6b5353a0b call 7ff6b53b8254 1365->1384 1369->1348 1374->1345 1396 7ff6b535330b-7ff6b535331a 1374->1396 1381 7ff6b5353230-7ff6b5353237 1375->1381 1377->1331 1386 7ff6b5353239-7ff6b535323d 1381->1386 1387 7ff6b535323f-7ff6b5353246 1381->1387 1395 7ff6b5353a0c-7ff6b5353a11 call 7ff6b53b8254 1384->1395 1386->1387 1391 7ff6b5353248-7ff6b535324b 1386->1391 1387->1381 1387->1391 1391->1374 1394 7ff6b535324d 1391->1394 1397 7ff6b5353250-7ff6b535325c 1394->1397 1410 7ff6b5353a12-7ff6b5353a17 call 7ff6b53b8254 1395->1410 1399 7ff6b535331c-7ff6b5353332 1396->1399 1400 7ff6b5353352-7ff6b5353382 1396->1400 1401 7ff6b535326e-7ff6b5353271 1397->1401 1402 7ff6b535325e-7ff6b5353262 1397->1402 1404 7ff6b535334d call 7ff6b53ce880 1399->1404 1405 7ff6b5353334-7ff6b5353347 1399->1405 1407 7ff6b535338c-7ff6b53533cb call 7ff6b534e8c0 1400->1407 1408 7ff6b5353384-7ff6b5353388 1400->1408 1401->1374 1409 7ff6b5353273-7ff6b5353277 1401->1409 1402->1401 1406 7ff6b5353264-7ff6b535326a 1402->1406 1404->1400 1405->1377 1405->1404 1406->1397 1412 7ff6b535326c 1406->1412 1419 7ff6b53533da-7ff6b5353404 call 7ff6b534e9a0 1407->1419 1420 7ff6b53533cd-7ff6b53533d6 1407->1420 1408->1407 1414 7ff6b5353280-7ff6b535328c 1409->1414 1423 7ff6b5353a18-7ff6b5353a1d call 7ff6b534cf70 1410->1423 1412->1374 1416 7ff6b5353294-7ff6b535329a 1414->1416 1417 7ff6b535328e-7ff6b5353292 1414->1417 1416->1374 1416->1414 1417->1374 1417->1416 1426 7ff6b535340a 1419->1426 1427 7ff6b5353789-7ff6b5353793 1419->1427 1420->1419 1423->1346 1429 7ff6b5353410-7ff6b5353431 call 7ff6b534eaf0 1426->1429 1430 7ff6b5353795-7ff6b535379f 1427->1430 1431 7ff6b53537bf-7ff6b53537c9 1427->1431 1439 7ff6b5353433-7ff6b535343b 1429->1439 1440 7ff6b5353441-7ff6b5353444 1429->1440 1430->1431 1435 7ff6b53537a1-7ff6b53537b3 1430->1435 1432 7ff6b53537cb-7ff6b53537d5 1431->1432 1433 7ff6b53537f5-7ff6b53537fc 1431->1433 1432->1433 1436 7ff6b53537d7-7ff6b53537e9 1432->1436 1433->1312 1438 7ff6b53537fe-7ff6b5353808 1433->1438 1435->1431 1446 7ff6b53537b5-7ff6b53537be 1435->1446 1436->1433 1447 7ff6b53537eb-7ff6b53537f4 1436->1447 1438->1312 1441 7ff6b535380a-7ff6b535381e 1438->1441 1439->1365 1439->1440 1444 7ff6b535344a-7ff6b5353461 call 7ff6b539f8f0 1440->1444 1445 7ff6b5353769-7ff6b5353783 call 7ff6b534e7b0 1440->1445 1441->1312 1454 7ff6b5353820-7ff6b535382a 1441->1454 1456 7ff6b535375d-7ff6b5353764 call 7ff6b534f380 1444->1456 1457 7ff6b5353467-7ff6b53534b0 call 7ff6b5363a40 call 7ff6b534d4e0 call 7ff6b534d370 1444->1457 1445->1427 1445->1429 1446->1431 1447->1433 1454->1312 1456->1445 1466 7ff6b53534b2 1457->1466 1467 7ff6b53534b5-7ff6b5353554 call 7ff6b5365310 call 7ff6b53655e0 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 1457->1467 1466->1467 1478 7ff6b5353556-7ff6b5353567 1467->1478 1479 7ff6b5353587-7ff6b535359f 1467->1479 1480 7ff6b5353569-7ff6b535357c 1478->1480 1481 7ff6b5353582 call 7ff6b53ce880 1478->1481 1482 7ff6b53535d2-7ff6b53535ea 1479->1482 1483 7ff6b53535a1-7ff6b53535b2 1479->1483 1480->1384 1480->1481 1481->1479 1487 7ff6b53535ec-7ff6b5353602 1482->1487 1488 7ff6b5353622-7ff6b5353643 1482->1488 1485 7ff6b53535cd call 7ff6b53ce880 1483->1485 1486 7ff6b53535b4-7ff6b53535c7 1483->1486 1485->1482 1486->1395 1486->1485 1491 7ff6b535361d call 7ff6b53ce880 1487->1491 1492 7ff6b5353604-7ff6b5353617 1487->1492 1488->1423 1489 7ff6b5353649-7ff6b535375c call 7ff6b537d590 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 call 7ff6b53629b0 call 7ff6b5361900 call 7ff6b53629b0 call 7ff6b5361900 call 7ff6b53617a0 call 7ff6b5363ff0 1488->1489 1489->1456 1491->1488 1492->1410 1492->1491
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$CloseOpenQueryValue
                                                                        • String ID: content$directory_iterator::directory_iterator$exists$filename$status
                                                                        • API String ID: 1254564140-3429737954
                                                                        • Opcode ID: c68d1b0223e9d2953e45b434fa426007baeddbc17e6c4ca0c4c75fbc2e2c51ba
                                                                        • Instruction ID: 7e0a6c76bfe1b63df5fc8439b1fb1041549aab356a680185d1e9fbdcd247ba59
                                                                        • Opcode Fuzzy Hash: c68d1b0223e9d2953e45b434fa426007baeddbc17e6c4ca0c4c75fbc2e2c51ba
                                                                        • Instruction Fuzzy Hash: 18827072A15BC589DB608F38D8403ED73A1FB89B58F505225EB9D47B9AEF38D984C340

                                                                        Control-flow Graph

                                                                        • Executed
                                                                        • Not Executed
                                                                        control_flow_graph 1514 7ff6b53520b0-7ff6b5352182 1515 7ff6b5352185-7ff6b535218c 1514->1515 1515->1515 1516 7ff6b535218e-7ff6b53522ea call 7ff6b53686b0 1515->1516 1519 7ff6b53522f0-7ff6b53522f8 1516->1519 1519->1519 1520 7ff6b53522fa-7ff6b5352378 call 7ff6b53686b0 1519->1520 1523 7ff6b5352380-7ff6b5352388 1520->1523 1523->1523 1524 7ff6b535238a-7ff6b5352411 call 7ff6b53686b0 RegOpenKeyExA 1523->1524 1527 7ff6b5352417-7ff6b5352456 RegQueryValueExA 1524->1527 1528 7ff6b53524ee-7ff6b53524f5 1524->1528 1527->1528 1531 7ff6b535245c-7ff6b53524a9 call 7ff6b53686b0 call 7ff6b53628e0 1527->1531 1529 7ff6b53524fd-7ff6b535256e call 7ff6b5375c20 1528->1529 1530 7ff6b53524f7 RegCloseKey 1528->1530 1536 7ff6b53525a2-7ff6b53525b5 1529->1536 1537 7ff6b5352570-7ff6b5352582 1529->1537 1530->1529 1549 7ff6b53524ab-7ff6b53524bf 1531->1549 1550 7ff6b53524df-7ff6b53524e7 1531->1550 1541 7ff6b53525bb-7ff6b5352601 call 7ff6b534eaf0 1536->1541 1542 7ff6b5352aa3-7ff6b5352aae 1536->1542 1539 7ff6b535259d call 7ff6b53ce880 1537->1539 1540 7ff6b5352584-7ff6b5352597 1537->1540 1539->1536 1540->1539 1546 7ff6b5352c55-7ff6b5352c5a call 7ff6b53b8254 1540->1546 1566 7ff6b5352607-7ff6b535260a 1541->1566 1567 7ff6b5352c25-7ff6b5352c27 1541->1567 1544 7ff6b5352ae9-7ff6b5352b0e 1542->1544 1545 7ff6b5352ab0-7ff6b5352ac9 1542->1545 1554 7ff6b5352b44-7ff6b5352b5e 1544->1554 1555 7ff6b5352b10-7ff6b5352b24 1544->1555 1551 7ff6b5352acb-7ff6b5352ade 1545->1551 1552 7ff6b5352ae4 call 7ff6b53ce880 1545->1552 1573 7ff6b5352c5b-7ff6b5352c70 call 7ff6b534e1d0 1546->1573 1557 7ff6b53524da call 7ff6b53ce880 1549->1557 1558 7ff6b53524c1-7ff6b53524d4 1549->1558 1550->1528 1551->1552 1559 7ff6b5352c71-7ff6b5352c76 call 7ff6b53b8254 1551->1559 1552->1544 1564 7ff6b5352b94-7ff6b5352bae 1554->1564 1565 7ff6b5352b60-7ff6b5352b74 1554->1565 1562 7ff6b5352b26-7ff6b5352b39 1555->1562 1563 7ff6b5352b3f call 7ff6b53ce880 1555->1563 1557->1550 1558->1557 1568 7ff6b5352c4f-7ff6b5352c54 call 7ff6b53b8254 1558->1568 1601 7ff6b5352c77-7ff6b5352c7c call 7ff6b53b8254 1559->1601 1562->1563 1574 7ff6b5352c8f-7ff6b5352c94 call 7ff6b53b8254 1562->1574 1563->1554 1570 7ff6b5352be0-7ff6b5352c24 call 7ff6b53ce860 1564->1570 1571 7ff6b5352bb0-7ff6b5352bc4 1564->1571 1579 7ff6b5352b76-7ff6b5352b89 1565->1579 1580 7ff6b5352b8f call 7ff6b53ce880 1565->1580 1566->1542 1581 7ff6b5352610-7ff6b535262d call 7ff6b5365140 1566->1581 1575 7ff6b5352c29 1567->1575 1576 7ff6b5352c34-7ff6b5352c4e call 7ff6b534e240 1567->1576 1568->1546 1586 7ff6b5352bdb call 7ff6b53ce880 1571->1586 1587 7ff6b5352bc6-7ff6b5352bd9 1571->1587 1573->1559 1583 7ff6b5352c95-7ff6b5352c9a call 7ff6b53b8254 1574->1583 1575->1542 1576->1568 1579->1580 1579->1583 1580->1564 1581->1573 1602 7ff6b5352633-7ff6b535264e 1581->1602 1586->1570 1587->1586 1595 7ff6b5352c2e-7ff6b5352c33 call 7ff6b53b8254 1587->1595 1595->1576 1610 7ff6b5352c7d-7ff6b5352c82 call 7ff6b53b8254 1601->1610 1607 7ff6b5352658-7ff6b535268e call 7ff6b534e8c0 1602->1607 1608 7ff6b5352650-7ff6b5352654 1602->1608 1615 7ff6b535269d-7ff6b53526be call 7ff6b534e9a0 1607->1615 1616 7ff6b5352690-7ff6b5352699 1607->1616 1608->1607 1617 7ff6b5352c83-7ff6b5352c88 call 7ff6b53b8254 1610->1617 1622 7ff6b53526c4-7ff6b53526c8 1615->1622 1623 7ff6b5352a01-7ff6b5352a0b 1615->1623 1616->1615 1624 7ff6b5352c89-7ff6b5352c8e call 7ff6b534cf70 1617->1624 1625 7ff6b53526d0-7ff6b53526e5 call 7ff6b539f8f0 1622->1625 1626 7ff6b5352a0d-7ff6b5352a17 1623->1626 1627 7ff6b5352a37-7ff6b5352a41 1623->1627 1624->1574 1638 7ff6b53526eb-7ff6b5352737 call 7ff6b5363a40 call 7ff6b534d4e0 call 7ff6b534d370 1625->1638 1639 7ff6b53529de-7ff6b53529fb call 7ff6b534f380 call 7ff6b534e7b0 1625->1639 1626->1627 1632 7ff6b5352a19-7ff6b5352a2b 1626->1632 1628 7ff6b5352a6d-7ff6b5352a74 1627->1628 1629 7ff6b5352a43-7ff6b5352a4d 1627->1629 1628->1542 1635 7ff6b5352a76-7ff6b5352a80 1628->1635 1629->1628 1633 7ff6b5352a4f-7ff6b5352a61 1629->1633 1632->1627 1642 7ff6b5352a2d-7ff6b5352a36 1632->1642 1633->1628 1646 7ff6b5352a63-7ff6b5352a6c 1633->1646 1635->1542 1637 7ff6b5352a82-7ff6b5352a96 1635->1637 1637->1542 1649 7ff6b5352a98-7ff6b5352aa2 1637->1649 1659 7ff6b535273c-7ff6b53527db call 7ff6b5365310 call 7ff6b53655e0 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 1638->1659 1660 7ff6b5352739 1638->1660 1639->1623 1639->1625 1642->1627 1646->1628 1649->1542 1671 7ff6b53527dd-7ff6b53527ee 1659->1671 1672 7ff6b535280e-7ff6b5352826 1659->1672 1660->1659 1673 7ff6b5352809 call 7ff6b53ce880 1671->1673 1674 7ff6b53527f0-7ff6b5352803 1671->1674 1675 7ff6b5352828-7ff6b5352839 1672->1675 1676 7ff6b5352859-7ff6b5352871 1672->1676 1673->1672 1674->1601 1674->1673 1678 7ff6b535283b-7ff6b535284e 1675->1678 1679 7ff6b5352854 call 7ff6b53ce880 1675->1679 1680 7ff6b53528a9-7ff6b53528c7 1676->1680 1681 7ff6b5352873-7ff6b5352889 1676->1681 1678->1610 1678->1679 1679->1676 1680->1624 1682 7ff6b53528cd-7ff6b53529dd call 7ff6b537d590 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 call 7ff6b53629b0 call 7ff6b5361900 call 7ff6b53629b0 call 7ff6b5361900 call 7ff6b53617a0 call 7ff6b5363ff0 1680->1682 1684 7ff6b535288b-7ff6b535289e 1681->1684 1685 7ff6b53528a4 call 7ff6b53ce880 1681->1685 1682->1639 1684->1617 1684->1685 1685->1680
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$CloseOpenQueryValue
                                                                        • String ID: content$directory_iterator::directory_iterator$exists$filename
                                                                        • API String ID: 1254564140-1400943384
                                                                        • Opcode ID: fe0f5a0e777df163b00289a232bc5a8405e57c7a5efa77f273698b9a9cc3fd11
                                                                        • Instruction ID: 1a84cf07b8bd42dfccfbcd0bd6617d9fc46d640d2c06bd7aa4c1767302397711
                                                                        • Opcode Fuzzy Hash: fe0f5a0e777df163b00289a232bc5a8405e57c7a5efa77f273698b9a9cc3fd11
                                                                        • Instruction Fuzzy Hash: E7723072A15BC589DB218F39D8803ED77A0FB49B98F105225EB9D57B9AEF38D580C340

                                                                        Control-flow Graph

                                                                        • Executed
                                                                        • Not Executed
                                                                        control_flow_graph 1707 7ff6b538d080-7ff6b538d978 call 7ff6b534eaf0 * 2 1715 7ff6b538d97e-7ff6b538dd49 call 7ff6b534d4e0 call 7ff6b534d370 call 7ff6b538fdd0 call 7ff6b539f8f0 call 7ff6b534f380 1707->1715 1716 7ff6b538dd92-7ff6b538ddbc call 7ff6b53ce860 1707->1716 1732 7ff6b538dd7b-7ff6b538dd8b 1715->1732 1733 7ff6b538dd4b-7ff6b538dd5f 1715->1733 1732->1716 1734 7ff6b538dd61-7ff6b538dd74 1733->1734 1735 7ff6b538dd76 call 7ff6b53ce880 1733->1735 1734->1735 1736 7ff6b538ddbd-7ff6b538e39d call 7ff6b53b8254 call 7ff6b53639b0 call 7ff6b53679f0 call 7ff6b5367ac0 call 7ff6b53d0e88 call 7ff6b534e1d0 * 3 call 7ff6b53b8254 * 4 call 7ff6b534e1d0 call 7ff6b53b8254 * 2 call 7ff6b534cf70 call 7ff6b53b8254 call 7ff6b534e1d0 call 7ff6b53b8254 * 2 call 7ff6b534cf70 call 7ff6b534d4e0 call 7ff6b534d370 1734->1736 1735->1732 1786 7ff6b538e3a0-7ff6b538e3a7 1736->1786 1786->1786 1787 7ff6b538e3a9-7ff6b538e5a8 call 7ff6b5375c20 call 7ff6b534d810 call 7ff6b534da40 1786->1787 1794 7ff6b538e5b0-7ff6b538e5b8 1787->1794 1794->1794 1795 7ff6b538e5ba-7ff6b538e98a call 7ff6b53686b0 call 7ff6b5375c20 call 7ff6b534d810 call 7ff6b539f020 call 7ff6b534da40 * 2 call 7ff6b5362c80 1794->1795 1810 7ff6b538e990-7ff6b538e997 1795->1810 1810->1810 1811 7ff6b538e999-7ff6b538e9c7 call 7ff6b5367600 1810->1811 1814 7ff6b538f363-7ff6b538f36e 1811->1814 1815 7ff6b538e9cd-7ff6b538e9dc call 7ff6b534ea50 1811->1815 1817 7ff6b538f370-7ff6b538f37a 1814->1817 1818 7ff6b538f3a2-7ff6b538f3c2 1814->1818 1815->1814 1824 7ff6b538e9e2-7ff6b538ea8e 1815->1824 1817->1818 1822 7ff6b538f37c 1817->1822 1819 7ff6b538f3e1-7ff6b538f405 call 7ff6b534f380 call 7ff6b5362880 call 7ff6b534da40 1818->1819 1820 7ff6b538f3c4-7ff6b538f3cd 1818->1820 1840 7ff6b538f40a-7ff6b538f464 call 7ff6b5362880 call 7ff6b53ce860 1819->1840 1820->1819 1830 7ff6b538f3cf-7ff6b538f3e0 1820->1830 1825 7ff6b538f384-7ff6b538f387 1822->1825 1824->1814 1828 7ff6b538f477-7ff6b538f4f6 call 7ff6b534cf70 call 7ff6b534e240 call 7ff6b534e1d0 call 7ff6b53b8254 call 7ff6b538ce40 1824->1828 1825->1818 1829 7ff6b538f389-7ff6b538f3a0 1825->1829 1829->1825 1830->1819
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID: cannot use push_back() with $directory_iterator::directory_iterator$exists$prefs.js$status
                                                                        • API String ID: 0-2713369562
                                                                        • Opcode ID: 3b4f4422a52561bd1ffdc2d0feed999f23c4e58c7e2ed330231bbbadc801fcb0
                                                                        • Instruction ID: d8c533df98a03893af2a2781b1a0ae8767264894ab615e7cd65c14f152aeb6e6
                                                                        • Opcode Fuzzy Hash: 3b4f4422a52561bd1ffdc2d0feed999f23c4e58c7e2ed330231bbbadc801fcb0
                                                                        • Instruction Fuzzy Hash: DF522732519FC584E6B19B19E8813EAB3A4FBC9B40F505625DBCC82B5AEF7CD594CB00

                                                                        Control-flow Graph

                                                                        • Executed
                                                                        • Not Executed
                                                                        control_flow_graph 1852 7ff6b53db5b0-7ff6b53db5f0 1853 7ff6b53db5f2-7ff6b53db5f9 1852->1853 1854 7ff6b53db605-7ff6b53db60e 1852->1854 1853->1854 1855 7ff6b53db5fb-7ff6b53db600 1853->1855 1856 7ff6b53db610-7ff6b53db613 1854->1856 1857 7ff6b53db62a-7ff6b53db62c 1854->1857 1860 7ff6b53db884-7ff6b53db8aa call 7ff6b53ce860 1855->1860 1856->1857 1861 7ff6b53db615-7ff6b53db61d 1856->1861 1858 7ff6b53db882 1857->1858 1859 7ff6b53db632-7ff6b53db636 1857->1859 1858->1860 1864 7ff6b53db70d-7ff6b53db734 call 7ff6b53db984 1859->1864 1865 7ff6b53db63c-7ff6b53db63f 1859->1865 1862 7ff6b53db623-7ff6b53db626 1861->1862 1863 7ff6b53db61f-7ff6b53db621 1861->1863 1862->1857 1863->1857 1863->1862 1875 7ff6b53db756-7ff6b53db75f 1864->1875 1876 7ff6b53db736-7ff6b53db73f 1864->1876 1869 7ff6b53db653-7ff6b53db665 GetFileAttributesExW 1865->1869 1870 7ff6b53db641-7ff6b53db649 1865->1870 1873 7ff6b53db667-7ff6b53db670 GetLastError 1869->1873 1874 7ff6b53db6b8-7ff6b53db6c7 1869->1874 1870->1869 1872 7ff6b53db64b-7ff6b53db64d 1870->1872 1872->1864 1872->1869 1873->1860 1877 7ff6b53db676-7ff6b53db688 FindFirstFileW 1873->1877 1878 7ff6b53db6cb-7ff6b53db6cd 1874->1878 1881 7ff6b53db813-7ff6b53db81c 1875->1881 1882 7ff6b53db765-7ff6b53db77d GetFileInformationByHandleEx 1875->1882 1879 7ff6b53db74f-7ff6b53db751 1876->1879 1880 7ff6b53db741-7ff6b53db749 CloseHandle 1876->1880 1883 7ff6b53db695-7ff6b53db6b6 FindClose 1877->1883 1884 7ff6b53db68a-7ff6b53db690 GetLastError 1877->1884 1885 7ff6b53db6cf-7ff6b53db6d7 1878->1885 1886 7ff6b53db6d9-7ff6b53db707 1878->1886 1879->1860 1880->1879 1887 7ff6b53db8c5-7ff6b53db8ca call 7ff6b53b98b4 1880->1887 1888 7ff6b53db81e-7ff6b53db832 GetFileInformationByHandleEx 1881->1888 1889 7ff6b53db86b-7ff6b53db86d 1881->1889 1890 7ff6b53db7a5-7ff6b53db7be 1882->1890 1891 7ff6b53db77f-7ff6b53db78b GetLastError 1882->1891 1883->1878 1884->1860 1885->1864 1885->1886 1886->1858 1886->1864 1909 7ff6b53db8cb-7ff6b53db8d0 call 7ff6b53b98b4 1887->1909 1893 7ff6b53db834-7ff6b53db840 GetLastError 1888->1893 1894 7ff6b53db858-7ff6b53db868 1888->1894 1897 7ff6b53db86f-7ff6b53db873 1889->1897 1898 7ff6b53db8ab-7ff6b53db8af 1889->1898 1890->1881 1899 7ff6b53db7c0-7ff6b53db7c4 1890->1899 1895 7ff6b53db79e-7ff6b53db7a0 1891->1895 1896 7ff6b53db78d-7ff6b53db798 CloseHandle 1891->1896 1893->1895 1903 7ff6b53db846-7ff6b53db851 CloseHandle 1893->1903 1894->1889 1895->1860 1896->1895 1904 7ff6b53db8d7-7ff6b53db8df call 7ff6b53b98b4 1896->1904 1897->1858 1905 7ff6b53db875-7ff6b53db880 CloseHandle 1897->1905 1900 7ff6b53db8be-7ff6b53db8c3 1898->1900 1901 7ff6b53db8b1-7ff6b53db8bc CloseHandle 1898->1901 1906 7ff6b53db80c 1899->1906 1907 7ff6b53db7c6-7ff6b53db7e0 GetFileInformationByHandleEx 1899->1907 1900->1860 1901->1887 1901->1900 1910 7ff6b53db853 1903->1910 1911 7ff6b53db8d1-7ff6b53db8d6 call 7ff6b53b98b4 1903->1911 1905->1858 1905->1887 1908 7ff6b53db810 1906->1908 1913 7ff6b53db803-7ff6b53db80a 1907->1913 1914 7ff6b53db7e2-7ff6b53db7ee GetLastError 1907->1914 1908->1881 1909->1911 1910->1895 1911->1904 1913->1908 1914->1895 1918 7ff6b53db7f0-7ff6b53db7fb CloseHandle 1914->1918 1918->1909 1919 7ff6b53db801 1918->1919 1919->1895
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Close$ErrorFileFindHandleLast$AttributesFirst__std_fs_open_handle
                                                                        • String ID:
                                                                        • API String ID: 2398595512-0
                                                                        • Opcode ID: ae06ef96b620ec177ea6819a3a1ac38214177ad565b87e13f1ccf53398ca1eb7
                                                                        • Instruction ID: b76d77abf3dd061c2f4c21243a234297ef2a84f3680294eddecf331f2e3763d5
                                                                        • Opcode Fuzzy Hash: ae06ef96b620ec177ea6819a3a1ac38214177ad565b87e13f1ccf53398ca1eb7
                                                                        • Instruction Fuzzy Hash: 1C918531A68A4246EA654B2DA4246B522A0AF45FB4F544730DBBDC77DAFF3CEC058B00

                                                                        Control-flow Graph

                                                                        • Executed
                                                                        • Not Executed
                                                                        control_flow_graph 1976 7ff6b535ca10-7ff6b535ca7a CredEnumerateA 1977 7ff6b535d49c-7ff6b535d4cb call 7ff6b53ce860 1976->1977 1978 7ff6b535ca80-7ff6b535ca89 1976->1978 1980 7ff6b535d48f-7ff6b535d496 CredFree 1978->1980 1981 7ff6b535ca8f-7ff6b535caa7 1978->1981 1980->1977 1983 7ff6b535cab0-7ff6b535cb02 call 7ff6b53ce888 1981->1983 1986 7ff6b535cd4d-7ff6b535cd54 1983->1986 1987 7ff6b535cb08-7ff6b535cb2e 1983->1987 1988 7ff6b535cd5a-7ff6b535cd7e 1986->1988 1989 7ff6b535cfa9-7ff6b535cfb0 1986->1989 1990 7ff6b535cb30-7ff6b535cb38 1987->1990 1991 7ff6b535cd80-7ff6b535cd88 1988->1991 1992 7ff6b535d1f7-7ff6b535d1fa 1989->1992 1993 7ff6b535cfb6-7ff6b535d09f call 7ff6b53686b0 call 7ff6b5365310 call 7ff6b53655e0 1989->1993 1990->1990 1994 7ff6b535cb3a-7ff6b535cbf7 call 7ff6b53686b0 call 7ff6b5365310 call 7ff6b53655e0 1990->1994 1991->1991 1997 7ff6b535cd8a-7ff6b535ce49 call 7ff6b53686b0 call 7ff6b5365310 call 7ff6b53655e0 1991->1997 1995 7ff6b535d473-7ff6b535d489 call 7ff6b53600f0 1992->1995 1996 7ff6b535d200-7ff6b535d28a 1992->1996 2024 7ff6b535d0a0-7ff6b535d0a8 1993->2024 2025 7ff6b535cc00-7ff6b535cc08 1994->2025 1995->1980 1995->1983 2001 7ff6b535d290-7ff6b535d298 1996->2001 2027 7ff6b535ce50-7ff6b535ce58 1997->2027 2001->2001 2006 7ff6b535d29a-7ff6b535d34b call 7ff6b53686b0 call 7ff6b5361900 2001->2006 2026 7ff6b535d350-7ff6b535d358 2006->2026 2024->2024 2028 7ff6b535d0aa-7ff6b535d103 call 7ff6b53686b0 call 7ff6b5366bc0 call 7ff6b5363ff0 2024->2028 2025->2025 2029 7ff6b535cc0a-7ff6b535cc63 call 7ff6b53686b0 call 7ff6b5366bc0 call 7ff6b5363ff0 2025->2029 2026->2026 2030 7ff6b535d35a-7ff6b535d3f8 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 call 7ff6b53ce888 call 7ff6b53851b0 2026->2030 2027->2027 2031 7ff6b535ce5a-7ff6b535ceb3 call 7ff6b53686b0 call 7ff6b5366bc0 call 7ff6b5363ff0 2027->2031 2056 7ff6b535d136-7ff6b535d156 2028->2056 2057 7ff6b535d105-7ff6b535d116 2028->2057 2058 7ff6b535cc96-7ff6b535ccb9 2029->2058 2059 7ff6b535cc65-7ff6b535cc76 2029->2059 2127 7ff6b535d3fa-7ff6b535d3fc 2030->2127 2128 7ff6b535d404-7ff6b535d419 call 7ff6b53637f0 2030->2128 2065 7ff6b535cee6-7ff6b535cf0c 2031->2065 2066 7ff6b535ceb5-7ff6b535cec6 2031->2066 2060 7ff6b535d18c-7ff6b535d1ae 2056->2060 2061 7ff6b535d158-7ff6b535d16c 2056->2061 2067 7ff6b535d118-7ff6b535d12b 2057->2067 2068 7ff6b535d131 call 7ff6b53ce880 2057->2068 2062 7ff6b535ccbb-7ff6b535cccc 2058->2062 2063 7ff6b535ccec-7ff6b535cd04 2058->2063 2069 7ff6b535cc78-7ff6b535cc8b 2059->2069 2070 7ff6b535cc91 call 7ff6b53ce880 2059->2070 2077 7ff6b535d1e2-7ff6b535d1f5 2060->2077 2078 7ff6b535d1b0-7ff6b535d1c2 2060->2078 2071 7ff6b535d187 call 7ff6b53ce880 2061->2071 2072 7ff6b535d16e-7ff6b535d181 2061->2072 2073 7ff6b535cce7 call 7ff6b53ce880 2062->2073 2074 7ff6b535ccce-7ff6b535cce1 2062->2074 2079 7ff6b535cd06-7ff6b535cd18 2063->2079 2080 7ff6b535cd38-7ff6b535cd4a 2063->2080 2075 7ff6b535cf42-7ff6b535cf63 2065->2075 2076 7ff6b535cf0e-7ff6b535cf22 2065->2076 2082 7ff6b535cec8-7ff6b535cedb 2066->2082 2083 7ff6b535cee1 call 7ff6b53ce880 2066->2083 2067->2068 2084 7ff6b535d54a-7ff6b5366d9d call 7ff6b53b8254 2067->2084 2068->2056 2069->2070 2085 7ff6b535d526-7ff6b535d52b call 7ff6b53b8254 2069->2085 2070->2058 2071->2060 2072->2071 2088 7ff6b535d4cc-7ff6b535d4d1 call 7ff6b53b8254 2072->2088 2073->2063 2074->2073 2089 7ff6b535d52c-7ff6b535d531 call 7ff6b53b8254 2074->2089 2095 7ff6b535cf96-7ff6b535cfa6 2075->2095 2096 7ff6b535cf65-7ff6b535cf76 2075->2096 2090 7ff6b535cf3d call 7ff6b53ce880 2076->2090 2091 7ff6b535cf24-7ff6b535cf37 2076->2091 2077->1996 2097 7ff6b535d1dd call 7ff6b53ce880 2078->2097 2098 7ff6b535d1c4-7ff6b535d1d7 2078->2098 2099 7ff6b535cd1a-7ff6b535cd2d 2079->2099 2100 7ff6b535cd33 call 7ff6b53ce880 2079->2100 2080->1986 2082->2083 2103 7ff6b535d538-7ff6b535d53d call 7ff6b53b8254 2082->2103 2083->2065 2136 7ff6b5366d9f 2084->2136 2137 7ff6b5366dd1-7ff6b5366de4 2084->2137 2085->2089 2135 7ff6b535d4d2-7ff6b535d51f call 7ff6b53639b0 call 7ff6b53679f0 call 7ff6b5367ac0 call 7ff6b53d0e88 2088->2135 2112 7ff6b535d532-7ff6b535d537 call 7ff6b53b8254 2089->2112 2090->2075 2091->2090 2105 7ff6b535d53e-7ff6b535d543 call 7ff6b53b8254 2091->2105 2095->1989 2109 7ff6b535cf78-7ff6b535cf8b 2096->2109 2110 7ff6b535cf91 call 7ff6b53ce880 2096->2110 2097->2077 2098->2097 2111 7ff6b535d520-7ff6b535d525 call 7ff6b53b8254 2098->2111 2099->2100 2099->2112 2100->2080 2103->2105 2120 7ff6b535d544-7ff6b535d549 call 7ff6b53b8254 2105->2120 2109->2110 2109->2120 2110->2095 2111->2085 2112->2103 2120->2084 2127->2135 2138 7ff6b535d402 2127->2138 2139 7ff6b535d41d-7ff6b535d429 2128->2139 2135->2111 2143 7ff6b5366da0-7ff6b5366dcf call 7ff6b5369380 call 7ff6b5379810 call 7ff6b53ce880 2136->2143 2138->2139 2144 7ff6b535d42b-7ff6b535d44a 2139->2144 2145 7ff6b535d44c-7ff6b535d456 call 7ff6b5370610 2139->2145 2143->2137 2148 7ff6b535d45b-7ff6b535d469 call 7ff6b5363ff0 2144->2148 2145->2148 2148->1995
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$Cred$EnumerateFree
                                                                        • String ID: cannot use push_back() with
                                                                        • API String ID: 1347986415-4122110429
                                                                        • Opcode ID: f3625956b1ff6e516f56da58d55d27a7ac63a458bf1a20c5410d74d164e79c39
                                                                        • Instruction ID: 59f74909b349a33b6475207b5f853ff20070b484688de314480eaca604d30936
                                                                        • Opcode Fuzzy Hash: f3625956b1ff6e516f56da58d55d27a7ac63a458bf1a20c5410d74d164e79c39
                                                                        • Instruction Fuzzy Hash: CC627372A18BC589E7218F28E8403ED7761F749B98F505225EB9C47B9EEF38D694C700

                                                                        Control-flow Graph

                                                                        • Executed
                                                                        • Not Executed
                                                                        control_flow_graph 2164 7ff6b5369f80-7ff6b5369fc5 2165 7ff6b5369fcb-7ff6b5369ff5 call 7ff6b53e1650 2164->2165 2166 7ff6b536a291-7ff6b536a2cb call 7ff6b5371e10 call 7ff6b536c600 2164->2166 2172 7ff6b5369ff7-7ff6b536a000 2165->2172 2173 7ff6b536a004-7ff6b536a03d call 7ff6b536b5b0 call 7ff6b5370c20 call 7ff6b536c600 2165->2173 2174 7ff6b536a2d0-7ff6b536a2d6 2166->2174 2172->2173 2202 7ff6b536a1d4-7ff6b536a1db 2173->2202 2203 7ff6b536a043-7ff6b536a0c8 call 7ff6b53686b0 call 7ff6b536b780 call 7ff6b5371af0 call 7ff6b536bd00 2173->2203 2176 7ff6b536a2dc-7ff6b536a35b call 7ff6b53686b0 call 7ff6b536b780 call 7ff6b5371af0 call 7ff6b536bd00 2174->2176 2177 7ff6b536a467-7ff6b536a46b 2174->2177 2231 7ff6b536a5ab-7ff6b536a5c7 call 7ff6b5363e90 call 7ff6b53d0e88 2176->2231 2232 7ff6b536a361-7ff6b536a369 2176->2232 2180 7ff6b536a539-7ff6b536a540 2177->2180 2181 7ff6b536a471-7ff6b536a4ce call 7ff6b53637f0 call 7ff6b5363ff0 2177->2181 2186 7ff6b536a50d-7ff6b536a538 call 7ff6b53ce860 2180->2186 2187 7ff6b536a542-7ff6b536a557 2180->2187 2181->2186 2211 7ff6b536a4d0-7ff6b536a4e5 2181->2211 2193 7ff6b536a4fc-7ff6b536a508 call 7ff6b53ce880 2187->2193 2194 7ff6b536a559-7ff6b536a56c 2187->2194 2193->2186 2195 7ff6b536a576-7ff6b536a57b call 7ff6b53b8254 2194->2195 2196 7ff6b536a56e 2194->2196 2219 7ff6b536a57c-7ff6b536a598 call 7ff6b5363e90 call 7ff6b53d0e88 2195->2219 2196->2193 2208 7ff6b536a1dd-7ff6b536a223 call 7ff6b53637f0 2202->2208 2209 7ff6b536a225-7ff6b536a228 2202->2209 2203->2219 2259 7ff6b536a0ce-7ff6b536a0d6 2203->2259 2227 7ff6b536a270-7ff6b536a27f call 7ff6b5363ff0 2208->2227 2215 7ff6b536a22a-7ff6b536a26b call 7ff6b53637f0 2209->2215 2216 7ff6b536a280-7ff6b536a28c call 7ff6b536b3d0 2209->2216 2211->2193 2218 7ff6b536a4e7-7ff6b536a4fa 2211->2218 2215->2227 2216->2186 2218->2193 2218->2195 2250 7ff6b536a599-7ff6b536a59e call 7ff6b53b8254 2219->2250 2227->2216 2251 7ff6b536a5c8-7ff6b536a5cd call 7ff6b53b8254 2231->2251 2238 7ff6b536a39c-7ff6b536a3e1 call 7ff6b53d07d0 * 2 2232->2238 2239 7ff6b536a36b-7ff6b536a37c 2232->2239 2262 7ff6b536a415-7ff6b536a428 2238->2262 2263 7ff6b536a3e3-7ff6b536a3f5 2238->2263 2245 7ff6b536a397 call 7ff6b53ce880 2239->2245 2246 7ff6b536a37e-7ff6b536a391 2239->2246 2245->2238 2246->2245 2246->2251 2267 7ff6b536a59f-7ff6b536a5a4 call 7ff6b53b8254 2250->2267 2266 7ff6b536a5ce-7ff6b536a5e6 call 7ff6b53b8254 2251->2266 2264 7ff6b536a10a-7ff6b536a150 call 7ff6b53d07d0 * 2 2259->2264 2265 7ff6b536a0d8-7ff6b536a0ea 2259->2265 2272 7ff6b536a45c-7ff6b536a462 2262->2272 2273 7ff6b536a42a-7ff6b536a43c 2262->2273 2270 7ff6b536a3f7-7ff6b536a40a 2263->2270 2271 7ff6b536a410 call 7ff6b53ce880 2263->2271 2295 7ff6b536a152-7ff6b536a163 2264->2295 2296 7ff6b536a183-7ff6b536a195 2264->2296 2274 7ff6b536a0ec-7ff6b536a0ff 2265->2274 2275 7ff6b536a105 call 7ff6b53ce880 2265->2275 2284 7ff6b536a5e8-7ff6b536a5eb 2266->2284 2285 7ff6b536a5f3 2266->2285 2286 7ff6b536a5a5-7ff6b536a5aa call 7ff6b53b8254 2267->2286 2270->2266 2270->2271 2271->2262 2272->2177 2280 7ff6b536a457 call 7ff6b53ce880 2273->2280 2281 7ff6b536a43e-7ff6b536a451 2273->2281 2274->2250 2274->2275 2275->2264 2280->2272 2281->2280 2288 7ff6b536a570-7ff6b536a575 call 7ff6b53b8254 2281->2288 2284->2285 2286->2231 2288->2195 2297 7ff6b536a165-7ff6b536a178 2295->2297 2298 7ff6b536a17e call 7ff6b53ce880 2295->2298 2299 7ff6b536a1c9-7ff6b536a1cf 2296->2299 2300 7ff6b536a197-7ff6b536a1a9 2296->2300 2297->2267 2297->2298 2298->2296 2299->2202 2302 7ff6b536a1ab-7ff6b536a1be 2300->2302 2303 7ff6b536a1c4 call 7ff6b53ce880 2300->2303 2302->2286 2302->2303 2303->2299
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_destroy
                                                                        • String ID: value
                                                                        • API String ID: 1346393832-494360628
                                                                        • Opcode ID: 77c398e42319cb3f72657f0fcf0c0d1a16adf19cfbf0f7d3d9d4373457347ef9
                                                                        • Instruction ID: 39683d77232cd29888ea9d8c1b093f2cbe0daf8e725f63d0fd125c8425b144fa
                                                                        • Opcode Fuzzy Hash: 77c398e42319cb3f72657f0fcf0c0d1a16adf19cfbf0f7d3d9d4373457347ef9
                                                                        • Instruction Fuzzy Hash: D902A262A2CBC185EB41CB78D4402ED6760EB85BA4F105235FB9D86BDEEF2CD984C300

                                                                        Control-flow Graph

                                                                        • Executed
                                                                        • Not Executed
                                                                        control_flow_graph 2515 7ff6b539c600-7ff6b539c622 call 7ff6b539f820 2518 7ff6b539c64e-7ff6b539c700 call 7ff6b53ab9b0 * 2 call 7ff6b53a8030 call 7ff6b539d030 2515->2518 2519 7ff6b539c624-7ff6b539c647 call 7ff6b539fb60 call 7ff6b53aa780 call 7ff6b5362660 ExitProcess 2515->2519 2534 7ff6b539c702-7ff6b539c714 2518->2534 2535 7ff6b539c734-7ff6b539c76b OpenMutexA 2518->2535 2536 7ff6b539c72f call 7ff6b53ce880 2534->2536 2537 7ff6b539c716-7ff6b539c729 2534->2537 2538 7ff6b539c779-7ff6b539c7b0 CreateMutexExA call 7ff6b53966f0 call 7ff6b539fca0 2535->2538 2539 7ff6b539c76d-7ff6b539c772 ExitProcess 2535->2539 2536->2535 2537->2536 2540 7ff6b539c8c6-7ff6b539c8cb call 7ff6b53b8254 2537->2540 2550 7ff6b539c7be-7ff6b539c821 call 7ff6b53a8330 call 7ff6b535d570 call 7ff6b535e610 call 7ff6b535ecb0 call 7ff6b535f9e0 call 7ff6b535ca10 call 7ff6b538cab0 call 7ff6b538f7a0 call 7ff6b5351b90 call 7ff6b535add0 call 7ff6b5359680 call 7ff6b539d260 call 7ff6b535bf40 call 7ff6b53577d0 call 7ff6b5354b70 call 7ff6b5357aa0 call 7ff6b53a4a30 2538->2550 2551 7ff6b539c7b2-7ff6b539c7b7 ExitProcess 2538->2551 2547 7ff6b539c8cc-7ff6b539c8d1 call 7ff6b53b8254 2540->2547 2588 7ff6b539c826-7ff6b539c836 call 7ff6b539bcc0 2550->2588 2592 7ff6b539c838-7ff6b539c844 ReleaseMutex CloseHandle 2588->2592 2593 7ff6b539c84a-7ff6b539c851 2588->2593 2592->2593 2594 7ff6b539c853-7ff6b539c858 call 7ff6b539c8e0 2593->2594 2595 7ff6b539c859-7ff6b539c865 2593->2595 2594->2595 2597 7ff6b539c895-7ff6b539c8c5 call 7ff6b53ce860 2595->2597 2598 7ff6b539c867-7ff6b539c879 2595->2598 2600 7ff6b539c890 call 7ff6b53ce880 2598->2600 2601 7ff6b539c87b-7ff6b539c88e 2598->2601 2600->2597 2601->2547 2601->2600
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Process$ExitOpenToken$CloseCurrentFileHandleInformationInitializeModuleMutexName
                                                                        • String ID: SeDebugPrivilege$SeImpersonatePrivilege
                                                                        • API String ID: 3348294976-3768118664
                                                                        • Opcode ID: 617da249283f2d9320b64a1b23aee101a8acda4f9b5654c5cc8d1f0bc494ee8f
                                                                        • Instruction ID: 38d22b5f0917eef4cc4e3847999d9e2b307e24a0ff85aba664834acc6f77efca
                                                                        • Opcode Fuzzy Hash: 617da249283f2d9320b64a1b23aee101a8acda4f9b5654c5cc8d1f0bc494ee8f
                                                                        • Instruction Fuzzy Hash: 2A614F6292CB8681EA51AB6CB4552FE6350EF89B80F505535E78EC279FFF2CE8458700

                                                                        Control-flow Graph

                                                                        • Executed
                                                                        • Not Executed
                                                                        control_flow_graph 2605 7ff6b5385970-7ff6b53859b0 2606 7ff6b53859b6-7ff6b53859c0 2605->2606 2607 7ff6b5385aaf-7ff6b5385ab8 2605->2607 2610 7ff6b5385aa6-7ff6b5385aac 2606->2610 2611 7ff6b53859c6-7ff6b53859ce 2606->2611 2608 7ff6b5385aba-7ff6b5385ac6 2607->2608 2609 7ff6b5385b02-7ff6b5385b14 call 7ff6b53db4c0 2607->2609 2612 7ff6b5385ada-7ff6b5385ae1 call 7ff6b5392660 2608->2612 2613 7ff6b5385ac8-7ff6b5385ad8 2608->2613 2626 7ff6b5385b56-7ff6b5385b5a 2609->2626 2627 7ff6b5385b16-7ff6b5385b1a 2609->2627 2610->2607 2614 7ff6b53859db-7ff6b53859df 2611->2614 2615 7ff6b53859d0-7ff6b53859d5 2611->2615 2617 7ff6b5385ae6-7ff6b5385b00 call 7ff6b534e2a0 2612->2617 2613->2617 2619 7ff6b5385a38-7ff6b5385a3a 2614->2619 2620 7ff6b53859e1-7ff6b53859ea 2614->2620 2615->2610 2615->2614 2628 7ff6b5385b5e-7ff6b5385b64 2617->2628 2619->2607 2623 7ff6b5385a3c-7ff6b5385a6c 2619->2623 2624 7ff6b53859ec 2620->2624 2625 7ff6b53859ef-7ff6b5385a06 call 7ff6b53db5b0 2620->2625 2630 7ff6b5385a9f-7ff6b5385aa1 2623->2630 2631 7ff6b5385a6e-7ff6b5385a80 2623->2631 2624->2625 2644 7ff6b5385a08-7ff6b5385a12 2625->2644 2645 7ff6b5385a14-7ff6b5385a17 2625->2645 2626->2628 2633 7ff6b5385b20-7ff6b5385b26 2627->2633 2634 7ff6b5385b6a-7ff6b5385b6c 2628->2634 2635 7ff6b5385cb3-7ff6b5385cc0 call 7ff6b534e4f0 2628->2635 2640 7ff6b5385cc2-7ff6b5385cf2 call 7ff6b53ce860 2630->2640 2631->2630 2636 7ff6b5385a82-7ff6b5385a94 2631->2636 2638 7ff6b5385b28-7ff6b5385b30 2633->2638 2639 7ff6b5385b54 2633->2639 2643 7ff6b5385b70-7ff6b5385b73 2634->2643 2635->2640 2636->2630 2663 7ff6b5385a96-7ff6b5385a99 2636->2663 2646 7ff6b5385b32-7ff6b5385b36 2638->2646 2647 7ff6b5385b3f-7ff6b5385b50 call 7ff6b53db4c0 2638->2647 2639->2626 2651 7ff6b5385b79-7ff6b5385b81 2643->2651 2652 7ff6b5385cf5-7ff6b5385d29 2643->2652 2644->2619 2655 7ff6b5385a19-7ff6b5385a1c 2645->2655 2656 7ff6b5385a36 2645->2656 2646->2639 2654 7ff6b5385b38-7ff6b5385b3d 2646->2654 2647->2633 2665 7ff6b5385b52 2647->2665 2661 7ff6b5385b87-7ff6b5385bba call 7ff6b53db4e0 * 2 2651->2661 2662 7ff6b5385cf3 2651->2662 2659 7ff6b5385d2b-7ff6b5385d36 2652->2659 2660 7ff6b5385d55-7ff6b5385d57 2652->2660 2654->2639 2654->2647 2655->2656 2657 7ff6b5385a1e-7ff6b5385a21 2655->2657 2656->2619 2657->2656 2664 7ff6b5385a23-7ff6b5385a26 2657->2664 2659->2660 2666 7ff6b5385d38-7ff6b5385d4a 2659->2666 2660->2640 2675 7ff6b5385bbc 2661->2675 2676 7ff6b5385bbf-7ff6b5385bd2 call 7ff6b534d020 2661->2676 2662->2652 2663->2630 2664->2656 2668 7ff6b5385a28-7ff6b5385a2b 2664->2668 2665->2626 2666->2660 2673 7ff6b5385d4c-7ff6b5385d4f 2666->2673 2668->2619 2670 7ff6b5385a2d-7ff6b5385a34 2668->2670 2670->2619 2670->2656 2673->2660 2675->2676 2679 7ff6b5385c2d-7ff6b5385c37 2676->2679 2680 7ff6b5385bd4-7ff6b5385bdb 2676->2680 2683 7ff6b5385c3d-7ff6b5385c49 2679->2683 2684 7ff6b5385d5c-7ff6b5385d61 call 7ff6b53645e0 2679->2684 2681 7ff6b5385bdd-7ff6b5385be1 2680->2681 2682 7ff6b5385be3 2680->2682 2681->2682 2687 7ff6b5385be7-7ff6b5385bea 2681->2687 2682->2687 2685 7ff6b5385c4b 2683->2685 2686 7ff6b5385c4e-7ff6b5385c64 call 7ff6b53db4c0 2683->2686 2685->2686 2686->2643 2694 7ff6b5385c6a-7ff6b5385c6e 2686->2694 2687->2679 2691 7ff6b5385bec 2687->2691 2693 7ff6b5385bf0-7ff6b5385bfc 2691->2693 2695 7ff6b5385c0c-7ff6b5385c0f 2693->2695 2696 7ff6b5385bfe-7ff6b5385c02 2693->2696 2697 7ff6b5385c70-7ff6b5385c76 2694->2697 2695->2679 2699 7ff6b5385c11-7ff6b5385c1d 2695->2699 2696->2695 2698 7ff6b5385c04-7ff6b5385c0a 2696->2698 2700 7ff6b5385c78-7ff6b5385c80 2697->2700 2701 7ff6b5385ca7-7ff6b5385ca9 2697->2701 2698->2693 2698->2695 2702 7ff6b5385c25-7ff6b5385c2b 2699->2702 2703 7ff6b5385c1f-7ff6b5385c23 2699->2703 2704 7ff6b5385c82-7ff6b5385c86 2700->2704 2705 7ff6b5385c90-7ff6b5385ca1 call 7ff6b53db4c0 2700->2705 2706 7ff6b5385cab-7ff6b5385cad 2701->2706 2702->2679 2702->2699 2703->2679 2703->2702 2704->2701 2707 7ff6b5385c88-7ff6b5385c8e 2704->2707 2705->2697 2710 7ff6b5385ca3-7ff6b5385ca5 2705->2710 2706->2635 2706->2643 2707->2701 2707->2705 2710->2706
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID: .$@$@$cannot use push_back() with $chrome_key$content$directory_iterator::directory_iterator$exists$filename$key$prefs.js$recursive_directory_iterator::operator++$recursive_directory_iterator::recursive_directory_iterator$status
                                                                        • API String ID: 0-4287193513
                                                                        • Opcode ID: 8adc91dd6644a2bfb7387dc78b72df08f999bd5353c1b7ff9b33895fcf5abe12
                                                                        • Instruction ID: 44ad5dabc259d73000878a760fd8a374393dca132db6d4cd5ff22c8d92563c0d
                                                                        • Opcode Fuzzy Hash: 8adc91dd6644a2bfb7387dc78b72df08f999bd5353c1b7ff9b33895fcf5abe12
                                                                        • Instruction Fuzzy Hash: 7EC1B022A18B8296EB298E29D4841F963A0FB55F94F544231EB5DC378AFF7CEC41C701
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Internet$Query$AvailableDataHttpInfoOpen_invalid_parameter_noinfo_noreturn$CloseConcurrency::cancel_current_taskFileHandleRead
                                                                        • String ID:
                                                                        • API String ID: 1352168858-0
                                                                        • Opcode ID: 58f98962fe06158b31631e628ad7e1738d27d0a2909a2e7e3a0f022cf9efdd7e
                                                                        • Instruction ID: 7df8b25cd10ab0949d65f48602e1949abeb35507c7e88b257e4d93ff73195689
                                                                        • Opcode Fuzzy Hash: 58f98962fe06158b31631e628ad7e1738d27d0a2909a2e7e3a0f022cf9efdd7e
                                                                        • Instruction Fuzzy Hash: 4902A532A28B9585EB10CB69E8403AE77B5FB95B94F100225EF9C57B99EF7CD490C700
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$Process32$CloseCreateFirstHandleNextSnapshotToolhelp32
                                                                        • String ID: [PID:
                                                                        • API String ID: 1946380282-2210602247
                                                                        • Opcode ID: 75960466dfb22bb2a306a6a9d77edd6b0067b15d627c6204e9c6655a97bc35d8
                                                                        • Instruction ID: 35af94510fc47a7b73ac0aaf1e98abc150bb9934eff8e7a23a95ec8701e17849
                                                                        • Opcode Fuzzy Hash: 75960466dfb22bb2a306a6a9d77edd6b0067b15d627c6204e9c6655a97bc35d8
                                                                        • Instruction Fuzzy Hash: BBE1B572A18BC185EB21CB29E4803ED77A1F789B94F505225EB9D47B9EEF38D644C700
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 3668304517-0
                                                                        • Opcode ID: 5247411f787a999a7cf2db075e4552cc8a45f43d7f137c5f7f86f5096a64e4da
                                                                        • Instruction ID: 6f12ecceb7effdb160ae374bf78da21601042cfa22ceb45afda4ad8b713c4714
                                                                        • Opcode Fuzzy Hash: 5247411f787a999a7cf2db075e4552cc8a45f43d7f137c5f7f86f5096a64e4da
                                                                        • Instruction Fuzzy Hash: 31725F62A19BC585EB208B69E8403ED73A1F789B98F505325EF9C57B9EEF38D540C700
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: File$PointerReadSize_invalid_parameter_noinfo_noreturn
                                                                        • String ID: exists$ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
                                                                        • API String ID: 2478245620-15404121
                                                                        • Opcode ID: 8cdf98b74691f3bd8b70ec143bc6e60ee69bb8cc810ea23612f5f3421e56b4bf
                                                                        • Instruction ID: 33108a6fd6557c3e8e372c84c8698d1c33ff8da07bf18db9d8c7d002c6756fd7
                                                                        • Opcode Fuzzy Hash: 8cdf98b74691f3bd8b70ec143bc6e60ee69bb8cc810ea23612f5f3421e56b4bf
                                                                        • Instruction Fuzzy Hash: 7A320762A14BC589EB21CF28D8803ED37A1FB45B88F508236DB4D97B5AEF79D945C700
                                                                        APIs
                                                                        • _get_daylight.LIBCMT ref: 00007FF6B53C2E81
                                                                          • Part of subcall function 00007FF6B53C24E8: _invalid_parameter_noinfo.LIBCMT ref: 00007FF6B53C24FC
                                                                          • Part of subcall function 00007FF6B53BD3C8: RtlFreeHeap.NTDLL ref: 00007FF6B53BD3DE
                                                                          • Part of subcall function 00007FF6B53BD3C8: GetLastError.KERNEL32 ref: 00007FF6B53BD3E8
                                                                          • Part of subcall function 00007FF6B53B8284: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,00007FF6B53B8233,?,?,?,?,-2723E8D8DEBC5093,00007FF6B53B811E), ref: 00007FF6B53B828D
                                                                          • Part of subcall function 00007FF6B53B8284: GetCurrentProcess.KERNEL32(?,?,?,?,00007FF6B53B8233,?,?,?,?,-2723E8D8DEBC5093,00007FF6B53B811E), ref: 00007FF6B53B82B2
                                                                          • Part of subcall function 00007FF6B53CBA84: _invalid_parameter_noinfo.LIBCMT ref: 00007FF6B53CB9CF
                                                                        • _get_daylight.LIBCMT ref: 00007FF6B53C2E70
                                                                          • Part of subcall function 00007FF6B53C2548: _invalid_parameter_noinfo.LIBCMT ref: 00007FF6B53C255C
                                                                        • _get_daylight.LIBCMT ref: 00007FF6B53C30E6
                                                                        • _get_daylight.LIBCMT ref: 00007FF6B53C30F7
                                                                        • _get_daylight.LIBCMT ref: 00007FF6B53C3108
                                                                        • GetTimeZoneInformation.KERNEL32(00007FF6B53C33F8), ref: 00007FF6B53C312F
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _get_daylight$_invalid_parameter_noinfo$CurrentErrorFeatureFreeHeapInformationLastPresentProcessProcessorTimeZone
                                                                        • String ID: Eastern Standard Time$Eastern Summer Time
                                                                        • API String ID: 4070488512-239921721
                                                                        • Opcode ID: d27e707e32a7a668b79f18f39980f86f66c1361dc0c94ac41fd5faca01788e5a
                                                                        • Instruction ID: a54dc65e98f5db2a139418ac3f04b9c772e07708bfab086f58a0cab4fe105f78
                                                                        • Opcode Fuzzy Hash: d27e707e32a7a668b79f18f39980f86f66c1361dc0c94ac41fd5faca01788e5a
                                                                        • Instruction Fuzzy Hash: 7AD18D62A2876286EB24AF2DD8901F96761EF84F94F444135EB5D8778BEF3CEC418740
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type
                                                                        • String ID:
                                                                        • API String ID: 1617910340-0
                                                                        • Opcode ID: 9219a76bbf5b0a68fd8075754a2c2160bfaa822f6e476498c8a23ea95eed312f
                                                                        • Instruction ID: 1c70c53ab177eb98d4c2651f2db87097b7118635a8af0fc01fe6053cc255d504
                                                                        • Opcode Fuzzy Hash: 9219a76bbf5b0a68fd8075754a2c2160bfaa822f6e476498c8a23ea95eed312f
                                                                        • Instruction Fuzzy Hash: 45C1B132B34A4685EB11DFA9C4806EC37A1EB49F98F011235DB1E9739AEF38E851C310
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _get_daylight_invalid_parameter_noinfo$ErrorFreeHeapInformationLastTimeZone
                                                                        • String ID: Eastern Standard Time$Eastern Summer Time
                                                                        • API String ID: 3458911817-239921721
                                                                        • Opcode ID: a0b2f147c5ed72e73a9ba99eccd64d774068bd057930b9dd808764ab5dc4e304
                                                                        • Instruction ID: e8d6cec729c0522d96386dcc6ede800e19ee2b6410641c46df26537982de0e59
                                                                        • Opcode Fuzzy Hash: a0b2f147c5ed72e73a9ba99eccd64d774068bd057930b9dd808764ab5dc4e304
                                                                        • Instruction Fuzzy Hash: 5A510C32A2875286EB20EF29E8915F96760BB48B84F445535EB4DC779BEF3CE8418740
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _get_daylight$_isindst$_invalid_parameter_noinfo
                                                                        • String ID:
                                                                        • API String ID: 1405656091-0
                                                                        • Opcode ID: cd6fea744430340711cd49b3e9bdbfdb1b852b0eb5a7692198664b91c055b650
                                                                        • Instruction ID: 6c5b0ee35035a43eab4a1dd6f2f891e74d46b0170c7d5d8b2d3d9d8f801e29eb
                                                                        • Opcode Fuzzy Hash: cd6fea744430340711cd49b3e9bdbfdb1b852b0eb5a7692198664b91c055b650
                                                                        • Instruction Fuzzy Hash: 0481A2B3B147464BEB589F29C9512E862A5EB54F88F049135DB0D8A78AFF3CE9508B40
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID: cores
                                                                        • API String ID: 3668304517-2370456839
                                                                        • Opcode ID: a628815777d8d6e0677710be88961967982185a8745b0d9ccb59981e844e2b87
                                                                        • Instruction ID: 9e25c96ffd2a3940396abb04b3cdcbd8f33ae615166812eb14f429c4dc037774
                                                                        • Opcode Fuzzy Hash: a628815777d8d6e0677710be88961967982185a8745b0d9ccb59981e844e2b87
                                                                        • Instruction Fuzzy Hash: D3C1E263E18B818AFB10CB78D4413EC7761E799BA8F105325EB9C56B9AEF38D581C340
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: ProcessToken$AdjustCloseCurrentHandleLookupOpenPrivilegePrivilegesValue
                                                                        • String ID:
                                                                        • API String ID: 3038321057-0
                                                                        • Opcode ID: d2de06470b4ed8e39d37734a47601b9eff7cf65b32299141bc4bcc42cf026e17
                                                                        • Instruction ID: 43fd5498028af3046d34df55629b8ff7f369e625777c81f785d9e078f99e50b4
                                                                        • Opcode Fuzzy Hash: d2de06470b4ed8e39d37734a47601b9eff7cf65b32299141bc4bcc42cf026e17
                                                                        • Instruction Fuzzy Hash: B6216F32628B8186E760CB55F45439AB7A0FB88F80F558135EB8D83B5DEF7CD9458B40
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID: array$object$object key$object separator
                                                                        • API String ID: 0-2277530871
                                                                        • Opcode ID: 3e03f4fe6082dd8bdd1905404cf0848dc19667640bf96f70ae9083624029563c
                                                                        • Instruction ID: 764edc78285676c635f544233c5492f13da4b8a8ea79856d68c3b8d9d0b93a76
                                                                        • Opcode Fuzzy Hash: 3e03f4fe6082dd8bdd1905404cf0848dc19667640bf96f70ae9083624029563c
                                                                        • Instruction Fuzzy Hash: 10028162E28A8696EA10DF78C4915FD2361FB95B84F405236EB4D8779BEF68E944C300
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: 950a1ac75f399888271c1bcfc662195e87ef4bc118ea6b993eee68fc0321c217
                                                                        • Instruction ID: d13cc2c9c101fef6eab22dbbf7632494a2d77951f7dcf58ca796f5487a4b3181
                                                                        • Opcode Fuzzy Hash: 950a1ac75f399888271c1bcfc662195e87ef4bc118ea6b993eee68fc0321c217
                                                                        • Instruction Fuzzy Hash: 43F15072A19F8489EB208B69E44139D77A0F789798F104325EFDC56B9DEF39C5908700
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: a47f2d0b512ce9e7f670028296a07e4266ed9dbc5b54f7c97ff352ec49747c77
                                                                        • Instruction ID: 1e9d9f98e035d3ba86fdc7ca3773e9f1d13f4c17b6fb4a49d4836d0e6ebff256
                                                                        • Opcode Fuzzy Hash: a47f2d0b512ce9e7f670028296a07e4266ed9dbc5b54f7c97ff352ec49747c77
                                                                        • Instruction Fuzzy Hash: 5AF16F72A19F848AEB618B69E44039D77A0F78CB98F101325EFDC56B99EF38D5908740
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: 546c152f43f225051bdbc3a30ff509b75e6cae975be057ce56b515eef410c0ab
                                                                        • Instruction ID: 8d4738beabbf8f205848e4453b3864bfa5562204d107e4befbf5b14101a50d59
                                                                        • Opcode Fuzzy Hash: 546c152f43f225051bdbc3a30ff509b75e6cae975be057ce56b515eef410c0ab
                                                                        • Instruction Fuzzy Hash: 4DF16F72A19F848AEB618B69E44039D77A0F78CB98F105325EFDC56B99EF3CD5908700
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: InformationTimeZone
                                                                        • String ID: [UTC
                                                                        • API String ID: 565725191-1715286942
                                                                        • Opcode ID: 18a376713eb675e677f19022e6b5794e3e33c7ac33213d638e3d988cc9ced565
                                                                        • Instruction ID: 65928e8579a4623a20f903cd34b166d628b7c78ae9c5367d45786f3132320c87
                                                                        • Opcode Fuzzy Hash: 18a376713eb675e677f19022e6b5794e3e33c7ac33213d638e3d988cc9ced565
                                                                        • Instruction Fuzzy Hash: 23B14C32919BC889D7718F29E84129AB7A4F78DB88F105325EBCC57B59EF78D250CB40
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: DriveLogicalStrings
                                                                        • String ID:
                                                                        • API String ID: 2022863570-0
                                                                        • Opcode ID: 8e3b062baa65b3adcedbfaa3c8c3a2baafa25a4fda972cf0885935351d305318
                                                                        • Instruction ID: d123dedb7c55fd8a5e0414c67e4b3a605ff3000ffb454b260b41c905cfd6e0cf
                                                                        • Opcode Fuzzy Hash: 8e3b062baa65b3adcedbfaa3c8c3a2baafa25a4fda972cf0885935351d305318
                                                                        • Instruction Fuzzy Hash: B4517332A18B8182EB10CF28E4803AD7775FB85B94F145225EB9C53BA9EF7CE591D740
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: CryptDataFreeLocalUnprotect
                                                                        • String ID:
                                                                        • API String ID: 1561624719-0
                                                                        • Opcode ID: 3f0d2640eba4d0f7871c2ec703edcb503dbe0d7ea7d03094cd3af9045bbe76bf
                                                                        • Instruction ID: 02b2bcc5e933a11799bf311465c60c6037e18b05a210be82c1f68abbb9962078
                                                                        • Opcode Fuzzy Hash: 3f0d2640eba4d0f7871c2ec703edcb503dbe0d7ea7d03094cd3af9045bbe76bf
                                                                        • Instruction Fuzzy Hash: 32411932A28B81CAE3208F74D4403ED37A4F759B4CF444635EB8D46E8AEF79D5648754
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 3668304517-0
                                                                        • Opcode ID: e270d5c61eaf5cd8cbdd31763e29726b838d3f2bbb78946553259ec46c5a0162
                                                                        • Instruction ID: 29afc45beb768e59d18d89314ffa2b1f0136ba391033b7cb7f4692f660f79aa5
                                                                        • Opcode Fuzzy Hash: e270d5c61eaf5cd8cbdd31763e29726b838d3f2bbb78946553259ec46c5a0162
                                                                        • Instruction Fuzzy Hash: FDD15D62F18B8189F711CB78D4403EC37B2AB59B4CF055225EB8C66B9AEF389590C384
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: NameUser
                                                                        • String ID:
                                                                        • API String ID: 2645101109-0
                                                                        • Opcode ID: 543acbdf146a9e7b635a600a3cba3d05f3b2ef6cd278b1f660c9ea2185c3ff0f
                                                                        • Instruction ID: c2fbcab9b09397aa937a8fd5c1d537920d431776ff68a4a8b206eb96735751ab
                                                                        • Opcode Fuzzy Hash: 543acbdf146a9e7b635a600a3cba3d05f3b2ef6cd278b1f660c9ea2185c3ff0f
                                                                        • Instruction Fuzzy Hash: 9F01653291878182EB21CF15E8413EEB3A4FB98B84F441131E78D8274AEFBCD595CB40
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID: \u%04x
                                                                        • API String ID: 0-2916071157
                                                                        • Opcode ID: 9ac3e7affe24433a80f30ef63aa62ecbe97607ee0ab98c7cb77dcaf1733d29dc
                                                                        • Instruction ID: 6094ccac40004b49a5e723892b23372168480036a7b61332ace1d8d04c6bc5f7
                                                                        • Opcode Fuzzy Hash: 9ac3e7affe24433a80f30ef63aa62ecbe97607ee0ab98c7cb77dcaf1733d29dc
                                                                        • Instruction Fuzzy Hash: BA81C462A2868581FE54DB69D5506FE6760FB85F80F848432DB4E8379AFF3CEA15C340
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID: ":
                                                                        • API String ID: 0-3662656813
                                                                        • Opcode ID: 9785e1fa8e8452fe1f27990b068c258e0a1e89e149615b17a0c92ef7e8177fa0
                                                                        • Instruction ID: ee7977bc6af9c54cabb04490a8cc5708f3f4b606898e240bd724772efc97afc8
                                                                        • Opcode Fuzzy Hash: 9785e1fa8e8452fe1f27990b068c258e0a1e89e149615b17a0c92ef7e8177fa0
                                                                        • Instruction Fuzzy Hash: 29917C76708A8A81DB20DF2AD1942AD73A1F789FC8F449022DF9D47B69DF39D958C700
                                                                        Strings
                                                                        • ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/, xrefs: 00007FF6B5365399
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID: ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
                                                                        • API String ID: 0-1713319389
                                                                        • Opcode ID: a7242879f608aa47813c865fc74e262a7c273f84777ad565790803f492419e94
                                                                        • Instruction ID: 65a21fab81abaf54d29400acb92301c69b097110571a7f00503357c193255c07
                                                                        • Opcode Fuzzy Hash: a7242879f608aa47813c865fc74e262a7c273f84777ad565790803f492419e94
                                                                        • Instruction Fuzzy Hash: C541D46362D7E04AD702CB3984112BD7FB2D366F88B1C8162E7D88774BDA2DD616C711

                                                                        Control-flow Graph

                                                                        • Executed
                                                                        • Not Executed
                                                                        control_flow_graph 1922 7ff6b539ebf0-7ff6b539ec2b call 7ff6b539e970 1925 7ff6b539ec2d-7ff6b539ec3c EnterCriticalSection 1922->1925 1926 7ff6b539ec6c 1922->1926 1927 7ff6b539ec3e-7ff6b539ec60 GdiplusStartup 1925->1927 1928 7ff6b539ec90-7ff6b539ecaa LeaveCriticalSection GdipGetImageEncodersSize 1925->1928 1929 7ff6b539ec71-7ff6b539ec8f call 7ff6b53ce860 1926->1929 1927->1928 1930 7ff6b539ec62-7ff6b539ec66 LeaveCriticalSection 1927->1930 1928->1926 1932 7ff6b539ecac-7ff6b539ecbf 1928->1932 1930->1926 1934 7ff6b539ecc1-7ff6b539ecca call 7ff6b539e700 1932->1934 1935 7ff6b539ecfb-7ff6b539ed09 call 7ff6b53b83d8 1932->1935 1942 7ff6b539ecf8 1934->1942 1943 7ff6b539eccc-7ff6b539ecd6 1934->1943 1940 7ff6b539ed10-7ff6b539ed1a 1935->1940 1941 7ff6b539ed0b-7ff6b539ed0e 1935->1941 1944 7ff6b539ed1e 1940->1944 1941->1944 1942->1935 1945 7ff6b539ece2-7ff6b539ecf6 call 7ff6b53cf520 1943->1945 1946 7ff6b539ecd8 1943->1946 1947 7ff6b539ed21-7ff6b539ed24 1944->1947 1945->1947 1946->1945 1949 7ff6b539ed30-7ff6b539ed3e GdipGetImageEncoders 1947->1949 1950 7ff6b539ed26-7ff6b539ed2b 1947->1950 1953 7ff6b539ed44-7ff6b539ed4d 1949->1953 1954 7ff6b539ee89-7ff6b539ee8e 1949->1954 1952 7ff6b539ee9e-7ff6b539eea1 1950->1952 1957 7ff6b539eea3-7ff6b539eea7 1952->1957 1958 7ff6b539eec4-7ff6b539eec6 1952->1958 1955 7ff6b539ed7f 1953->1955 1956 7ff6b539ed4f-7ff6b539ed5d 1953->1956 1954->1952 1959 7ff6b539ed86-7ff6b539ed96 1955->1959 1960 7ff6b539ed60-7ff6b539ed6b 1956->1960 1961 7ff6b539eeb0-7ff6b539eec2 call 7ff6b53b7620 1957->1961 1958->1929 1962 7ff6b539edaf-7ff6b539edcb 1959->1962 1963 7ff6b539ed98-7ff6b539eda9 1959->1963 1964 7ff6b539ed78-7ff6b539ed7d 1960->1964 1965 7ff6b539ed6d-7ff6b539ed72 1960->1965 1961->1958 1968 7ff6b539ee38-7ff6b539ee77 GdipCreateBitmapFromHBITMAP GdipSaveImageToStream 1962->1968 1969 7ff6b539edcd-7ff6b539ee26 GdipCreateBitmapFromScan0 GdipSaveImageToStream 1962->1969 1963->1954 1963->1962 1964->1955 1964->1960 1965->1964 1970 7ff6b539ee2d-7ff6b539ee31 1965->1970 1973 7ff6b539ee90-7ff6b539ee9d GdipDisposeImage 1968->1973 1974 7ff6b539ee79 1968->1974 1971 7ff6b539ee36 1969->1971 1972 7ff6b539ee28-7ff6b539ee2b 1969->1972 1970->1959 1971->1973 1975 7ff6b539ee7c-7ff6b539ee83 GdipDisposeImage 1972->1975 1973->1952 1974->1975 1975->1954
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Gdip$Image$CriticalSection$DisposeEncodersLeave$BitmapCreateEnterErrorFromGdiplusInitializeLastSaveScan0SizeStartupStream
                                                                        • String ID: &
                                                                        • API String ID: 1703174404-3042966939
                                                                        • Opcode ID: dd964381881d80bb3d13f7f21f812b9ad7ab8c9b9795b3d442a88d8ae0dd4017
                                                                        • Instruction ID: a26cc16a56237e307fb10644b55aeb920f6c68407f2def5c4159ed1e85a59710
                                                                        • Opcode Fuzzy Hash: dd964381881d80bb3d13f7f21f812b9ad7ab8c9b9795b3d442a88d8ae0dd4017
                                                                        • Instruction Fuzzy Hash: AE918172A14B4299E7208F28D8005E837A0FB48F98F554535DB4E87B9AEF3CED51D340

                                                                        Control-flow Graph

                                                                        • Executed
                                                                        • Not Executed
                                                                        control_flow_graph 2305 7ff6b539fca0-7ff6b539fdc6 call 7ff6b53a58d0 call 7ff6b537d590 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b53686b0 call 7ff6b5361900 call 7ff6b5363ff0 WSAStartup 2320 7ff6b539fe87 2305->2320 2321 7ff6b539fdcc-7ff6b539fdec socket 2305->2321 2324 7ff6b539fe89-7ff6b539fe91 2320->2324 2322 7ff6b539fe81 WSACleanup 2321->2322 2323 7ff6b539fdf2-7ff6b539fe1e htons 2321->2323 2322->2320 2325 7ff6b539fe24-7ff6b539fe34 call 7ff6b53ad830 2323->2325 2326 7ff6b539ff29-7ff6b539ff5a call 7ff6b539eed0 call 7ff6b53626d0 2323->2326 2327 7ff6b539fe93-7ff6b539fea4 2324->2327 2328 7ff6b539fec4-7ff6b539ff05 call 7ff6b53ce860 2324->2328 2340 7ff6b539fe36 2325->2340 2341 7ff6b539fe39-7ff6b539fe65 inet_pton connect 2325->2341 2350 7ff6b539ff92-7ff6b539ffaf call 7ff6b539eed0 2326->2350 2351 7ff6b539ff5c-7ff6b539ff72 2326->2351 2332 7ff6b539febf call 7ff6b53ce880 2327->2332 2333 7ff6b539fea6-7ff6b539feb9 2327->2333 2332->2328 2333->2332 2337 7ff6b53a002b-7ff6b53a0030 call 7ff6b53b8254 2333->2337 2347 7ff6b53a0031-7ff6b53a0036 call 7ff6b53b8254 2337->2347 2340->2341 2344 7ff6b539ff06-7ff6b539ff10 2341->2344 2345 7ff6b539fe6b-7ff6b539fe72 2341->2345 2344->2326 2348 7ff6b539ff12-7ff6b539ff1b 2344->2348 2345->2325 2349 7ff6b539fe74-7ff6b539fe7b closesocket 2345->2349 2354 7ff6b539ff20-7ff6b539ff28 call 7ff6b5364600 2348->2354 2355 7ff6b539ff1d 2348->2355 2349->2322 2359 7ff6b539ffb4-7ff6b539ffd8 call 7ff6b53626d0 2350->2359 2356 7ff6b539ff74-7ff6b539ff87 2351->2356 2357 7ff6b539ff8d call 7ff6b53ce880 2351->2357 2354->2326 2355->2354 2356->2347 2356->2357 2357->2350 2365 7ff6b53a0014-7ff6b53a0020 2359->2365 2366 7ff6b539ffda-7ff6b539fff0 2359->2366 2365->2324 2367 7ff6b539fff2-7ff6b53a0005 2366->2367 2368 7ff6b53a0007-7ff6b53a000c call 7ff6b53ce880 2366->2368 2367->2368 2369 7ff6b53a0025-7ff6b53a002a call 7ff6b53b8254 2367->2369 2368->2365 2369->2337
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$Info$CleanupStartupUserclosesocketconnecthtonsinet_ptonsocket
                                                                        • String ID: geo$system
                                                                        • API String ID: 2440148987-2364779556
                                                                        • Opcode ID: 02e0bb30d50e4f60a1a390282dc6d7d1ef9c07bed104d2a4ba7a7becf75d310b
                                                                        • Instruction ID: 1644aeeccf4b5dfe57a14c0fa2a6ca92c53d1fadc522c1e479c7abce5ff8a0b7
                                                                        • Opcode Fuzzy Hash: 02e0bb30d50e4f60a1a390282dc6d7d1ef9c07bed104d2a4ba7a7becf75d310b
                                                                        • Instruction Fuzzy Hash: B3B1A062F28B8285FB01DBA8E4402EC2371AB55B98F415236DB5D977AFEE38D945C340

                                                                        Control-flow Graph

                                                                        • Executed
                                                                        • Not Executed
                                                                        control_flow_graph 2374 7ff6b53a4a30-7ff6b53a4a92 call 7ff6b53cf520 call 7ff6b53ac190 2379 7ff6b53a4a94 2374->2379 2380 7ff6b53a4a97-7ff6b53a4ae1 call 7ff6b5365310 call 7ff6b5364fe0 2374->2380 2379->2380 2385 7ff6b53a4ae3-7ff6b53a4af5 2380->2385 2386 7ff6b53a4b15-7ff6b53a4b34 2380->2386 2387 7ff6b53a4b10 call 7ff6b53ce880 2385->2387 2388 7ff6b53a4af7-7ff6b53a4b0a 2385->2388 2389 7ff6b53a4b36-7ff6b53a4b4b 2386->2389 2390 7ff6b53a4b6b-7ff6b53a4bef call 7ff6b53a0e00 call 7ff6b53e1650 2386->2390 2387->2386 2388->2387 2391 7ff6b53a51fc-7ff6b53a5201 call 7ff6b53b8254 2388->2391 2393 7ff6b53a4b66 call 7ff6b53ce880 2389->2393 2394 7ff6b53a4b4d-7ff6b53a4b60 2389->2394 2406 7ff6b53a4bf4-7ff6b53a4c14 recv 2390->2406 2397 7ff6b53a5202-7ff6b53a5207 call 7ff6b53b8254 2391->2397 2393->2390 2394->2393 2394->2397 2405 7ff6b53a5208-7ff6b53a520d call 7ff6b53b8254 2397->2405 2420 7ff6b53a520e-7ff6b53a5213 call 7ff6b53b8254 2405->2420 2408 7ff6b53a4cd7-7ff6b53a4d19 2406->2408 2409 7ff6b53a4c1a-7ff6b53a4c36 2406->2409 2410 7ff6b53a4d1f 2408->2410 2411 7ff6b53a5011-7ff6b53a5029 2408->2411 2413 7ff6b53a4c76-7ff6b53a4c92 call 7ff6b5369030 2409->2413 2414 7ff6b53a4c38-7ff6b53a4c74 call 7ff6b53e0fb0 2409->2414 2419 7ff6b53a4d20-7ff6b53a4d2c call 7ff6b53b89b0 2410->2419 2416 7ff6b53a502f-7ff6b53a5080 call 7ff6b536b220 call 7ff6b53a0e00 2411->2416 2417 7ff6b53a5220-7ff6b53a5225 call 7ff6b534b8e0 2411->2417 2423 7ff6b53a4c97-7ff6b53a4ca0 2413->2423 2414->2423 2438 7ff6b53a5085-7ff6b53a5095 2416->2438 2434 7ff6b53a5226-7ff6b53a522b call 7ff6b53b8254 2417->2434 2435 7ff6b53a4d32-7ff6b53a4d35 2419->2435 2436 7ff6b53a5005-7ff6b53a500b 2419->2436 2432 7ff6b53a5214-7ff6b53a5219 call 7ff6b53b8254 2420->2432 2423->2406 2429 7ff6b53a4ca6-7ff6b53a4cd3 2423->2429 2429->2408 2446 7ff6b53a521a-7ff6b53a521f call 7ff6b53b8254 2432->2446 2450 7ff6b53a522c-7ff6b53a5231 call 7ff6b53b8254 2434->2450 2435->2436 2440 7ff6b53a4d3b-7ff6b53a4dec call 7ff6b5366700 call 7ff6b5390040 call 7ff6b53637f0 call 7ff6b53a0e90 call 7ff6b53ac190 2435->2440 2436->2411 2436->2419 2442 7ff6b53a5097-7ff6b53a50a9 2438->2442 2443 7ff6b53a50c9-7ff6b53a50cf 2438->2443 2483 7ff6b53a4dee 2440->2483 2484 7ff6b53a4df1-7ff6b53a4e92 call 7ff6b5365310 call 7ff6b5363d70 call 7ff6b53a0e00 2440->2484 2447 7ff6b53a50c4 call 7ff6b53ce880 2442->2447 2448 7ff6b53a50ab-7ff6b53a50be 2442->2448 2449 7ff6b53a50d4-7ff6b53a50fc recv 2443->2449 2446->2417 2447->2443 2448->2434 2448->2447 2452 7ff6b53a50fe closesocket 2449->2452 2453 7ff6b53a5104-7ff6b53a5117 WSACleanup 2449->2453 2463 7ff6b53a5232-7ff6b53a5237 call 7ff6b53b8254 2450->2463 2452->2453 2459 7ff6b53a514e-7ff6b53a5176 2453->2459 2460 7ff6b53a5119-7ff6b53a512e 2453->2460 2467 7ff6b53a5178-7ff6b53a518d 2459->2467 2468 7ff6b53a51ad-7ff6b53a51fb call 7ff6b53ce860 2459->2468 2465 7ff6b53a5130-7ff6b53a5143 2460->2465 2466 7ff6b53a5149 call 7ff6b53ce880 2460->2466 2465->2450 2465->2466 2466->2459 2473 7ff6b53a518f-7ff6b53a51a2 2467->2473 2474 7ff6b53a51a8 call 7ff6b53ce880 2467->2474 2473->2463 2473->2474 2474->2468 2483->2484 2491 7ff6b53a4e94-7ff6b53a4ea6 2484->2491 2492 7ff6b53a4ec6-7ff6b53a4ee4 2484->2492 2495 7ff6b53a4ec1 call 7ff6b53ce880 2491->2495 2496 7ff6b53a4ea8-7ff6b53a4ebb 2491->2496 2493 7ff6b53a4ee6-7ff6b53a4efb 2492->2493 2494 7ff6b53a4f1b-7ff6b53a4f38 2492->2494 2497 7ff6b53a4f16 call 7ff6b53ce880 2493->2497 2498 7ff6b53a4efd-7ff6b53a4f10 2493->2498 2499 7ff6b53a4f6f-7ff6b53a4fb8 call 7ff6b5363ff0 * 2 2494->2499 2500 7ff6b53a4f3a-7ff6b53a4f4f 2494->2500 2495->2492 2496->2405 2496->2495 2497->2494 2498->2420 2498->2497 2510 7ff6b53a4fef-7ff6b53a5000 2499->2510 2511 7ff6b53a4fba-7ff6b53a4fcf 2499->2511 2503 7ff6b53a4f51-7ff6b53a4f64 2500->2503 2504 7ff6b53a4f6a call 7ff6b53ce880 2500->2504 2503->2432 2503->2504 2504->2499 2510->2449 2512 7ff6b53a4fd1-7ff6b53a4fe4 2511->2512 2513 7ff6b53a4fea call 7ff6b53ce880 2511->2513 2512->2446 2512->2513 2513->2510
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$recv$Cleanupclosesocket
                                                                        • String ID:
                                                                        • API String ID: 3402187201-0
                                                                        • Opcode ID: e4049c0f03e734e85074100bd3b76624debaa060f52d0637e420a22afa0280fc
                                                                        • Instruction ID: 1c443b530f00e6a2ee0cb672f75de4c6df909b3e974bf9ab656f4d55ba2b97a6
                                                                        • Opcode Fuzzy Hash: e4049c0f03e734e85074100bd3b76624debaa060f52d0637e420a22afa0280fc
                                                                        • Instruction Fuzzy Hash: 3B125472A28BC141EE619B18E4453EE6751EB89B90F505631D79D86BDFEF7CD880C700
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 3668304517-0
                                                                        • Opcode ID: d330a8cb40c11d9bbda9cd3e9dcd861a0136ce310c17c43692026fbbce82bec1
                                                                        • Instruction ID: eddbbf1cb33532c41c3455862ccaba18e98c942b3508df31b9006d06c063cbb7
                                                                        • Opcode Fuzzy Hash: d330a8cb40c11d9bbda9cd3e9dcd861a0136ce310c17c43692026fbbce82bec1
                                                                        • Instruction Fuzzy Hash: 13E1D2A3E28BC145EF119B38C4453ED6711EB99BA4F105721EB6C46BDFEFB895818340
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo
                                                                        • String ID:
                                                                        • API String ID: 3215553584-0
                                                                        • Opcode ID: f3fc50aa6c1617f97820c214b6f357f8593fa625a947542fe4ec2dfdbb2d532b
                                                                        • Instruction ID: b4fa5d3b5f6cb7f0471ba367aff91342a265530acf6626e81f4413df0dd0a475
                                                                        • Opcode Fuzzy Hash: f3fc50aa6c1617f97820c214b6f357f8593fa625a947542fe4ec2dfdbb2d532b
                                                                        • Instruction Fuzzy Hash: 6DC1DE22A2CBD281EA62AB5894042FD7BA1FB81F80F554131DB4D8739BEF7CEC458700
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$CloseEnumOpen
                                                                        • String ID:
                                                                        • API String ID: 2177193445-0
                                                                        • Opcode ID: a7c187bf2d3df3035d1c32dd6db5852f892d83f129299faf2889f6e133470741
                                                                        • Instruction ID: e51aa3ad6b6964cb0f1bf4e55652917cfdd915330b2ba698a6a2b037501f3b2d
                                                                        • Opcode Fuzzy Hash: a7c187bf2d3df3035d1c32dd6db5852f892d83f129299faf2889f6e133470741
                                                                        • Instruction Fuzzy Hash: B9717472A18B4685EB10CB69E4843AD6760FB45BA8F100225EFAD57BDAEF7CD481C740
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: CriticalSection$EnterLeave$DeleteGdiplusObjectShutdown
                                                                        • String ID:
                                                                        • API String ID: 4268643673-0
                                                                        • Opcode ID: f5a1ecfcc53808b035d0d15b7c47fae7049546fa7d089acffeffd9e0bb2d86bb
                                                                        • Instruction ID: 90a5401d07c77c33b00549cccaf637fbfbe84f7bce4a9e30423a42283485e1f8
                                                                        • Opcode Fuzzy Hash: f5a1ecfcc53808b035d0d15b7c47fae7049546fa7d089acffeffd9e0bb2d86bb
                                                                        • Instruction Fuzzy Hash: BB112B32525B5291EB109F29E8400AD7774FB48F64B684335D76E827BAEF38DC96C340
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID: exists
                                                                        • API String ID: 3668304517-2996790960
                                                                        • Opcode ID: e0ca86984dcd63806b142e340e89520d029b4b1e41b0c09aa18580b05522bf4e
                                                                        • Instruction ID: 5c789cc37886c0e82381b26a4ccebedb4f7ce1fd8835502d855c130ef731dc32
                                                                        • Opcode Fuzzy Hash: e0ca86984dcd63806b142e340e89520d029b4b1e41b0c09aa18580b05522bf4e
                                                                        • Instruction Fuzzy Hash: 73A18472A24B8596EB14DF2CD8402ED6361FB84B98F105635EB5C87B9EEF39D981C700
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID: exists
                                                                        • API String ID: 3668304517-2996790960
                                                                        • Opcode ID: e207551f326048aa0344b556460f67db7219f5dab07e3a915515719821886c2f
                                                                        • Instruction ID: 57f25be4d461463c32602c025a3ed592fdf1dca14505f7595681fa226de70847
                                                                        • Opcode Fuzzy Hash: e207551f326048aa0344b556460f67db7219f5dab07e3a915515719821886c2f
                                                                        • Instruction Fuzzy Hash: FCA18372A24B8585EB149F2CE8402ED6361FB48B98F145631EB5D87BEEEF38D941C340
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: EnumOpen
                                                                        • String ID:
                                                                        • API String ID: 3231578192-0
                                                                        • Opcode ID: 69580b2b5a3aab25ec6d1d344f29727ed6fdfb6e770ce3ab2c6c0fb9dc78db39
                                                                        • Instruction ID: 2b2370c500f64bdff8d0e44a0b1ae6d858940e6985298093304468596114b1f5
                                                                        • Opcode Fuzzy Hash: 69580b2b5a3aab25ec6d1d344f29727ed6fdfb6e770ce3ab2c6c0fb9dc78db39
                                                                        • Instruction Fuzzy Hash: AB31B132A14B8685EB20CFA5E8506EE73A4FB44B98F200225EF9D57B59EF7CD491C700
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID: exists$ios_base::badbit set
                                                                        • API String ID: 3668304517-2074760687
                                                                        • Opcode ID: 8d76c458315178a25db09c9fdcb847d61e55080ddf0c55f8758765ae8eff06c0
                                                                        • Instruction ID: 95ba579b3f14d6a8b7d3fb0e0f56e6a1b97a6dbc2e3ad9239abb8b40f079e738
                                                                        • Opcode Fuzzy Hash: 8d76c458315178a25db09c9fdcb847d61e55080ddf0c55f8758765ae8eff06c0
                                                                        • Instruction Fuzzy Hash: 5EF11072A1D7C691EA61DB18E4943EE6360FBC5B44F404136DB8D82AAEEF7CD905CB00
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID: exists$ios_base::badbit set
                                                                        • API String ID: 0-2074760687
                                                                        • Opcode ID: 086b57f9886700431aaf3c7483acab306003d5ac3e84676a1be3477eb7fef4fe
                                                                        • Instruction ID: a8fbedef54e52041556fb32be396106ad55b69319d7db96af6f6f303b20d33df
                                                                        • Opcode Fuzzy Hash: 086b57f9886700431aaf3c7483acab306003d5ac3e84676a1be3477eb7fef4fe
                                                                        • Instruction Fuzzy Hash: 00F11172619BC691EA21DB18E4943EE6360FB84B44F404136DB8D87BAEEF7CD945CB40
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$DriveFileFindFirstLogicalStrings
                                                                        • String ID: content$filename
                                                                        • API String ID: 3820383557-474635906
                                                                        • Opcode ID: fa5208d88c68d2acc46f28a84c02dd075b818341273278fff3188706dd4d5c7b
                                                                        • Instruction ID: 6dd44b55fb75bd3de36facfc0b120d12a74ed534efbe58bae268ffe51d94bd80
                                                                        • Opcode Fuzzy Hash: fa5208d88c68d2acc46f28a84c02dd075b818341273278fff3188706dd4d5c7b
                                                                        • Instruction Fuzzy Hash: 30416662E2864141ED219B19F0402EEA751EB89FF4F181731EBAD477DFEE6CD9818700
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 73155330-0
                                                                        • Opcode ID: c982040780983701d7c8c68c8f15831c94ac4fcd0ba8b68d463e439d02204967
                                                                        • Instruction ID: b4adbb7d9838145ede69c00ce3733d5ea1df3c1545e1defaa23ce106cdc2789c
                                                                        • Opcode Fuzzy Hash: c982040780983701d7c8c68c8f15831c94ac4fcd0ba8b68d463e439d02204967
                                                                        • Instruction Fuzzy Hash: E451D962B2D74145EE659B19A5003F9A291AB08FE4F580635DF6D877CFFE7CD8918300
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: ProcessToken$CloseCurrentHandleInformationOpen
                                                                        • String ID:
                                                                        • API String ID: 215268677-0
                                                                        • Opcode ID: 1c225c442ed3ae12c114120d81f2afce391d37106ff629cfd40a7a8c2f449ed4
                                                                        • Instruction ID: 7f109c17ae6a7d224b0b712147b778a811bfc1083729d1c459f10287a2ff637f
                                                                        • Opcode Fuzzy Hash: 1c225c442ed3ae12c114120d81f2afce391d37106ff629cfd40a7a8c2f449ed4
                                                                        • Instruction Fuzzy Hash: A2110D72629B8182E7519B15F44039AB7A0FB88F80F545135EB9D87B6DDF3CD845CB40
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 73155330-3916222277
                                                                        • Opcode ID: b0b8d49bc1df27a546c8eec398477bcb107d70757808efc6048da727df17449e
                                                                        • Instruction ID: da2472f720c4ee6d5ef4cd52530dc292f986ada93d9d22c40483306b39fdf38d
                                                                        • Opcode Fuzzy Hash: b0b8d49bc1df27a546c8eec398477bcb107d70757808efc6048da727df17449e
                                                                        • Instruction Fuzzy Hash: 8B519032A18B4686EB158F2AD1902AC7360FB48F90F554635DF4D87BAADF7DE861C300
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Value
                                                                        • String ID: ProductName$SOFTWARE\Microsoft\Windows NT\CurrentVersion
                                                                        • API String ID: 3702945584-1787575317
                                                                        • Opcode ID: d87b399df5c9077b40aef7209b4abd77c2f618c6539b482bda78f483f437df22
                                                                        • Instruction ID: 54302e44443562b27b507d1c57e8a50156ae04a9414a32dd128973625a6ea6f7
                                                                        • Opcode Fuzzy Hash: d87b399df5c9077b40aef7209b4abd77c2f618c6539b482bda78f483f437df22
                                                                        • Instruction Fuzzy Hash: 66116032518B8582DB218F25F45039AB3A4FB89B84F504235EB9C43B59DF7CD555CB40
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$Cleanupclosesocketrecv
                                                                        • String ID:
                                                                        • API String ID: 1729841683-0
                                                                        • Opcode ID: 54f43d891644014835c493d497154d131fa72254285a80c0f04bf4e12e8f8f00
                                                                        • Instruction ID: f1e66b5c82d7cc61d3f08079574ffe3aedd0092ff647cb44683d57959efd61ce
                                                                        • Opcode Fuzzy Hash: 54f43d891644014835c493d497154d131fa72254285a80c0f04bf4e12e8f8f00
                                                                        • Instruction Fuzzy Hash: 1E914463E28BC141EE219718E4443EE6761EB85BA0F105335DBAD46BDEEF7CD8809740
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: __std_fs_directory_iterator_open
                                                                        • String ID:
                                                                        • API String ID: 4007087469-0
                                                                        • Opcode ID: d4604204593d342e570c4926b62fada30b6957409627625e7c2239f99d44b0cf
                                                                        • Instruction ID: b3dd5d3b6779b761a82af4784350c85a4bd4c6688ae070fc3ad75260ede53cea
                                                                        • Opcode Fuzzy Hash: d4604204593d342e570c4926b62fada30b6957409627625e7c2239f99d44b0cf
                                                                        • Instruction Fuzzy Hash: 5D619362F24A4285EB10DB6DD4802FC23A1EB48BA4F004631DF2D967DAFE3DDD959341
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 3668304517-0
                                                                        • Opcode ID: 1fcdd001bad7e88b769d8549c00ef065f4b371976f5fa0d120353f35bad732bd
                                                                        • Instruction ID: 0d0f8eb19c57a305dbe745e7f2d4c3b4c01cd25c51b387f1b6d69aa0dbc0bec3
                                                                        • Opcode Fuzzy Hash: 1fcdd001bad7e88b769d8549c00ef065f4b371976f5fa0d120353f35bad732bd
                                                                        • Instruction Fuzzy Hash: 7B318BB3A29B8484EF55DE28D4643FCA355EB44F88F540539DB5D8AB9AEF29C8908300
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: FolderFreeKnownPathTask_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 2444108017-0
                                                                        • Opcode ID: ae204a587ab0ef826eab955bf18b5cfd079d10c08874d19813b769850f893d30
                                                                        • Instruction ID: 9005fac86f166d5640b39205b18f729b8f1c4de27ba79dcc5c667acf07bb0066
                                                                        • Opcode Fuzzy Hash: ae204a587ab0ef826eab955bf18b5cfd079d10c08874d19813b769850f893d30
                                                                        • Instruction Fuzzy Hash: 35318A7292878581E620CF29E44025EB761FB99BB4F105335FBAD4379AEF7CD5818740
                                                                        APIs
                                                                        • GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,00007FF6B53CD34F), ref: 00007FF6B53CE25D
                                                                        • FreeEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,00007FF6B53CD34F), ref: 00007FF6B53CE2CF
                                                                          • Part of subcall function 00007FF6B53BE8BC: HeapAlloc.KERNEL32 ref: 00007FF6B53BE8FA
                                                                        • FreeEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,00007FF6B53CD34F), ref: 00007FF6B53CE32E
                                                                          • Part of subcall function 00007FF6B53BD3C8: RtlFreeHeap.NTDLL ref: 00007FF6B53BD3DE
                                                                          • Part of subcall function 00007FF6B53BD3C8: GetLastError.KERNEL32 ref: 00007FF6B53BD3E8
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: EnvironmentFreeStrings$Heap$AllocErrorLast
                                                                        • String ID:
                                                                        • API String ID: 3331406755-0
                                                                        • Opcode ID: f79ec361922fc1fde17e438abd9a0df1426056f3875ee8e29d5efadf54f3a626
                                                                        • Instruction ID: 8b5eac1162c42c8e01b451eff82e5e906c194d66d19d02ff4180d1a347ed5511
                                                                        • Opcode Fuzzy Hash: f79ec361922fc1fde17e438abd9a0df1426056f3875ee8e29d5efadf54f3a626
                                                                        • Instruction Fuzzy Hash: 5331DB31A2C76281E625AF2964011BD7694BF48FD0F485235EB5E83BDBEF3CE8519300
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: CloseOpenQueryValue
                                                                        • String ID:
                                                                        • API String ID: 3677997916-0
                                                                        • Opcode ID: c76bf7f6fb56c596a02d874e197e6ed852ab18b90a89a93ee840bc8b0d2acff9
                                                                        • Instruction ID: 6da89d90781b4ad2d63da61057c648dca6c13d404c35368584802578a7a47fe1
                                                                        • Opcode Fuzzy Hash: c76bf7f6fb56c596a02d874e197e6ed852ab18b90a89a93ee840bc8b0d2acff9
                                                                        • Instruction Fuzzy Hash: 4021A962E28B8641EE50CB29E4507AEA750FBD5FD4F405235EB8D82B5EEE2CD485C700
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Info$User
                                                                        • String ID:
                                                                        • API String ID: 2017065092-0
                                                                        • Opcode ID: 877c1b4e073b3a87c3d7ac6068cbd316133fc0437c9f32c249d117db553f0db1
                                                                        • Instruction ID: 4ca36f9a070ef809fce401ccbb26950ef2143d7daa486b254e7778ab1822b7b4
                                                                        • Opcode Fuzzy Hash: 877c1b4e073b3a87c3d7ac6068cbd316133fc0437c9f32c249d117db553f0db1
                                                                        • Instruction Fuzzy Hash: 79119032A2878182DB108F65E45075EB3A1FB80FC8F055139EB8947B5AEF7CE8908B44
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Process$CurrentExitTerminate
                                                                        • String ID:
                                                                        • API String ID: 1703294689-0
                                                                        • Opcode ID: 38c7b4f83e553420579c8e330882a64258dcf8d372290847a19fb81a50e45df1
                                                                        • Instruction ID: d9af55a54f28e8c4f71c321f6062261ec07c6e64fdb08746ea802dd227622dd6
                                                                        • Opcode Fuzzy Hash: 38c7b4f83e553420579c8e330882a64258dcf8d372290847a19fb81a50e45df1
                                                                        • Instruction Fuzzy Hash: 8FD09E10B2871652EF543B7858951FC12555F99F02F411438DA4BC639BFE2DBC494310
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: CurrentProfile
                                                                        • String ID: Unknown
                                                                        • API String ID: 2104809126-1654365787
                                                                        • Opcode ID: 074748e7d716de5a741a71d41128afce1c4a4904971589a04e7448f2158e9804
                                                                        • Instruction ID: ddb1c376897e180a0ad0fd2c7d35c334350d959141f9e280b6fe345faa05733e
                                                                        • Opcode Fuzzy Hash: 074748e7d716de5a741a71d41128afce1c4a4904971589a04e7448f2158e9804
                                                                        • Instruction Fuzzy Hash: A131D322A2CBC186E7118F14E4502EAB770FB99B44F541235EBCD42A5ADF7CD995CB00
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: a3bcc4ad50dac9bc57f7f1afbf8202ee64cfbe29c1620eabfb65d15c4670d6b7
                                                                        • Instruction ID: 8bdd44bf73b2a935dcc8e3b810ea3cc127b40270a19a02bceec5bdf97e69db44
                                                                        • Opcode Fuzzy Hash: a3bcc4ad50dac9bc57f7f1afbf8202ee64cfbe29c1620eabfb65d15c4670d6b7
                                                                        • Instruction Fuzzy Hash: 69A16F72A14B8586EB519F29D8443AD77A0F789F94F188135EB4D877AAEF3CC881C740
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 73155330-0
                                                                        • Opcode ID: ad4055faee7288f66228d296372c78f9137bed5d5abb172f92ae91a1768b0b61
                                                                        • Instruction ID: 1102cc73c6e6d77f3c10517791ca9d722384ce3fea92c6e4e735a8ba950e5575
                                                                        • Opcode Fuzzy Hash: ad4055faee7288f66228d296372c78f9137bed5d5abb172f92ae91a1768b0b61
                                                                        • Instruction Fuzzy Hash: BE61AC2AA18A8184EF15DA59D1542BD27A1AB04FD8F548631CF5D873DAFF3EEC46D300
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$CloseOpen
                                                                        • String ID:
                                                                        • API String ID: 3087652857-0
                                                                        • Opcode ID: 8c278f5547a466ec54e0be15147785784f58f0030a1dc7da1f4e2a7823480ad4
                                                                        • Instruction ID: 291e6fa39091ede676404d3729c36f4dc47f3074eabf04ff166662841dc21bbd
                                                                        • Opcode Fuzzy Hash: 8c278f5547a466ec54e0be15147785784f58f0030a1dc7da1f4e2a7823480ad4
                                                                        • Instruction Fuzzy Hash: 4F718062A18B8185EB20CB68E4403ED77A1F789B94F505225EB9D87B9EEF7CD544C700
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 73155330-0
                                                                        • Opcode ID: c46320af81983bf8b7d8a097502b6e08044de0ccd2ffde461da5f276321cfa26
                                                                        • Instruction ID: 1931e6534963cdfdaaebb8e006f71ba0410ab84162d6ed94bca0aee82c994cec
                                                                        • Opcode Fuzzy Hash: c46320af81983bf8b7d8a097502b6e08044de0ccd2ffde461da5f276321cfa26
                                                                        • Instruction Fuzzy Hash: 8051CA72A29B4681EA11DB19E4403B9B3A0FF59F84F544535DB8D8376AEF7CD8918300
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 73155330-0
                                                                        • Opcode ID: 48f184e3a50fa740ea764832f58b5c85ec3e3188245a360da0dc6bed7c2c5238
                                                                        • Instruction ID: ce2559ef484048d844c2f94d0c81f8bcf5df1a926252c01c79845f414406cce3
                                                                        • Opcode Fuzzy Hash: 48f184e3a50fa740ea764832f58b5c85ec3e3188245a360da0dc6bed7c2c5238
                                                                        • Instruction Fuzzy Hash: C841B26272CB8281EE109B19E1042EDA692FB09FD4F540635EF6D4B78FEE3CD8519310
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 73155330-0
                                                                        • Opcode ID: ffaf9a7a538868ca1479d97af9205b187dea902369c89d1255280d304756ba1d
                                                                        • Instruction ID: 55446b42d504b612c4e2f0c10c58eaf430867029af0cba21dd37ba879918f8a5
                                                                        • Opcode Fuzzy Hash: ffaf9a7a538868ca1479d97af9205b187dea902369c89d1255280d304756ba1d
                                                                        • Instruction Fuzzy Hash: 1D419472A28B8581EA25CB69E5445BEA7A0FB48FD0F504535DBAD43B8AEF3CD850C300
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 73155330-0
                                                                        • Opcode ID: 9676c107121d3e70a5adfe4281e7c37e46f938058757e8ddbb0459af90ab29eb
                                                                        • Instruction ID: 5d00ff678da565bf363526dc84844d9fc75a984e2ff7dc1d0e334b64b5bed6db
                                                                        • Opcode Fuzzy Hash: 9676c107121d3e70a5adfe4281e7c37e46f938058757e8ddbb0459af90ab29eb
                                                                        • Instruction Fuzzy Hash: 37411262B2C74281EE219B1AA5143F9A251AB08FD4F544635EF6D8B7CFEE3CD9429700
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 73155330-0
                                                                        • Opcode ID: cfc677c0362671b68f402e64f126341eafd3132707cfd2e1d4c22178fd9eeaf6
                                                                        • Instruction ID: 85a0670ef4f93438d817bbf191f55c990a3c519b100d87165847bf46ac22be34
                                                                        • Opcode Fuzzy Hash: cfc677c0362671b68f402e64f126341eafd3132707cfd2e1d4c22178fd9eeaf6
                                                                        • Instruction Fuzzy Hash: 5531E022F2D78244FE55AE19A5803F912819B05FE4F540235CB2D87BCBFE3CE8919340
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 73155330-0
                                                                        • Opcode ID: 0ababa0627008bd160181e784337c41553f7c6b491df3b020ffa885aa2a51f5a
                                                                        • Instruction ID: 192e39dc584face719a0a2122168235a87014eb2afd2fc032890ad6ae94f1101
                                                                        • Opcode Fuzzy Hash: 0ababa0627008bd160181e784337c41553f7c6b491df3b020ffa885aa2a51f5a
                                                                        • Instruction Fuzzy Hash: FF312562B2C78284EE609B19A4043ECA291EB08FD4F580635DF5C8B7CBEE3CE851C300
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: InformationVolume_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 4269842375-0
                                                                        • Opcode ID: 9b54662dfc31b99104d5a64d46f481d5e14be556eb9875cdf2309875b13e82c8
                                                                        • Instruction ID: 6bc7a992579721c7e7eebd3721db6d94ec0dc295b9db3a071c13e2b92a08d280
                                                                        • Opcode Fuzzy Hash: 9b54662dfc31b99104d5a64d46f481d5e14be556eb9875cdf2309875b13e82c8
                                                                        • Instruction Fuzzy Hash: F1517F72E28B8185EB11CF68D4402ED7760F799B88F505221EB8D93B9EEF78D985C740
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task__std_exception_copy_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 2371198981-0
                                                                        • Opcode ID: 0c938f5ff597287b413f46e3d76a37b7088594cabf2e2eb79db2830f1b0d95ab
                                                                        • Instruction ID: 444716a9aa682177c815fd5b95163355d86b4c39b0b4d945ea73393d9613c0f1
                                                                        • Opcode Fuzzy Hash: 0c938f5ff597287b413f46e3d76a37b7088594cabf2e2eb79db2830f1b0d95ab
                                                                        • Instruction Fuzzy Hash: 6D21E426A29B4241EA299B19D5403F86290AB44FA4F154635EF6C87BCBFE7CD8D28340
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo
                                                                        • String ID:
                                                                        • API String ID: 3215553584-0
                                                                        • Opcode ID: 77ff38050bbf038ec147631c291faae903e00292372ea36fba1d268a897535c6
                                                                        • Instruction ID: 74a2840a14e9182d98c70db0cfba12dbbacf061ca2c20a7e656c44fe1f14e53c
                                                                        • Opcode Fuzzy Hash: 77ff38050bbf038ec147631c291faae903e00292372ea36fba1d268a897535c6
                                                                        • Instruction Fuzzy Hash: D5319C22A29E4682EE94FB18E4515F92362AB95F90F550131E75EC73DBFE3CE901C704
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: CloseOpen
                                                                        • String ID:
                                                                        • API String ID: 47109696-0
                                                                        • Opcode ID: f1dca321947a1367f0d55f51290a78f41f5e328790fa86022a41bb21031095aa
                                                                        • Instruction ID: 50f319fa076c98a2db7f8b161d1e71982c6d7db7a183300a8a7bdd440030ad3b
                                                                        • Opcode Fuzzy Hash: f1dca321947a1367f0d55f51290a78f41f5e328790fa86022a41bb21031095aa
                                                                        • Instruction Fuzzy Hash: 72219661B28A4545FB509B29E4413EAA360EF98FD4F545131EB4E87B9FEF2CD8418700
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 3668304517-0
                                                                        • Opcode ID: 19d8cef9d40cb5f6eec943bdf1482a87d63508befa2c44a48ff5201e4d6f36a8
                                                                        • Instruction ID: 0c9498a209508120f19159abafbfc0bdf32d6f93b31bff139b8f0cdb64131614
                                                                        • Opcode Fuzzy Hash: 19d8cef9d40cb5f6eec943bdf1482a87d63508befa2c44a48ff5201e4d6f36a8
                                                                        • Instruction Fuzzy Hash: D51186A2B26B8585EF49DF78D4553BD6391DB08F94F144535DB6C8B78AEF2CC8908300
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: CloseCreateCredEnumerateFirstHandleMutexProcess32ReleaseSnapshotToolhelp32recv
                                                                        • String ID:
                                                                        • API String ID: 420082584-0
                                                                        • Opcode ID: bece3b694530cfbeca66faa9e7e0d6adff72bc4c5de40ce38d1c4fa0504811a1
                                                                        • Instruction ID: 8ce7354dcdee82f02b3556745461af484ab624a442d29a0d899d8ea0a27191b6
                                                                        • Opcode Fuzzy Hash: bece3b694530cfbeca66faa9e7e0d6adff72bc4c5de40ce38d1c4fa0504811a1
                                                                        • Instruction Fuzzy Hash: 5E210491E3C68641F952B77CA0163F96240AF85F90F586A31EB9EC17DFBE1CAC409712
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Initialize_invalid_parameter_noinfo_set_fmode
                                                                        • String ID:
                                                                        • API String ID: 3548387204-0
                                                                        • Opcode ID: d990e7904117e8ad445fc8e6d111c2d0f5dc5b035b4e5bb7541dde9c55fd2088
                                                                        • Instruction ID: 0c3af58f2bbe84d22a4fee0f9335458f6b202928b348bdfaa8e246eae9d7b13a
                                                                        • Opcode Fuzzy Hash: d990e7904117e8ad445fc8e6d111c2d0f5dc5b035b4e5bb7541dde9c55fd2088
                                                                        • Instruction Fuzzy Hash: E9119901E2C2A711FA1477B844562F812915F94B45F481878EB4ECA3CBFE2EAC958762
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: CloseHandleMutexReleaserecv
                                                                        • String ID:
                                                                        • API String ID: 2659716615-0
                                                                        • Opcode ID: dd2cc705cdbd18044620e585c3dda16eabb8828c2173ec8563691370528ef67d
                                                                        • Instruction ID: 9c6bdd3d1252c64421c0f564580afff57c85a67f6ac36c54194e80d8eb370966
                                                                        • Opcode Fuzzy Hash: dd2cc705cdbd18044620e585c3dda16eabb8828c2173ec8563691370528ef67d
                                                                        • Instruction Fuzzy Hash: EC116A92E2C68641FA62B73CA0163F95340AF85F90F485630EB9EC17DFBE1CAC409711
                                                                        APIs
                                                                        • SetFilePointerEx.KERNEL32(?,?,?,?,?,00007FF6B53C0E88,?,?,?,?,00000000,00007FF6B53C0F91), ref: 00007FF6B53C0EE8
                                                                        • GetLastError.KERNEL32(?,?,?,?,?,00007FF6B53C0E88,?,?,?,?,00000000,00007FF6B53C0F91), ref: 00007FF6B53C0EF2
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: ErrorFileLastPointer
                                                                        • String ID:
                                                                        • API String ID: 2976181284-0
                                                                        • Opcode ID: 85342b8448b5f83962e520861b5040a532baca975cc467821ece28218af4e603
                                                                        • Instruction ID: 95c198be002421b953a67a14729557615c499be83b7382621c88e420121c1035
                                                                        • Opcode Fuzzy Hash: 85342b8448b5f83962e520861b5040a532baca975cc467821ece28218af4e603
                                                                        • Instruction Fuzzy Hash: 5F11B261A28B9181DA108B29A4041AD6361EB45FF4F544331EB7D877DEEF7CE8518700
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task$std::bad_alloc::bad_alloc
                                                                        • String ID:
                                                                        • API String ID: 1173176844-0
                                                                        • Opcode ID: ad7fb39d7d0572768195cdb96d88edf57c93c5d00d8eaa663e4c704e5b7bea2c
                                                                        • Instruction ID: 98f0043f35e3fe5ffa1826aa78cad4059ec4a3336316390c8129164171a73ab3
                                                                        • Opcode Fuzzy Hash: ad7fb39d7d0572768195cdb96d88edf57c93c5d00d8eaa663e4c704e5b7bea2c
                                                                        • Instruction Fuzzy Hash: 96E09201E2932B05F96AA1AA19150F510400F49F70E181B30DB7D883CBBF2CACA19350
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: ErrorFreeHeapLast
                                                                        • String ID:
                                                                        • API String ID: 485612231-0
                                                                        • Opcode ID: b7253a55b1276d1b57d670979138b52c86c30a15e8b70f9b8b054cc625f4c6ce
                                                                        • Instruction ID: 77acd0e343b6f9510baf92b082fa4df44a27414c9027020fb2915cdc476237eb
                                                                        • Opcode Fuzzy Hash: b7253a55b1276d1b57d670979138b52c86c30a15e8b70f9b8b054cc625f4c6ce
                                                                        • Instruction Fuzzy Hash: 5BE0EC41F2AA0692FE5877FAA8451B512925F94F40F444434DB0DC635BFD2CAC958304
                                                                        APIs
                                                                          • Part of subcall function 00007FF6B5370610: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6B5370778
                                                                          • Part of subcall function 00007FF6B5370610: _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6B5370784
                                                                        • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6B536447D
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
                                                                        • String ID:
                                                                        • API String ID: 3936042273-0
                                                                        • Opcode ID: 8b63aff671ea4424fcc8d86e58390cf3b414aa6dd3dbafb3b21bf28b59b76f5e
                                                                        • Instruction ID: 1f3c72f20aeda5741e2bfe662106f692ea529ae7deb4c96500dffc4a7d194515
                                                                        • Opcode Fuzzy Hash: 8b63aff671ea4424fcc8d86e58390cf3b414aa6dd3dbafb3b21bf28b59b76f5e
                                                                        • Instruction Fuzzy Hash: D2E15922E28B4184EB51DF69E4912ED3770FB44F98F55412ACF5D97B9AEF38D8A08340
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 3668304517-0
                                                                        • Opcode ID: 537b6f56e1df4810c213e73d318223818d58133d769faf41797cf51966d6e2cf
                                                                        • Instruction ID: 97da4208d53c1459f0fcbc9046ad77643ebcc2ce470a64a91ce6267b9bb3e56f
                                                                        • Opcode Fuzzy Hash: 537b6f56e1df4810c213e73d318223818d58133d769faf41797cf51966d6e2cf
                                                                        • Instruction Fuzzy Hash: AFB17D73619B81CADB218F29D0902EC73A1FB48B58F445636EB5D87B9AEF38D954C310
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 3668304517-0
                                                                        • Opcode ID: 7e7f4a0975ce12a370147af02dae87945938562f497badccff8603b604800ab9
                                                                        • Instruction ID: ce788a201ddd015907f39f6b58ae4f1f6047034affd00a51f2c4b50256afa5f4
                                                                        • Opcode Fuzzy Hash: 7e7f4a0975ce12a370147af02dae87945938562f497badccff8603b604800ab9
                                                                        • Instruction Fuzzy Hash: 3851D512F18A818AFB168F7CD4003FC7371AF54B48F045A21DF8D66B9AEF39A9918344
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo
                                                                        • String ID:
                                                                        • API String ID: 3215553584-0
                                                                        • Opcode ID: 506399ceb7efd258d9ee9312528a7fb0108d3bcc24f039aa6e7519c78468f3b6
                                                                        • Instruction ID: fc396ab5890b90fce10ab642a8e07bfd8cd8e2f3aa761d2b216e91d85f667c91
                                                                        • Opcode Fuzzy Hash: 506399ceb7efd258d9ee9312528a7fb0108d3bcc24f039aa6e7519c78468f3b6
                                                                        • Instruction Fuzzy Hash: B641B232A28A4587FB64AB1CE5412B977A0EB56F90F140531D79EC779AEF3CE802C750
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 3668304517-0
                                                                        • Opcode ID: af219e07592d3e4ddcb2aa59d6567795c060df3c327f1d120c968fde123da8b2
                                                                        • Instruction ID: 53ddbb1634391ea304aa8946c9ea71285ab0a5048036513d3366916e98c32e0e
                                                                        • Opcode Fuzzy Hash: af219e07592d3e4ddcb2aa59d6567795c060df3c327f1d120c968fde123da8b2
                                                                        • Instruction Fuzzy Hash: D1412872B25B488EEB408FB9D4413EC73B1E74CB98F005625EF9C66B89EE3495648394
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo
                                                                        • String ID:
                                                                        • API String ID: 3215553584-0
                                                                        • Opcode ID: a24f7c79d48368e33d7deb9d4eeecb52ce7ec7a6106812cc151fd4020b53ad0d
                                                                        • Instruction ID: 4c94f7049c1f37d6bd71312b1529c4b23648999c0e737635a27529f122c9bf48
                                                                        • Opcode Fuzzy Hash: a24f7c79d48368e33d7deb9d4eeecb52ce7ec7a6106812cc151fd4020b53ad0d
                                                                        • Instruction Fuzzy Hash: BA31A422A28B6285FA52BB5D94013FC2650AB84FA0F424135EB5D873DBEF7CEC41C754
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 3668304517-0
                                                                        • Opcode ID: b4325394841097dc207bbc729bbf94e901fe83a4d13f313c93b63ae7a0871957
                                                                        • Instruction ID: 5c8308a173321c07e1256362dfda7845f0c95eead6c16a89b02ae3041efeaeeb
                                                                        • Opcode Fuzzy Hash: b4325394841097dc207bbc729bbf94e901fe83a4d13f313c93b63ae7a0871957
                                                                        • Instruction Fuzzy Hash: 70312576B1AB4982EF198F69D4902AC3361EB88F88B458436DF4D47369EF3CD891C340
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: HandleModule$AddressFreeLibraryProc
                                                                        • String ID:
                                                                        • API String ID: 3947729631-0
                                                                        • Opcode ID: 9e03c0276b42d0bae273c9ceb8b8abd1e24865752fa8da44abca3c0ffcb1668a
                                                                        • Instruction ID: 7169d0cc6c39d77393e24f818a0f59660fae9ddf4952123bf32700a99af945a1
                                                                        • Opcode Fuzzy Hash: 9e03c0276b42d0bae273c9ceb8b8abd1e24865752fa8da44abca3c0ffcb1668a
                                                                        • Instruction Fuzzy Hash: 67217F32E247558AEBA4AF68C4443EC37A0EB44B1DF540635E75D86BDAEF38D884C750
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo
                                                                        • String ID:
                                                                        • API String ID: 3215553584-0
                                                                        • Opcode ID: 277766cc613ac521deff1262cc5973a4c6dda0ce244441028124d0478fb53980
                                                                        • Instruction ID: 4aeb3e3706d3715751072f692ac596c173a8abee7f1061ce6cab894e0fbc43b1
                                                                        • Opcode Fuzzy Hash: 277766cc613ac521deff1262cc5973a4c6dda0ce244441028124d0478fb53980
                                                                        • Instruction Fuzzy Hash: 46113B22A29A4181EA60AF19D4002FEB671BF89F80F444431EB8D9B7DBEE3DDD009740
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo
                                                                        • String ID:
                                                                        • API String ID: 3215553584-0
                                                                        • Opcode ID: 4bdd7c7df9abbb715da046ae302baf4d590079e7e30464498c50f0bf6b7ea38d
                                                                        • Instruction ID: 8722883fec0f69418a61a5058bc69118fcfda527461dc509363c2ec7d7e3997e
                                                                        • Opcode Fuzzy Hash: 4bdd7c7df9abbb715da046ae302baf4d590079e7e30464498c50f0bf6b7ea38d
                                                                        • Instruction Fuzzy Hash: 54213032628AC187DB619F18D4807B9B6A4EB85F94F544234E75D877DAEF3DD9108B00
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 3668304517-0
                                                                        • Opcode ID: c98089154d41e91aef4fb596ab2a74aafa6efc439ad7e522330d1ce16319ce63
                                                                        • Instruction ID: 78898328022e9f469e7edc543ca9a9471a9dfb0669d42e66f1be88409ed3c3bc
                                                                        • Opcode Fuzzy Hash: c98089154d41e91aef4fb596ab2a74aafa6efc439ad7e522330d1ce16319ce63
                                                                        • Instruction Fuzzy Hash: 3AF0C2A2B25BC540EF159B6CE0043AC6351AB44F88F540031C78C4A7ABEF7FD895C340
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 3668304517-0
                                                                        • Opcode ID: c574df8fe4f5f00ffea31855a7c07f7e09cae9b3bda18de6976169ed6b791a31
                                                                        • Instruction ID: c4039f62075e6679d7b8672ee3ae70e07f89969a763cf37e3ae995c9e6ceab7e
                                                                        • Opcode Fuzzy Hash: c574df8fe4f5f00ffea31855a7c07f7e09cae9b3bda18de6976169ed6b791a31
                                                                        • Instruction Fuzzy Hash: BBF0B4A2B2868180FF04DB2CD0053AC63A1EB48F88F540831DB4C8675AEF7DCC948340
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: send
                                                                        • String ID:
                                                                        • API String ID: 2809346765-0
                                                                        • Opcode ID: 10723b900c3d3fb221c2729e0f2ab508e71a113b43aaaf7fd55bda6ca2804ccb
                                                                        • Instruction ID: f1be82951a4c2b827000c6bc1d164676b865bdceea1c7f96aef426c73e3d921e
                                                                        • Opcode Fuzzy Hash: 10723b900c3d3fb221c2729e0f2ab508e71a113b43aaaf7fd55bda6ca2804ccb
                                                                        • Instruction Fuzzy Hash: 3401A225B28A8585DF508F1AB940569A7A0FB88FD4F485130EF5D43B4EEF28D8418700
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: FileFindNext
                                                                        • String ID:
                                                                        • API String ID: 2029273394-0
                                                                        • Opcode ID: 61598aa622094b9ec1bb0f92b50d03696b3dc6fab078c114e82ad6d4659b4b0f
                                                                        • Instruction ID: 5e5f41cae21134ace95806ea58429fdd178ff5fb7ce4088bd50d1136a08dbc45
                                                                        • Opcode Fuzzy Hash: 61598aa622094b9ec1bb0f92b50d03696b3dc6fab078c114e82ad6d4659b4b0f
                                                                        • Instruction Fuzzy Hash: DF01F42661CA8185EA71CB56F4542AA7364F788FD4F444032DF8D83B5DEE3DD886CB00
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo
                                                                        • String ID:
                                                                        • API String ID: 3215553584-0
                                                                        • Opcode ID: 68ea0e6e30933e9dd76abf56f21314c638998a57c534cc3687c594a1fb5b02e7
                                                                        • Instruction ID: 6a64893a0c5b203e0d64f5c27c255e60423edfab8d6eddc0df8ff887007f6cb5
                                                                        • Opcode Fuzzy Hash: 68ea0e6e30933e9dd76abf56f21314c638998a57c534cc3687c594a1fb5b02e7
                                                                        • Instruction Fuzzy Hash: 85E06D31A39E4285EFA57AAD91411BC6160AF44FB0F544331EB3C863CBEE7898508710
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: FileFindNext
                                                                        • String ID:
                                                                        • API String ID: 2029273394-0
                                                                        • Opcode ID: 4104833be8186ecfced91f05a1dc286f8d4e1ac7fad94ea37a2bf5d234dce428
                                                                        • Instruction ID: 65710359fd191957f65bde900094b122634567aa5bc43b74b600f149a854e9f3
                                                                        • Opcode Fuzzy Hash: 4104833be8186ecfced91f05a1dc286f8d4e1ac7fad94ea37a2bf5d234dce428
                                                                        • Instruction Fuzzy Hash: ABC04C15F6E642D1EA541B6B5C821A211E05B54B51F450030C708C0355FD5CA9E68B11
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: InfoNativeSystem
                                                                        • String ID:
                                                                        • API String ID: 1721193555-0
                                                                        • Opcode ID: ebb3c2d15c06801dfe805b6087078b0f501a5fe9f8c446694f4975735c5f9cad
                                                                        • Instruction ID: 7356d89832a43736e94eb09809cd29f76b560c9b11bf4c031ce5df6ace615c13
                                                                        • Opcode Fuzzy Hash: ebb3c2d15c06801dfe805b6087078b0f501a5fe9f8c446694f4975735c5f9cad
                                                                        • Instruction Fuzzy Hash: 8DB09236A289C0D3C611EB08E8420597331FB94B0AFD00020E38E82729DE2CDA2A8F00
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: AllocHeap
                                                                        • String ID:
                                                                        • API String ID: 4292702814-0
                                                                        • Opcode ID: eba47d0c810211a009f984e3ce810decee2d7cb9fb39a7e87e15bbee8ef19542
                                                                        • Instruction ID: 41433fc058fd3b6de298de2c0ae07f22a7189e1d1fec5e8e5efa118ea0287962
                                                                        • Opcode Fuzzy Hash: eba47d0c810211a009f984e3ce810decee2d7cb9fb39a7e87e15bbee8ef19542
                                                                        • Instruction Fuzzy Hash: 4AF03A01B29A0A54FE94766D58106F522805F88F61F490330DA2EC53CBEE2CBC84A321
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                                                        • String ID: cannot compare iterators of different containers$cannot use push_back() with $type must be string, but is $value
                                                                        • API String ID: 73155330-2711811579
                                                                        • Opcode ID: d187969b3f8adc0d7d83df29c316cce47e6f364642cfc6bf6309e0d85370cb42
                                                                        • Instruction ID: c0a9ecd155697250c52af2c9542e9f77a48a20752e8d13b665fc9135c68e28cc
                                                                        • Opcode Fuzzy Hash: d187969b3f8adc0d7d83df29c316cce47e6f364642cfc6bf6309e0d85370cb42
                                                                        • Instruction Fuzzy Hash: AB535E62A14BC589DB719F28D8803ED23A4FB45B58F405635DB5D9BB9EEF38DA84C300
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: memcpy_s$_invalid_parameter_noinfo
                                                                        • String ID: $
                                                                        • API String ID: 2880407647-227171996
                                                                        • Opcode ID: 49a4e64996860ac975e7d62cf44a3f3077f64a100a8fbd3398d3c45755aa41bf
                                                                        • Instruction ID: 6a14060a66e250abd743b39cd5c8af1a09e0eec17520f3273bc5901e418aa95d
                                                                        • Opcode Fuzzy Hash: 49a4e64996860ac975e7d62cf44a3f3077f64a100a8fbd3398d3c45755aa41bf
                                                                        • Instruction Fuzzy Hash: 0803B672A24AC14BE7759E29D9807F97791FB44B88F005135EB0A97B4DEF39AE01CB40
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: lstrcpy$lstrcat$AllocateInitLockMemoryObjectStringUnicodeVirtual$AcquireEnumerateFolderFreeInitializeKnownLoadedModulesPathReleaseTaskUninitialize_invalid_parameter_noinfo_noreturn
                                                                        • String ID: 0
                                                                        • API String ID: 2979746431-4108050209
                                                                        • Opcode ID: be3c9c5b6b29e4456c2bc1c511291065cd00b5f8cb3857b0f644a8fdea2a94a5
                                                                        • Instruction ID: f25fefd74df0184a3917214e0cb06d383339ab4d6e87cf1d8d4b8f6f0c774644
                                                                        • Opcode Fuzzy Hash: be3c9c5b6b29e4456c2bc1c511291065cd00b5f8cb3857b0f644a8fdea2a94a5
                                                                        • Instruction Fuzzy Hash: 59C2B936626F988AD7908F69E88169DB3B5F788B88B105225FFCD57B18EF38C154C740
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID: config$content$filename$status$users
                                                                        • API String ID: 3668304517-2677590375
                                                                        • Opcode ID: 5961c5f104c8461b027db5d1534595f1a469070d5504b5e383ec641362e7a33b
                                                                        • Instruction ID: 6bb6d851b2f93a3c521ef6052af09ccfdf2b65da46c1dd565af9382bf42f96da
                                                                        • Opcode Fuzzy Hash: 5961c5f104c8461b027db5d1534595f1a469070d5504b5e383ec641362e7a33b
                                                                        • Instruction Fuzzy Hash: 82C25162A15BC285DB319F38D8903ED6361FB45B98F405236DB5D8AB9EEF38DA44C340
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$ExecuteShell
                                                                        • String ID: .cmd$.exe$.exe$.ps1$.vbs$abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+=-&^%$#@!(){}[},.;'$ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set$open$runas
                                                                        • API String ID: 4120902618-4093014531
                                                                        • Opcode ID: 7479964b09d7e937c2731e9b908c03d085839642c0324ba9434fc91e233fbea9
                                                                        • Instruction ID: e946c94696a2b3bcadad6637ef20d2dc23241d7dfecf5f9bb4cb34e1a7448c68
                                                                        • Opcode Fuzzy Hash: 7479964b09d7e937c2731e9b908c03d085839642c0324ba9434fc91e233fbea9
                                                                        • Instruction Fuzzy Hash: F7228272A28B8585EB10DF28D4403ED67A1FB44B98F505235EB5D87BAEEF78D984C340
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID: Software$exists
                                                                        • API String ID: 0-2364128853
                                                                        • Opcode ID: 754b6d5de3f8b423738aca6b75d482b608bbcfa6901d960764bf722898531e8f
                                                                        • Instruction ID: 0bb8a9636c4fc27dfb65532488828c738ef16340bf70496616e416c0d5aa2bf4
                                                                        • Opcode Fuzzy Hash: 754b6d5de3f8b423738aca6b75d482b608bbcfa6901d960764bf722898531e8f
                                                                        • Instruction Fuzzy Hash: 6BD28073A15BC589EB518F29E8403ED7360FB89B94F105225EB9D57B9AEF78D980C300
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                                                        • String ID: BOOTNXT$autorun.inf$boot.ini$boot.sdi$bootfont.bin$bootmgfw.efi$bootmgr$bootsect.bak$bootstat.dat$d3d9caps.dat$desktop.ini$gdipfontcachev1.dat$iconcache.db$indexervolumeguid$mib.bin$ntldr$ntuser.dat$ntuser.dat.log$ntuser.ini$reagent.xml$thumbs.db$winre.wim$winsipolicy.p7b$wpsettings.dat
                                                                        • API String ID: 73155330-850610325
                                                                        • Opcode ID: 22dcfd16a23274500c0631d97ecb7b22965bfb45e38d580db89ddce6ecc7947a
                                                                        • Instruction ID: e071c5e9f7a4c3830d3604c89b5c1f88bc2a928f34921db8072d94113c466eaf
                                                                        • Opcode Fuzzy Hash: 22dcfd16a23274500c0631d97ecb7b22965bfb45e38d580db89ddce6ecc7947a
                                                                        • Instruction Fuzzy Hash: 43C1A452D34BCA45E721DB38D8813F55361FBEA744F506736EA88A586BEF68A7C0C340
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                                                        • String ID: #recycle$$recycle.bin$$windows.~bt$$windows.~ws$$winreagent$All users$AppData$Application Data$Boot$PerfLogs$Program Files$Program Files (x86)$ProgramData$System Volume Information$Windows$Windows.old$Windows.~bt$bootmgr$config.msi$ntldr
                                                                        • API String ID: 73155330-2722463023
                                                                        • Opcode ID: 7d392a795bfbfd6594683dd8fb9872c8abf8b0b593989480866b32def73f354a
                                                                        • Instruction ID: 4e903e01649d8fd4b79490d11604f9cb6a0271d3f33802d1c58c6801300ff0d4
                                                                        • Opcode Fuzzy Hash: 7d392a795bfbfd6594683dd8fb9872c8abf8b0b593989480866b32def73f354a
                                                                        • Instruction Fuzzy Hash: 05A1A452D34BCA45E721DB38D8813F55361FBEA744F506736EA8CA685BEF68A6C4C300
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Initialize_invalid_parameter_noinfo_noreturn
                                                                        • String ID: @
                                                                        • API String ID: 3490963316-2766056989
                                                                        • Opcode ID: 340411d1fce1f4d2458475e6b7cafb7ea6d02391b27961439f40ad3dfb835a2a
                                                                        • Instruction ID: 648f9c254d624bbfc7af8ea6cc41e3e9d1ae8920287f4713d8de9db20ac74f2a
                                                                        • Opcode Fuzzy Hash: 340411d1fce1f4d2458475e6b7cafb7ea6d02391b27961439f40ad3dfb835a2a
                                                                        • Instruction Fuzzy Hash: 61A16C72B28B418AE720CB69E4446AD7761FB88B48F044235DF5E93B9AEF38D954C344
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$__std_fs_convert_wide_to_narrow$__std_fs_code_page
                                                                        • String ID: content$directory_iterator::directory_iterator$exists$filename$status
                                                                        • API String ID: 2212124024-3429737954
                                                                        • Opcode ID: 4a5c084437b6e505fe191a25d1ddd3fa9523bf8bbcd3d4d616036c48336d69b0
                                                                        • Instruction ID: b5db463594c9eb9f33083576f24b42bcf1e942b6401ed7ed361aff513d527608
                                                                        • Opcode Fuzzy Hash: 4a5c084437b6e505fe191a25d1ddd3fa9523bf8bbcd3d4d616036c48336d69b0
                                                                        • Instruction Fuzzy Hash: 3B728332A15BC185EB219F38D8903ED6360FB89B94F445635DB8D87B9AEF78DA44C340
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_destroy
                                                                        • String ID: value
                                                                        • API String ID: 1346393832-494360628
                                                                        • Opcode ID: 58ac9e99c7e9caeb46c8d6d8eb90e0f66bb103b216faee546cb3e1aa741f4388
                                                                        • Instruction ID: a1a4f2e6d81195f76f18ea8649856a7581a220bad53ff81a2a2004ebcc630c25
                                                                        • Opcode Fuzzy Hash: 58ac9e99c7e9caeb46c8d6d8eb90e0f66bb103b216faee546cb3e1aa741f4388
                                                                        • Instruction Fuzzy Hash: 8602A562A29BC185EB41CB78D4403ED6761EB85BA4F105235EB9E86BDFEF2CD584C700
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo
                                                                        • String ID: s$s$W$
                                                                        • API String ID: 3215553584-4165748295
                                                                        • Opcode ID: 9b1f272bfafe38334aa377421cf6210804c5f9af34e63209d09ff03d43a97708
                                                                        • Instruction ID: 393bbec6fa48c569f1d13cb05740e3e7354b5cf596b24406e7ea354bc5bd5469
                                                                        • Opcode Fuzzy Hash: 9b1f272bfafe38334aa377421cf6210804c5f9af34e63209d09ff03d43a97708
                                                                        • Instruction Fuzzy Hash: 73A2C572A283A28BE7658E68D4507FD77A1FB44B48F445135DB09D7B8AEF38AD40CB40
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: lstrcatlstrcpy$Object$AcquireAllocateInitializeLockMemoryUninitializeVirtual
                                                                        • String ID: 0
                                                                        • API String ID: 3636535045-4108050209
                                                                        • Opcode ID: 256d7544adc4c5c9ea952a558105b7fb008bcdf57b8585116dd0ba0e073c8c51
                                                                        • Instruction ID: ad73b9384e652e5115312f1978b7d3104caab8805c24cbdef4c34e6132ee3e27
                                                                        • Opcode Fuzzy Hash: 256d7544adc4c5c9ea952a558105b7fb008bcdf57b8585116dd0ba0e073c8c51
                                                                        • Instruction Fuzzy Hash: 8AB2893662AF988AD7808F69E88155EB3B5F788B88B106215FFCD57B18EF38C154C740
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Crypt$_invalid_parameter_noinfo_noreturn$AlgorithmConcurrency::cancel_current_taskGenerateOpenPropertyProviderSymmetric
                                                                        • String ID: AES$ChainingMode$ChainingModeGCM
                                                                        • API String ID: 2556340343-1213888626
                                                                        • Opcode ID: 4d2ae9936c16117bf66a9a82cdf8c67db15cfebaaeeafde8e0b7fccba3920ac7
                                                                        • Instruction ID: 5183ec67d04ab5b304b556764fcdbee7028b141b1b1887e89114828f81ae80b9
                                                                        • Opcode Fuzzy Hash: 4d2ae9936c16117bf66a9a82cdf8c67db15cfebaaeeafde8e0b7fccba3920ac7
                                                                        • Instruction Fuzzy Hash: 2E61C562A2878545FB249B29E4403E9A360EB84FD4F144631EF5D8BBDBEF3CD9918300
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID: ZPTcrQssPSx9WOSFMOMK+XoqcG1eYI9iRKFdlGnQ0T0=$pfHPZt1s0Dk=$port
                                                                        • API String ID: 0-2592750929
                                                                        • Opcode ID: fe16ae3c725d1eb1c5c11142da1a117778a9c063c3c2cd6928c6efc9df6e0444
                                                                        • Instruction ID: 38c0c78cc270806ea28b9d82e6fa8f9bc193611518ee994d6f46295cd1179a47
                                                                        • Opcode Fuzzy Hash: fe16ae3c725d1eb1c5c11142da1a117778a9c063c3c2cd6928c6efc9df6e0444
                                                                        • Instruction Fuzzy Hash: E27272B2A29BC581D661CB29E4403EAB3A4FB99784F105225EBCD53B5EEF3CD591C700
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Value$Locale$CodeErrorInfoLastPageValid$DefaultEnumLocalesProcessSystemUser
                                                                        • String ID:
                                                                        • API String ID: 2591520935-0
                                                                        • Opcode ID: 35311c5f5cbb088db9cafc063da405a92d1dac0a49a1e36eea51d3b328654a2c
                                                                        • Instruction ID: d689584d1b8d84ab544b4b186ac2ef3bda5065573b97d36a2fe4a763267c379d
                                                                        • Opcode Fuzzy Hash: 35311c5f5cbb088db9cafc063da405a92d1dac0a49a1e36eea51d3b328654a2c
                                                                        • Instruction Fuzzy Hash: FD714723B2972689EB519B68D8606F823A4AB48F44F454435CB1DD378AFF3CF845CB50
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                        • String ID:
                                                                        • API String ID: 3140674995-0
                                                                        • Opcode ID: 6458172863af31e20951f5f8dc1d486a5fb90de472876968ccfd77d10a4e7fe6
                                                                        • Instruction ID: 29bc58f3ccc6769521e56f0e15a0c702aa174886d97b757952a11d208755baff
                                                                        • Opcode Fuzzy Hash: 6458172863af31e20951f5f8dc1d486a5fb90de472876968ccfd77d10a4e7fe6
                                                                        • Instruction Fuzzy Hash: D5315276619B8196EB608F64E8403ED7364FB84B48F44413ADB4E87B9AEF3CD948C714
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$ExecuteFileModuleNameShell
                                                                        • String ID:
                                                                        • API String ID: 3435646932-0
                                                                        • Opcode ID: a7338904e57405cb7424316b332a1e38ca99d4c22208ccb12818e04892214995
                                                                        • Instruction ID: 29de8114afd1b0a0d1f9697980c75c53a96220fb26aa5b5cb7463b296d73baee
                                                                        • Opcode Fuzzy Hash: a7338904e57405cb7424316b332a1e38ca99d4c22208ccb12818e04892214995
                                                                        • Instruction Fuzzy Hash: 26122B72A29F848ADB408F29E88169EB3A4F788B94F505225EFDD57B59EF38D150C700
                                                                        APIs
                                                                        Strings
                                                                        • ERROR : Unable to initialize critical section in CAtlBaseModule, xrefs: 00007FF6B53DD887
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: DebugDebuggerErrorLastOutputPresentString
                                                                        • String ID: ERROR : Unable to initialize critical section in CAtlBaseModule
                                                                        • API String ID: 389471666-631824599
                                                                        • Opcode ID: 9ee4415ca50324c33a3d5a57874f9cc99ad178eb9645fb895110d63af1d9e2c1
                                                                        • Instruction ID: c42ec0bce11a8d20d2672718d6cc2ad8e54c48ebedbda487944e640728f1c24c
                                                                        • Opcode Fuzzy Hash: 9ee4415ca50324c33a3d5a57874f9cc99ad178eb9645fb895110d63af1d9e2c1
                                                                        • Instruction Fuzzy Hash: E6113D32A24B42A6F7159B2AD6443F932A4FB44B45F404535C74DC3A9AFF7CE864C750
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo
                                                                        • String ID: 1#IND$1#INF$1#QNAN$1#SNAN$W$
                                                                        • API String ID: 3215553584-4287779413
                                                                        • Opcode ID: e914ef83dae64b72f50003c00f300a4745ddd1fbbdf1c541f482026cce5ebf66
                                                                        • Instruction ID: 1b29d6b3927aebb7a2decaaa237e58af0b6a7b8f090a820626459eca46fad30a
                                                                        • Opcode Fuzzy Hash: e914ef83dae64b72f50003c00f300a4745ddd1fbbdf1c541f482026cce5ebf66
                                                                        • Instruction Fuzzy Hash: 9971DF72E383664BE7608B6C94447F97291AB94B94F444635DB1DDABCAEF3CED408B00
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                        • String ID:
                                                                        • API String ID: 2933794660-0
                                                                        • Opcode ID: 4ffc0ff1ccd2cf120a16052376350404e0c91ed7b37e0d63ec5629fc76b72274
                                                                        • Instruction ID: 98ee56f73bf5a8efe3ea88392d958f286a054e251f682ed490f4aa8bbe864c37
                                                                        • Opcode Fuzzy Hash: 4ffc0ff1ccd2cf120a16052376350404e0c91ed7b37e0d63ec5629fc76b72274
                                                                        • Instruction Fuzzy Hash: 92113C26B24F028AEB00CF64E8542F833B4FB19B59F441E31DB6D867A9EF78D5648340
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _get_daylight$_invalid_parameter_noinfo
                                                                        • String ID:
                                                                        • API String ID: 1286766494-0
                                                                        • Opcode ID: 91154ea289c3556cf103cf6e37fc2ba0624cd5322ab1aec8ddf48183395d8b30
                                                                        • Instruction ID: 159d164ba0ec37ee1f057803e4f93c609d295efa494d2346f66a21e901fff19f
                                                                        • Opcode Fuzzy Hash: 91154ea289c3556cf103cf6e37fc2ba0624cd5322ab1aec8ddf48183395d8b30
                                                                        • Instruction Fuzzy Hash: 3592AE32A2C7A286EB649F2895502B937A5FB45B84F148135DB8D87B9EEF3DDD14C300
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: FormatInfoLocaleMessage
                                                                        • String ID: !x-sys-default-locale
                                                                        • API String ID: 4235545615-2729719199
                                                                        • Opcode ID: e9313e5009c165bfc27bb14f9f63cf4f23352891cc12b2974ad7925588fd8796
                                                                        • Instruction ID: bbbb2e89f60658662c95ebfe500299d12b993e88ccb3eee3bc22ea6a0fc98707
                                                                        • Opcode Fuzzy Hash: e9313e5009c165bfc27bb14f9f63cf4f23352891cc12b2974ad7925588fd8796
                                                                        • Instruction Fuzzy Hash: 9B018472B6878282E7118B1AB4547FA67A1F788B84F444035DB5987B9EDF3CD905CB00
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: memcpy_s
                                                                        • String ID:
                                                                        • API String ID: 1502251526-0
                                                                        • Opcode ID: eb07a1fe8bff8429000d82fc6708e1dd14e73367c47fa60bb37c8b50ad77a0f3
                                                                        • Instruction ID: 003d828990a3a83ae6048ebd4b34edf86b2af549b05658479451fa0f43c8a248
                                                                        • Opcode Fuzzy Hash: eb07a1fe8bff8429000d82fc6708e1dd14e73367c47fa60bb37c8b50ad77a0f3
                                                                        • Instruction Fuzzy Hash: C0C1E472B28A9587DB24DF1DA0446AAB791F784B84F448135DB4A87749EF3CED01CB00
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: DevicesDisplayEnum$_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 2655931952-0
                                                                        • Opcode ID: 94d2f9f446da62c2dc3d2d668c805b77a80d9ba8f9fb19c76c5bed2a069963bc
                                                                        • Instruction ID: ec22f79aa0eedce99b4128849c762f0f58d4fb03016ad73a71507f661c35b671
                                                                        • Opcode Fuzzy Hash: 94d2f9f446da62c2dc3d2d668c805b77a80d9ba8f9fb19c76c5bed2a069963bc
                                                                        • Instruction Fuzzy Hash: EE81D332A28B8586E711CF25E4443AE77A4F788B88F505225EF9C57B99EF3CD581C700
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID: invalid distance code$invalid distance too far back$invalid literal/length code
                                                                        • API String ID: 0-3255898291
                                                                        • Opcode ID: 6ea04a2f93dd3dc6463ff6e9b99ea612e1d6b379f2849f0432d7824071fe6352
                                                                        • Instruction ID: 75eeb174155e53a3cc85367c264d97fca08eb71769cb53cae6bf49ab619a686b
                                                                        • Opcode Fuzzy Hash: 6ea04a2f93dd3dc6463ff6e9b99ea612e1d6b379f2849f0432d7824071fe6352
                                                                        • Instruction Fuzzy Hash: 1BF11572B286D583DB588F2990447BD7BA2E784B84F048139EB9E437C9EE7CD804CB40
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: ExceptionRaise_clrfp
                                                                        • String ID:
                                                                        • API String ID: 15204871-0
                                                                        • Opcode ID: 7fa2203b5ce5cf4252278981a869295bf258e597fb1a3e488d01a74adacce12a
                                                                        • Instruction ID: 8488fe1da8b1b52aaf71ef6d239088d569aa07973f83042d4057df8a58223d8a
                                                                        • Opcode Fuzzy Hash: 7fa2203b5ce5cf4252278981a869295bf258e597fb1a3e488d01a74adacce12a
                                                                        • Instruction Fuzzy Hash: 8BB15A73A24B988AEB15CF2DC8463A87BA0F744F48F198921DB5D837A9DF39D851D700
                                                                        APIs
                                                                        • CryptProtectData.CRYPT32(?,?,?,?,?,?,?,?,1E5E0F68EF71A387,00007FF6B5397E98), ref: 00007FF6B5397F18
                                                                        • LocalFree.KERNEL32(?,?,?,?,?,?,?,?,1E5E0F68EF71A387,00007FF6B5397E98), ref: 00007FF6B5397FAA
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: CryptDataFreeLocalProtect
                                                                        • String ID:
                                                                        • API String ID: 2714945720-0
                                                                        • Opcode ID: a2378fc87af65e51448867ee86bab5adaeca8e4500ced070fe446fae58ae31d0
                                                                        • Instruction ID: e98f70a8aa52d616d9896c7c62c3b437d3092fd2513bcb65b39ea8bf0bca90c4
                                                                        • Opcode Fuzzy Hash: a2378fc87af65e51448867ee86bab5adaeca8e4500ced070fe446fae58ae31d0
                                                                        • Instruction Fuzzy Hash: 65414B32A28B81CAE3208F34D4403ED37A4FB59B8CF444235EB8D56E8AEF79D5648354
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: AlgorithmCloseCryptProvider_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 1900905105-0
                                                                        • Opcode ID: d48272242ff38cb51ff281d933a05202fbbbe6e34663287e7ca53ddf03012e02
                                                                        • Instruction ID: 4564de6ac2aeb1db782d32d980aef8733892707d655503f071f0cd9e453f270d
                                                                        • Opcode Fuzzy Hash: d48272242ff38cb51ff281d933a05202fbbbe6e34663287e7ca53ddf03012e02
                                                                        • Instruction Fuzzy Hash: 3A0181E2A15B8541EB589B29D4443BD6351EF98F88F944431DB4D4A78BEF7DC8948340
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID: a/p$am/pm
                                                                        • API String ID: 0-3206640213
                                                                        • Opcode ID: d4351435efb39c397654aac4863534f6b364d586ca34e5132229a126b3ed6b80
                                                                        • Instruction ID: e633d87172b0ba3b7d8f19cce2c3cbf7d146cc8218271f44a522947e2df655ee
                                                                        • Opcode Fuzzy Hash: d4351435efb39c397654aac4863534f6b364d586ca34e5132229a126b3ed6b80
                                                                        • Instruction Fuzzy Hash: E1E1AF22A2876285E7A4AF1995547F822A0FF55B86F544132EB4D8778EFF3EED40C300
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: 068306ddd40209d889ad2deda50cfd289cb5f07b5063c8971a8727913c04ec65
                                                                        • Instruction ID: 554cfbce90bcf3328fa3a4f0df792891c645a96e56311ebfc527bafce430248d
                                                                        • Opcode Fuzzy Hash: 068306ddd40209d889ad2deda50cfd289cb5f07b5063c8971a8727913c04ec65
                                                                        • Instruction Fuzzy Hash: 0FE19032A18B9586E720DB65E4406EE37A0F794B88F404A35DF9D93B5BEF78E645C300
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task
                                                                        • String ID:
                                                                        • API String ID: 118556049-0
                                                                        • Opcode ID: e15d2f162ff1955ab864f6985266ecf3f2bc5c0452e497727127c975e7191d30
                                                                        • Instruction ID: 03a0384e2ae9869010829cdc7614142ce99d1e6084de9f75fc9a8300c396ed79
                                                                        • Opcode Fuzzy Hash: e15d2f162ff1955ab864f6985266ecf3f2bc5c0452e497727127c975e7191d30
                                                                        • Instruction Fuzzy Hash: CDA17922A29B99C9EB00CB69D4903EC3BB0F759B48F544426DF8D97B5AEF38D491C350
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task
                                                                        • String ID:
                                                                        • API String ID: 118556049-0
                                                                        • Opcode ID: a9167eaa65478a799c7f3ec9e29dde26aa86ec3791fbfc1cbc06c4d1a3e3b434
                                                                        • Instruction ID: cbcd2f97c9b155531bdd0820b2490be905d5dd1a960547b9ba581726f95da652
                                                                        • Opcode Fuzzy Hash: a9167eaa65478a799c7f3ec9e29dde26aa86ec3791fbfc1cbc06c4d1a3e3b434
                                                                        • Instruction Fuzzy Hash: 4AA18B22A29B99C9EB00CBA9D4903EC37B0F759B48F544126DF8D97B5AEF38D491C300
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task
                                                                        • String ID:
                                                                        • API String ID: 118556049-0
                                                                        • Opcode ID: 1a0b0a27a47120f0dd3118ebd9992b9d6fd92610f51e4eb7e5d0b138f3b139a1
                                                                        • Instruction ID: c936f84bd209b8a657e08bf41119422c24a50338ad01f6b9d97c806687bcab6b
                                                                        • Opcode Fuzzy Hash: 1a0b0a27a47120f0dd3118ebd9992b9d6fd92610f51e4eb7e5d0b138f3b139a1
                                                                        • Instruction Fuzzy Hash: 3EA16B62A29B99C9EB008B69D4903EC67B0FB59B48F544426CF8D97B5AEF3CD491C310
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task
                                                                        • String ID:
                                                                        • API String ID: 118556049-0
                                                                        • Opcode ID: 19b8e35a52236dea822ac287a77672b763b92d4e180ebbf92390928410f80ccd
                                                                        • Instruction ID: e8c9656ceaed20f8310c9df37fe19d0e2eb4bba84229bf18311226bac76c9e6e
                                                                        • Opcode Fuzzy Hash: 19b8e35a52236dea822ac287a77672b763b92d4e180ebbf92390928410f80ccd
                                                                        • Instruction Fuzzy Hash: 76A18B62A29B99C9EB01CB69D4803EC37B0F759B48F584426CF8D97B5AEF38D491C300
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: ErrorLastValue$InfoLocale
                                                                        • String ID:
                                                                        • API String ID: 673564084-0
                                                                        • Opcode ID: d3f265d93177da05e9e3079d3dae9c7822de4fa7ba26229b0f968e85ede82faf
                                                                        • Instruction ID: 7394674af4cb4cc63fa37fc78a79e29bf2422dda5adb05cedb94edbd4839ecd0
                                                                        • Opcode Fuzzy Hash: d3f265d93177da05e9e3079d3dae9c7822de4fa7ba26229b0f968e85ede82faf
                                                                        • Instruction Fuzzy Hash: F7314432A2878686EB649B69D4613E973A1FB44F84F418135DB4DC378AEF3DF8118B00
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID: QN
                                                                        • API String ID: 0-3349929942
                                                                        • Opcode ID: 2db597cf25c999939cc3b819fed71c1e326e74b4ad1904394b10da5a057d82d8
                                                                        • Instruction ID: cfd85e09ea1d043c0c951c43df0846214b500c628dd55652e886c50b3b55f33d
                                                                        • Opcode Fuzzy Hash: 2db597cf25c999939cc3b819fed71c1e326e74b4ad1904394b10da5a057d82d8
                                                                        • Instruction Fuzzy Hash: 7002D532915BC489E7628F39E8803D9B7B4F7AD788F105225EBCC66B59EF74D2908740
                                                                        APIs
                                                                          • Part of subcall function 00007FF6B53B9EEC: GetLastError.KERNEL32 ref: 00007FF6B53B9EFB
                                                                          • Part of subcall function 00007FF6B53B9EEC: FlsGetValue.KERNEL32 ref: 00007FF6B53B9F10
                                                                          • Part of subcall function 00007FF6B53B9EEC: SetLastError.KERNEL32 ref: 00007FF6B53B9F9B
                                                                        • GetLocaleInfoW.KERNEL32(?,?,?,00007FF6B53C92C2), ref: 00007FF6B53C954F
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: ErrorLast$InfoLocaleValue
                                                                        • String ID:
                                                                        • API String ID: 3796814847-0
                                                                        • Opcode ID: 8a450860209e15821de9f16c01ed0612a725223f9a4b72f88eafb3edea00904a
                                                                        • Instruction ID: 562494ec8bc7cc3de07e0acb8d73faf9b476ded37d48ba400672556eaa82375e
                                                                        • Opcode Fuzzy Hash: 8a450860209e15821de9f16c01ed0612a725223f9a4b72f88eafb3edea00904a
                                                                        • Instruction Fuzzy Hash: 71112B33F2876243E7648719A060ABE2250EB44F54F554631D72E837CAFF29EC818B00
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: BlanketCreateInstanceProxy_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 2651345351-0
                                                                        • Opcode ID: 40773d99c68af0ed28a683e1120cd973a1f3f0d295592a8dd6d360565397851e
                                                                        • Instruction ID: 6372e7064107f4d8c2fc55fc596c962941ebe8668fb83e26b0179bd957c41fc9
                                                                        • Opcode Fuzzy Hash: 40773d99c68af0ed28a683e1120cd973a1f3f0d295592a8dd6d360565397851e
                                                                        • Instruction Fuzzy Hash: 1501A262F18A4586FB22DB69E4013ED6360BB48B58F400536CF4E83B5AEF3CD595C340
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID: 0-3916222277
                                                                        • Opcode ID: d56b133698f6429a15668cf33a50c2b0452d3e907794045ce25e286071ddca93
                                                                        • Instruction ID: 6c51ec777f4b0c2cde5546cb4c29161a226efe6a7faaa7cf454ecd57d4daa739
                                                                        • Opcode Fuzzy Hash: d56b133698f6429a15668cf33a50c2b0452d3e907794045ce25e286071ddca93
                                                                        • Instruction Fuzzy Hash: 77B15E72628E8585EB649F2DC0502AD3BA4E745F48F684235CB4E8739BEF39D892C705
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: HeapProcess
                                                                        • String ID:
                                                                        • API String ID: 54951025-0
                                                                        • Opcode ID: 9736d98ff4c00b43741f239e002f48ba729bdd9c0db5a1f9682fb9dc510a38ab
                                                                        • Instruction ID: b1b484b5db7ae7fea2d6da8b2f1e7b236061c3c1b6014405bb4a9537f5362f91
                                                                        • Opcode Fuzzy Hash: 9736d98ff4c00b43741f239e002f48ba729bdd9c0db5a1f9682fb9dc510a38ab
                                                                        • Instruction Fuzzy Hash: C5B09220E27B06C6EA482B597C8225823A47F88B01F990239D20C80325EF2C28E65701
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: c60e777daeaea113d67f9bda991af49b1d649395350f0fb3635444d7023d5cec
                                                                        • Instruction ID: b5d94517e7312476d28e1afe580a24a7a9aaa89d8ce7704bc8a3abfa65708524
                                                                        • Opcode Fuzzy Hash: c60e777daeaea113d67f9bda991af49b1d649395350f0fb3635444d7023d5cec
                                                                        • Instruction Fuzzy Hash: 79A28F36615FC88AD7418FAAEC8119973B6F748BA8B101629EFCC57F19EBB4C164C740
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: 28b26b264dc319334a57f9a21a87e01f2abcb0f4ad2a21d4ccd67af80162f90e
                                                                        • Instruction ID: 03ab0271e402089f9b4f0a64de0ea7e4247f57dd22b36671cc20378880b24d26
                                                                        • Opcode Fuzzy Hash: 28b26b264dc319334a57f9a21a87e01f2abcb0f4ad2a21d4ccd67af80162f90e
                                                                        • Instruction Fuzzy Hash: 2192D632918BC88AD7718F29E8812DAB7A8F79D748F505325EBCC56B19EF38D254C704
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: ff8ff783da37649173626c7f7158936b22345755ff077d27462f74136c1878ba
                                                                        • Instruction ID: 1f6353a537f43d89c1c70b0cff8fc5222e727a72529553c60ad07293a02316a5
                                                                        • Opcode Fuzzy Hash: ff8ff783da37649173626c7f7158936b22345755ff077d27462f74136c1878ba
                                                                        • Instruction Fuzzy Hash: 5EC10023B2969587EB1ACF56D9845A9B762F7D4FD0B55C131EB4A83B88DE3CD802C700
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: bd2058f1c1a01537bbcc10525baaa4b14614c3b84cd64c01d434f607c274e743
                                                                        • Instruction ID: d1ab7f760188ee277c9e122c92fe1a5a08bb9ef0083ab6adb3926d705eb74924
                                                                        • Opcode Fuzzy Hash: bd2058f1c1a01537bbcc10525baaa4b14614c3b84cd64c01d434f607c274e743
                                                                        • Instruction Fuzzy Hash: C412C532919BC98AD7718F29E84129AB3A4F79D788F505325EBCC57B19EF38D250CB04
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: ErrorLastNameTranslate$CodePageValidValue_invalid_parameter_noinfo
                                                                        • String ID:
                                                                        • API String ID: 4023145424-0
                                                                        • Opcode ID: a2379e98abae736fe33e8b4f9fedcc0141c51f1be06055089ccb01d873b85599
                                                                        • Instruction ID: 51e6ed1ad4bd1b5a7d03b8016cf6607a28f3b166ef56c2646fae088581b6c21e
                                                                        • Opcode Fuzzy Hash: a2379e98abae736fe33e8b4f9fedcc0141c51f1be06055089ccb01d873b85599
                                                                        • Instruction Fuzzy Hash: 09C1B562A28E8645EB60AB2994103FA67A0FB94F88F444035DF8DC779EFF3CD9458700
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: f0c2dc1868310f7be340402d514fcc5ddbcaaf30b09b4b1a75e66e521b583746
                                                                        • Instruction ID: ab372a0e23b7bca5fc1bb711a45a282335389defbba6f48070a31fcbbfd82b69
                                                                        • Opcode Fuzzy Hash: f0c2dc1868310f7be340402d514fcc5ddbcaaf30b09b4b1a75e66e521b583746
                                                                        • Instruction Fuzzy Hash: 32C1B162A28A4286EB299E2DC4506BD37A0EB45F48F144235CF5DC779BEF39DC86C740
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: ErrorLast$Value_invalid_parameter_noinfo
                                                                        • String ID:
                                                                        • API String ID: 1500699246-0
                                                                        • Opcode ID: 468b93f19c7ca54f8d79ce9aecab092ca155e8bca1880fa3cbddf3014db9fedd
                                                                        • Instruction ID: 38acd0f380d4bc3ebe740ac32a32d892155765b675336dd8cf73f050d8a966f4
                                                                        • Opcode Fuzzy Hash: 468b93f19c7ca54f8d79ce9aecab092ca155e8bca1880fa3cbddf3014db9fedd
                                                                        • Instruction Fuzzy Hash: 6EB1A132A2876692EBA5DB29D4116F973A0EB44F88F404131DB59C77CEEF3CEA418740
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo
                                                                        • String ID:
                                                                        • API String ID: 3215553584-0
                                                                        • Opcode ID: 65cb0e03891be60b6b6053fa39e45d28bcdd28ebeeb85bb53b847996ab939a74
                                                                        • Instruction ID: 5b5398942d1a2a37ac182840868140b8634db461f7b3c354c7c0222dcb947785
                                                                        • Opcode Fuzzy Hash: 65cb0e03891be60b6b6053fa39e45d28bcdd28ebeeb85bb53b847996ab939a74
                                                                        • Instruction Fuzzy Hash: 1081A332A24E1186EBA49F29D4813BD6361FB48F98F144636EF5DC778AEF38D9418340
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: 8096616a82d0af589e55529d9e21aaaddb0a4067eb04550f42ec58ec897b5e0e
                                                                        • Instruction ID: 7439f84f686b79b7b60a0aa5be0b67d29e22776a32f58505ec9653f72bd92d35
                                                                        • Opcode Fuzzy Hash: 8096616a82d0af589e55529d9e21aaaddb0a4067eb04550f42ec58ec897b5e0e
                                                                        • Instruction Fuzzy Hash: CA61F522B28BC882DA51CB1DE0406A9A361E759BD4F549235EB9D87B89FF3CE580C340
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: 35b24077aedd3f9e8a449d09c4eafcb8d5ede4dcad30c6275166c395dfd1882a
                                                                        • Instruction ID: d2ac0b7bd0eb941c509c516acf1e0bc5afe428f2fd1812988fe246b1f5a6d85d
                                                                        • Opcode Fuzzy Hash: 35b24077aedd3f9e8a449d09c4eafcb8d5ede4dcad30c6275166c395dfd1882a
                                                                        • Instruction Fuzzy Hash: CF61D12321E2C48FD30EDF7C589106D7F61D7A7908388469DEAC5EB74BC514C91ACBA6
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: afd72482e03d17e0c267891211c2a08fffdf3b2de236a6c27577c882ac387638
                                                                        • Instruction ID: 8a329f1c1556755d2609766852ca50400cf7488aac0f3a567308d402fe9788c4
                                                                        • Opcode Fuzzy Hash: afd72482e03d17e0c267891211c2a08fffdf3b2de236a6c27577c882ac387638
                                                                        • Instruction Fuzzy Hash: DC51F672A28AC146DB64DB1D94403B9B790FB46B94F105235DB9DC3B9EEF3EE9408B00
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: e6fef933332038a432e0cbe0650c9c98f510f7709ea3c3125d6e13103ebde481
                                                                        • Instruction ID: 1198c1209931bd2d5ede642e1be6e3ce5eb6759eda066c875370076752a3c2e6
                                                                        • Opcode Fuzzy Hash: e6fef933332038a432e0cbe0650c9c98f510f7709ea3c3125d6e13103ebde481
                                                                        • Instruction Fuzzy Hash: DA51D5B1FA80E107DFAC433DA835FB86DD99B82351B09E039E151C9BDBF41E8512A744
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: 8fb7937483d9751731351928e76aee8723c875862e1f4a830a78d4c5ab3ff41f
                                                                        • Instruction ID: 0756c38dea133fc75f0803fee79780ffd4fb52638ea6dee27358b02460cfcf11
                                                                        • Opcode Fuzzy Hash: 8fb7937483d9751731351928e76aee8723c875862e1f4a830a78d4c5ab3ff41f
                                                                        • Instruction Fuzzy Hash: 9B5104A3B0568443DB248B49F842796F7A5FB987C5F00A126EE8D57B69EB3CD5808700
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: 45278502b4de115ed76afef2690a2838d0b28876f14c66dd069eb4612fa83dd3
                                                                        • Instruction ID: 683193802ffc816176e64e76a94cb1baebfb22ed6be3a82fdd833259b30f3fe0
                                                                        • Opcode Fuzzy Hash: 45278502b4de115ed76afef2690a2838d0b28876f14c66dd069eb4612fa83dd3
                                                                        • Instruction Fuzzy Hash: 28516E36A28A5186E7249B2DD0403B927A1EB58F58F245131CB4D9779AFF3AEC43C780
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: c9c3f90e6787dc6e65e60abd648d80575bcfa0207306300bab00d1ff848a11e7
                                                                        • Instruction ID: 37adac26144b190b4425de34cee9121a1cdb301f0d1cbdb5e54ca2ba5db33ae3
                                                                        • Opcode Fuzzy Hash: c9c3f90e6787dc6e65e60abd648d80575bcfa0207306300bab00d1ff848a11e7
                                                                        • Instruction Fuzzy Hash: E6514E36B28A5186E7659B2DC0502A837A1EB48F58F244131CB4DD779AEF3AED53C780
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: ac8362b94cbf271fd23ce0d6965fdbbec26e6817efc2dd1af2fcdc0b4ee58872
                                                                        • Instruction ID: 168364ed28d557d4262a49c1ef7b09d965929a5c3d271ee9d457b3e5a59019e7
                                                                        • Opcode Fuzzy Hash: ac8362b94cbf271fd23ce0d6965fdbbec26e6817efc2dd1af2fcdc0b4ee58872
                                                                        • Instruction Fuzzy Hash: BC515F36A38A5186E7249B2DD0403B837A1EB44F59F244131CB4D9779AFF7AED52C740
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: 7d7dbd699fb3bd762dbe675c4fc42dbf179cbe829f533610fd9071a5c01d9a8f
                                                                        • Instruction ID: e909865a05a90fedcfcb28a2c62dcdf6bd78ea6f41d99e60a9ee79ecf090be8c
                                                                        • Opcode Fuzzy Hash: 7d7dbd699fb3bd762dbe675c4fc42dbf179cbe829f533610fd9071a5c01d9a8f
                                                                        • Instruction Fuzzy Hash: E3F062B1B282958AEBA48F2DB84266977D0F708780F908039E78DC3B18DA3C94618F44
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID:
                                                                        • String ID:
                                                                        • API String ID:
                                                                        • Opcode ID: 261fe6521d892542d75bab8d3c7c41f58578a8ad23917a021c9647768b8a2587
                                                                        • Instruction ID: 299d4648559812499201b4aa2c14f5e87a4997a0b3e695e5f5bc3c58846ed6ad
                                                                        • Opcode Fuzzy Hash: 261fe6521d892542d75bab8d3c7c41f58578a8ad23917a021c9647768b8a2587
                                                                        • Instruction Fuzzy Hash: 55A0022196CE53F5E6048B48E8510B42730FB54B51B800271C20DC266ABF3DAC52C314
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$Process32$CloseHandleImpersonateLoggedNextOpenProcessUser$CreateFirstRevertSelfSnapshotTokenToolhelp32
                                                                        • String ID:
                                                                        • API String ID: 2435156947-0
                                                                        • Opcode ID: 9eb6316bf9a3d5c729c92944e00dde4c55d48e24f54c754d0e24de184432b793
                                                                        • Instruction ID: 623cb845d6fd70736174ee937d734013836951f114e37b908ae9bfcf0c9537bf
                                                                        • Opcode Fuzzy Hash: 9eb6316bf9a3d5c729c92944e00dde4c55d48e24f54c754d0e24de184432b793
                                                                        • Instruction Fuzzy Hash: 6A2271A2A2878185FB009B6CD4443ED6761EB45BA4F505631EB6E86BDFEF7CD884C700
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID: ; expected $; last read: '$syntax error $unexpected $while parsing
                                                                        • API String ID: 3668304517-4239264347
                                                                        • Opcode ID: 4759e7637af97db017a4dc52dc87106eb20a3778af6e12682d5cae83adf0f2e3
                                                                        • Instruction ID: 051e52d3cce930d1ad90d591c64d9bc2fd5ab3007543d87bcc11832ec84b1559
                                                                        • Opcode Fuzzy Hash: 4759e7637af97db017a4dc52dc87106eb20a3778af6e12682d5cae83adf0f2e3
                                                                        • Instruction Fuzzy Hash: 38F16362F18B9189FB109BA8D4503EC2B71AB05BA8F504239DF1D57BDEEF789885D340
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo
                                                                        • String ID: 0$0$0
                                                                        • API String ID: 3215553584-3137946472
                                                                        • Opcode ID: 4b936a4394e80428ad7bf41d875096a3e7add69c0315c25dc0869b4c3066c4ac
                                                                        • Instruction ID: 914da077517b3e69e369b61b6e5794e2ab26c05d1735ee6187a0a0d33d3a3174
                                                                        • Opcode Fuzzy Hash: 4b936a4394e80428ad7bf41d875096a3e7add69c0315c25dc0869b4c3066c4ac
                                                                        • Instruction Fuzzy Hash: 00E1D53292DE4689F762AA2D80D03FD2791DB51F84F548032C78C8779BEE3DAD598701
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Concurrency::cancel_current_task$std::_$Locinfo::_Locinfo_ctorLockitLockit::_
                                                                        • String ID: bad locale name$false$true
                                                                        • API String ID: 164343898-1062449267
                                                                        • Opcode ID: 5c2984d9f35fc82fd5565a6530e0fabf19555f4e36f53be872b21c732f2ac9b9
                                                                        • Instruction ID: 5b7e16d4a9990b15da0abb82f098a40847e6c0deaa1346457ddb5bdba2cde1cd
                                                                        • Opcode Fuzzy Hash: 5c2984d9f35fc82fd5565a6530e0fabf19555f4e36f53be872b21c732f2ac9b9
                                                                        • Instruction Fuzzy Hash: 1C711922B19B418AEB15DF68E4502EC33B5EF44B08F144535DB4DA7B9BEF38A921D344
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Internet$CloseFileHandleOpenRead
                                                                        • String ID: File Downloader
                                                                        • API String ID: 4038090926-3631955488
                                                                        • Opcode ID: 2d8777ee4260c80b314c9bed156458a8780df2b315401914807f3b6119ccca09
                                                                        • Instruction ID: 3fcbbcd924315da5067adcadc11ac08f3f04cec7c623b3f263063707e080b2a1
                                                                        • Opcode Fuzzy Hash: 2d8777ee4260c80b314c9bed156458a8780df2b315401914807f3b6119ccca09
                                                                        • Instruction Fuzzy Hash: E731623261878582E710CF59E4506A9B760FB88FC4F544035EF4E83B5AEF7CE9458B00
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo
                                                                        • String ID: f$p$p
                                                                        • API String ID: 3215553584-1995029353
                                                                        • Opcode ID: eea83e675726579202ae46558f478e57f494447b85c4049c91ddb9471f815998
                                                                        • Instruction ID: 4da5d7e13f6d5846191ce942f6b586789441c27b0708183982fd238a0c3e2656
                                                                        • Opcode Fuzzy Hash: eea83e675726579202ae46558f478e57f494447b85c4049c91ddb9471f815998
                                                                        • Instruction Fuzzy Hash: 51128061A2C96386FB607A18A0542F976A1FB80F50F944135E799C77CEEF3CED848B14
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy
                                                                        • String ID: other_error
                                                                        • API String ID: 1944019136-896093151
                                                                        • Opcode ID: f2863eced8903010f95aa60885efb369d84bc1512526cd4d3b3634791fd3fac8
                                                                        • Instruction ID: 2ad603e274463307495615ca17388765915263a0c1e413f5b6821fb47b46cd6f
                                                                        • Opcode Fuzzy Hash: f2863eced8903010f95aa60885efb369d84bc1512526cd4d3b3634791fd3fac8
                                                                        • Instruction Fuzzy Hash: 3271B362F29B8189FB01CB78D4403EC6361AB59B98F005235EB6C567DEEE78D595C300
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: __std_exception_destroy_invalid_parameter_noinfo_noreturn
                                                                        • String ID: at line $, column
                                                                        • API String ID: 729085983-191570568
                                                                        • Opcode ID: 0568d2328471f8f76334d58d3ad0d9c07eec44adb01daa58e6bbaa1e44269a43
                                                                        • Instruction ID: 66281b0fb5e2b88e93755585b115172a0738ccb3d286cd2a28727a1c4d8ea9ad
                                                                        • Opcode Fuzzy Hash: 0568d2328471f8f76334d58d3ad0d9c07eec44adb01daa58e6bbaa1e44269a43
                                                                        • Instruction Fuzzy Hash: 1051C662A18B8141EA109B19E5442BE7761FB89FD0F144231EBAC47BDBEF3DD891C740
                                                                        APIs
                                                                        • LoadLibraryExW.KERNEL32(?,?,?,00007FF6B53D467E,?,?,?,00007FF6B53D4370,?,?,?,00007FF6B53D0E4D), ref: 00007FF6B53D4451
                                                                        • GetLastError.KERNEL32(?,?,?,00007FF6B53D467E,?,?,?,00007FF6B53D4370,?,?,?,00007FF6B53D0E4D), ref: 00007FF6B53D445F
                                                                        • LoadLibraryExW.KERNEL32(?,?,?,00007FF6B53D467E,?,?,?,00007FF6B53D4370,?,?,?,00007FF6B53D0E4D), ref: 00007FF6B53D4489
                                                                        • FreeLibrary.KERNEL32(?,?,?,00007FF6B53D467E,?,?,?,00007FF6B53D4370,?,?,?,00007FF6B53D0E4D), ref: 00007FF6B53D44F7
                                                                        • GetProcAddress.KERNEL32(?,?,?,00007FF6B53D467E,?,?,?,00007FF6B53D4370,?,?,?,00007FF6B53D0E4D), ref: 00007FF6B53D4503
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Library$Load$AddressErrorFreeLastProc
                                                                        • String ID: api-ms-
                                                                        • API String ID: 2559590344-2084034818
                                                                        • Opcode ID: 081807f0f237e99e654a6d52eb3ba83cc0c1c8883019cc9f4ec60aedd52be443
                                                                        • Instruction ID: 87bbeadc8a5f79213d1524436435f6f2b1dfece7837dcbe95152f990d1e365cf
                                                                        • Opcode Fuzzy Hash: 081807f0f237e99e654a6d52eb3ba83cc0c1c8883019cc9f4ec60aedd52be443
                                                                        • Instruction Fuzzy Hash: 5031A321A2AB4291EE52EB0AA8005B523F4BF44F64F498535DF1D8778AFF7CE8908300
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Value$ErrorLast
                                                                        • String ID:
                                                                        • API String ID: 2506987500-0
                                                                        • Opcode ID: 234b12f341dec54f59bcc24a3b45c090fbebf6e7b37c81ec12f591380fe05ed0
                                                                        • Instruction ID: 471864d740f3ab88b8265c0a784719af2363e5e518120dc1666b12928843ccd9
                                                                        • Opcode Fuzzy Hash: 234b12f341dec54f59bcc24a3b45c090fbebf6e7b37c81ec12f591380fe05ed0
                                                                        • Instruction Fuzzy Hash: 32213021B2DA4242FA59772955611B962415F44FB5F144B34EB2D867CFFE2CFC418710
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
                                                                        • String ID: CONOUT$
                                                                        • API String ID: 3230265001-3130406586
                                                                        • Opcode ID: 53dac6272d403f79ff27e653aa55d51cb6535fcae6368453f164039c5e4e95e8
                                                                        • Instruction ID: a02217fe49b10b5a38154aa283418b8678090b018a4701172f5756bf640b80f0
                                                                        • Opcode Fuzzy Hash: 53dac6272d403f79ff27e653aa55d51cb6535fcae6368453f164039c5e4e95e8
                                                                        • Instruction Fuzzy Hash: FC118E31A28B4186E7508B4AF8543A977A0FB88FE4F040234EB5DC77A9EF3CE9548740
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: ByteCharMultiWide$CompareInfoString
                                                                        • String ID:
                                                                        • API String ID: 2984826149-0
                                                                        • Opcode ID: 26eb7e015d5d110b74ff0d84bcaa31491d724dbf353ec7a17117fafe3eaea0ab
                                                                        • Instruction ID: 0d0ba0e1ba68184cc81a796c59430a1d9332fd242ef49e71417b17df76b25f7c
                                                                        • Opcode Fuzzy Hash: 26eb7e015d5d110b74ff0d84bcaa31491d724dbf353ec7a17117fafe3eaea0ab
                                                                        • Instruction Fuzzy Hash: F0A18062A6978246FB619F2894503F977A2AB41F98F444A31DB5D877CAFF3CEC448340
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo
                                                                        • String ID:
                                                                        • API String ID: 3215553584-0
                                                                        • Opcode ID: 619b2885e3fd1682f6a864358b33df5452abb606e6c6f730ccce56a3fdc98189
                                                                        • Instruction ID: 87bc3fa9559e7b80594da723e6884b58648d4dfc5bb2cc21a737559160ba0740
                                                                        • Opcode Fuzzy Hash: 619b2885e3fd1682f6a864358b33df5452abb606e6c6f730ccce56a3fdc98189
                                                                        • Instruction Fuzzy Hash: 57513E2292DE8685FB93AF2890A02FD7791AB45F44F448071C78C8739BEE2D9C46C742
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Is_bad_exception_allowedstd::bad_alloc::bad_alloc
                                                                        • String ID: csm$csm$csm
                                                                        • API String ID: 3523768491-393685449
                                                                        • Opcode ID: c1d1beaa4113af996e1338b12892c8267a8f52db6b2a83b87ebed410bd88f7c3
                                                                        • Instruction ID: a0760362d71977526460d0f950a603bd96057fdbbb9540f79a97d85b6fa3349a
                                                                        • Opcode Fuzzy Hash: c1d1beaa4113af996e1338b12892c8267a8f52db6b2a83b87ebed410bd88f7c3
                                                                        • Instruction Fuzzy Hash: AFE19F629687828AE7519B68D4802ED77B0FB44B48F114235EF8D877DBEF38E981C700
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 3668304517-0
                                                                        • Opcode ID: 803ca54e3e655cfce5e0d02a6eb01fa19050cbeec9da1d7b51a4c3d1aa9fb0d7
                                                                        • Instruction ID: d6f49fee5683f8445ff95e5e722e38ab154f23faffd3f9b72910bdd95eaa3293
                                                                        • Opcode Fuzzy Hash: 803ca54e3e655cfce5e0d02a6eb01fa19050cbeec9da1d7b51a4c3d1aa9fb0d7
                                                                        • Instruction Fuzzy Hash: 29D1A162F28B8185FA109B69E4402ED6761EB45BE8F101631EF5D97BDEEF78D881C300
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: AdjustPointer
                                                                        • String ID:
                                                                        • API String ID: 1740715915-0
                                                                        • Opcode ID: 3df3621708c9e1d29be45954cd8076bff015c977087edb3d15e3ad851c434b44
                                                                        • Instruction ID: badbb7d536fcd3109490b096e7d3e3fb3c0b03a6c0ef1d9c24338e55961f281e
                                                                        • Opcode Fuzzy Hash: 3df3621708c9e1d29be45954cd8076bff015c977087edb3d15e3ad851c434b44
                                                                        • Instruction Fuzzy Hash: 5AB1A322EA968682EA659B59D1406B863B1AF44FC4F198435DF4D877CFFE3CEC528300
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _set_statfp
                                                                        • String ID:
                                                                        • API String ID: 1156100317-0
                                                                        • Opcode ID: dafef7e4c20223e5ca6141b6b5924ce650fb2efe4a4f2b5535d10e0333dca376
                                                                        • Instruction ID: c5929ef3b9132c0f2406ff0bd1b74c15b4816854b81e951756a388f885c1899b
                                                                        • Opcode Fuzzy Hash: dafef7e4c20223e5ca6141b6b5924ce650fb2efe4a4f2b5535d10e0333dca376
                                                                        • Instruction Fuzzy Hash: 9981DA12D28B5645F6729B3DA4002FAA260AF55B94F044331EB4EA679EFF3CEC919700
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: EnvironmentInitStringStringsUnicode$Free_invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 1868271193-0
                                                                        • Opcode ID: f38410d1663a3c3ea2f5305d9f7767b79f8e6583bd52c22dc4790f0fe6c50e43
                                                                        • Instruction ID: 9b257c344365714304d444fe0be91738531475474eafde45d6648c9f0a62e8b4
                                                                        • Opcode Fuzzy Hash: f38410d1663a3c3ea2f5305d9f7767b79f8e6583bd52c22dc4790f0fe6c50e43
                                                                        • Instruction Fuzzy Hash: F8518072A18B8182EB118F19E4403AD7760FB94F94F549225DB9D43B9AEF7CE5E1C300
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
                                                                        • String ID: Nk
                                                                        • API String ID: 3936042273-1353404103
                                                                        • Opcode ID: 47971b2b297099cf51065093ee76f174fdeaffe5bb93d43a9961e66d31b14998
                                                                        • Instruction ID: 476f010d9336e585a0a2ee7588e42f9c384b47a75a6b47f4b1054c176704e88b
                                                                        • Opcode Fuzzy Hash: 47971b2b297099cf51065093ee76f174fdeaffe5bb93d43a9961e66d31b14998
                                                                        • Instruction Fuzzy Hash: 8CC17D33A18B858AE711CF69E4402ED73B1FB59B98F045625DF8D53B5AEF38E5A08300
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: CallEncodePointerTranslator
                                                                        • String ID: MOC$RCC
                                                                        • API String ID: 3544855599-2084237596
                                                                        • Opcode ID: 9c00d47a1c5516f7bd2be0d164cd20731702100fa42f3d3dd2f3d47e27ffce20
                                                                        • Instruction ID: 77b1331018cda7a00e215a6a4b62cdc4261dbdd870bc7a590a0b9c9648d4bcad
                                                                        • Opcode Fuzzy Hash: 9c00d47a1c5516f7bd2be0d164cd20731702100fa42f3d3dd2f3d47e27ffce20
                                                                        • Instruction Fuzzy Hash: 3E91C673A18B819AE751CB68E4802ED77B0FB44B88F14412AEF4D9779AEF38D595C700
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: CallEncodePointerTranslator
                                                                        • String ID: MOC$RCC
                                                                        • API String ID: 3544855599-2084237596
                                                                        • Opcode ID: a60986bc9adbf2c75a94aae45f25198f4bb40c34f31260bb5ef7955aadcba44f
                                                                        • Instruction ID: 4f2ace02d510ebf2fe5e3670a787ba3afad70d27d0ec921a5aabbb4c6a330635
                                                                        • Opcode Fuzzy Hash: a60986bc9adbf2c75a94aae45f25198f4bb40c34f31260bb5ef7955aadcba44f
                                                                        • Instruction Fuzzy Hash: 9B61B232918BC591D7219B29E4807EAB7A0FB84F94F044225EF8C43B9AEF7CD590CB00
                                                                        APIs
                                                                        • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6B53A0647
                                                                        • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6B53A064D
                                                                          • Part of subcall function 00007FF6B53D0E88: RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,-2723E8D8DEBC5094,00007FF6B53DC3D2), ref: 00007FF6B53D0ED8
                                                                          • Part of subcall function 00007FF6B53D0E88: RaiseException.KERNEL32(?,?,?,?,?,?,?,?,-2723E8D8DEBC5094,00007FF6B53DC3D2), ref: 00007FF6B53D0F19
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$ExceptionFileHeaderRaise
                                                                        • String ID: exists$ios_base::badbit set
                                                                        • API String ID: 240014264-2074760687
                                                                        • Opcode ID: a4f327a84339e12cc55e92ce62d72d2997565a8db53c75ec50c66e7b8b607d78
                                                                        • Instruction ID: 968589648d82fc7abe7be5e5d4c2d32e385cb71bb633dc6efce0896206b53dc6
                                                                        • Opcode Fuzzy Hash: a4f327a84339e12cc55e92ce62d72d2997565a8db53c75ec50c66e7b8b607d78
                                                                        • Instruction Fuzzy Hash: 25410D72619BC695EA21DB18E4942EA7761FB84B40F804532D78D83BAEEF7CD905CB40
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: AddressHandleModuleProc
                                                                        • String ID: GetTempPath2W$kernel32.dll
                                                                        • API String ID: 1646373207-1846531799
                                                                        • Opcode ID: 85c4015c5df5ee79752990f65a767554006cfd6127e60443cb10f02faa6b2ab0
                                                                        • Instruction ID: 66813f885c3914f9df97819d14cc5bd74e853fe920fe68ae4aa47689eb24c914
                                                                        • Opcode Fuzzy Hash: 85c4015c5df5ee79752990f65a767554006cfd6127e60443cb10f02faa6b2ab0
                                                                        • Instruction Fuzzy Hash: 05E01221B28B0691EE049B59F9844F97321BF48F81B985035CA0E8733AFF3CE8598700
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn$FreeString
                                                                        • String ID:
                                                                        • API String ID: 1965679434-0
                                                                        • Opcode ID: e707a254593d276e9d81f7da790380d37dd460deab93068eb36779375bd74940
                                                                        • Instruction ID: 2087190758d1572011e1b02be3f44d1f75cbf450dbc6eb272c72b5ce17800771
                                                                        • Opcode Fuzzy Hash: e707a254593d276e9d81f7da790380d37dd460deab93068eb36779375bd74940
                                                                        • Instruction Fuzzy Hash: F2E19162F28B818AFB00DBA9D4512EC23B2EB45B98F404535DF1D97B9FEE38D9558340
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: FileWrite$ConsoleErrorLastOutput
                                                                        • String ID:
                                                                        • API String ID: 2718003287-0
                                                                        • Opcode ID: 51ca5d62aa19301a18794717acfbf1a46562df65ce568f5fb7798e040ec77a5b
                                                                        • Instruction ID: 3775dfb0562ea7f7b44e289bb7a97a54a9a5348cbeccdecb76565f877924db7f
                                                                        • Opcode Fuzzy Hash: 51ca5d62aa19301a18794717acfbf1a46562df65ce568f5fb7798e040ec77a5b
                                                                        • Instruction Fuzzy Hash: A5D1D332B28A4589E721DF69D4406EC37B1FB55F98B084236CF5D97B9AEE38D806C740
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID:
                                                                        • API String ID: 3668304517-0
                                                                        • Opcode ID: dc1f7467f6b438ed16d1ac356133b9821a069205ebe8ddfd552de79892740363
                                                                        • Instruction ID: 109083aac7aa5309231fec5ec454ba26b332b871a6d9fc8973366c7785c60fcc
                                                                        • Opcode Fuzzy Hash: dc1f7467f6b438ed16d1ac356133b9821a069205ebe8ddfd552de79892740363
                                                                        • Instruction Fuzzy Hash: 55518E7272AB8581EE14CF68E4542AC73A5FB44F94F544635DBAC47B8AEF2CD8A0C340
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo
                                                                        • String ID:
                                                                        • API String ID: 3215553584-0
                                                                        • Opcode ID: f1f9df1a05da3301ed415653e8360f7cb12179a044a2575d07df28b1a0800ec9
                                                                        • Instruction ID: 0fa664588b7b14d5e30531e32f59cc91202ed08ac807f316558dd0c369a7a88e
                                                                        • Opcode Fuzzy Hash: f1f9df1a05da3301ed415653e8360f7cb12179a044a2575d07df28b1a0800ec9
                                                                        • Instruction Fuzzy Hash: D3416122929E8589EB53EF28C4552FD7BA0AB45F84F49C071C78C8738BEE3D9945C711
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: std::_$LockitLockit::_$Concurrency::cancel_current_taskFacet_Register
                                                                        • String ID:
                                                                        • API String ID: 1168246061-0
                                                                        • Opcode ID: fce11bbf2716b712929d21612f2a8f238f427733906def6abb3c40e1e27c6ea6
                                                                        • Instruction ID: cf07df01ef8d387416c06796e161eeff06386542da911954d5aab11c79c2aa28
                                                                        • Opcode Fuzzy Hash: fce11bbf2716b712929d21612f2a8f238f427733906def6abb3c40e1e27c6ea6
                                                                        • Instruction Fuzzy Hash: 12414121A2CB4280EA15DB19E4542E967B0FB44FA4F580135DB8D877AEEF7CE851C710
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: std::_$LockitLockit::_$Concurrency::cancel_current_taskFacet_Register
                                                                        • String ID:
                                                                        • API String ID: 1168246061-0
                                                                        • Opcode ID: acbc9ea0ed55ab8395d29e3490695ccec0bb7a6dea11a1816461c93234175631
                                                                        • Instruction ID: d8033b1aaa95ed273a3dc69d82d41e931ff826d8c7bd20ac8430f8fd14641c66
                                                                        • Opcode Fuzzy Hash: acbc9ea0ed55ab8395d29e3490695ccec0bb7a6dea11a1816461c93234175631
                                                                        • Instruction Fuzzy Hash: 6D417321A2CB4280EA55DF19E4842F97760FB88F94F580135EB4D877AEEE3CE8528700
                                                                        APIs
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: ByteCharErrorLastMultiWide
                                                                        • String ID:
                                                                        • API String ID: 203985260-0
                                                                        • Opcode ID: b0c4d9c72fcc6461851340ae7f6c093d4e41e08a8bab11e5154c9cbc0382217d
                                                                        • Instruction ID: 812b3ee3b2827cac1ac6a2059f3ad2631f400594bb9849e8a3c28c01442d6678
                                                                        • Opcode Fuzzy Hash: b0c4d9c72fcc6461851340ae7f6c093d4e41e08a8bab11e5154c9cbc0382217d
                                                                        • Instruction Fuzzy Hash: C2215176A28B4587E720CF15E45436E7AB4F789F94F140138DB8997B99EF3CE8118B00
                                                                        APIs
                                                                          • Part of subcall function 00007FF6B53DB210: GetModuleHandleW.KERNEL32(?,?,?,00007FF6B53DB8FA), ref: 00007FF6B53DB226
                                                                          • Part of subcall function 00007FF6B53DB210: GetProcAddress.KERNEL32(?,?,?,00007FF6B53DB8FA), ref: 00007FF6B53DB236
                                                                        • GetLastError.KERNEL32 ref: 00007FF6B53DB904
                                                                          • Part of subcall function 00007FF6B53B98B4: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,00007FF6B53AF8CA,?,?,-2723E8D8DEBC5093,00007FF6B53B8156), ref: 00007FF6B53B98DA
                                                                        • GetFileAttributesW.KERNEL32 ref: 00007FF6B53DB913
                                                                        • __std_fs_open_handle.LIBCPMT ref: 00007FF6B53DB93C
                                                                        • CloseHandle.KERNEL32 ref: 00007FF6B53DB94E
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Handle$AddressAttributesCloseErrorFeatureFileLastModulePresentProcProcessor__std_fs_open_handle
                                                                        • String ID:
                                                                        • API String ID: 156590933-0
                                                                        • Opcode ID: 6a84e7cc61d3f6faa1a02f0b285c9e89f06a54f244136a8e8d2e5cb925bd3053
                                                                        • Instruction ID: 9d590cec49b00ec6bd0efbbe4fe38cf4ac332932426f8b7999dcd61a07920def
                                                                        • Opcode Fuzzy Hash: 6a84e7cc61d3f6faa1a02f0b285c9e89f06a54f244136a8e8d2e5cb925bd3053
                                                                        • Instruction Fuzzy Hash: EA114621A7C68245EA50572DA0942BA6671DB44FB0F141634E77EC67EEEE3CD8418F00
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: __except_validate_context_record
                                                                        • String ID: csm$csm
                                                                        • API String ID: 1467352782-3733052814
                                                                        • Opcode ID: 4d7a57ad738694d133ebd4354881888b3b35db442aff29f4f0bd919a509eac2d
                                                                        • Instruction ID: 8378c743516ddd0094c36efe972f7c28748bafaeb3b7ccc4112d20cd452adc68
                                                                        • Opcode Fuzzy Hash: 4d7a57ad738694d133ebd4354881888b3b35db442aff29f4f0bd919a509eac2d
                                                                        • Instruction Fuzzy Hash: 4971806251868186EB618A29D4807B9BAA0FB44F85F148175EF4D87BCEEF3CD991C740
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: Unwind__except_validate_context_record
                                                                        • String ID: csm
                                                                        • API String ID: 2208346422-1018135373
                                                                        • Opcode ID: b6b4ec287b03b43af7135d47e4a928fccc53e45a76218f894a62c54d13e92dd1
                                                                        • Instruction ID: 8068dcfaa929bb32ff36c36181f108d8b0c0ff2440bb29482ab2c6909026a317
                                                                        • Opcode Fuzzy Hash: b6b4ec287b03b43af7135d47e4a928fccc53e45a76218f894a62c54d13e92dd1
                                                                        • Instruction Fuzzy Hash: 2F517122B6A6068AEB55CB19E044ABC27A1EB44F94F548131DB5E877DAFF7CEC41C700
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: std::_$Locinfo::_Locinfo_ctorLockitLockit::_
                                                                        • String ID: bad locale name
                                                                        • API String ID: 3988782225-1405518554
                                                                        • Opcode ID: 3ed45f339c8c002eab9b665f8468a7d6672470220fe7fd7aec0b4e39f8eb7c09
                                                                        • Instruction ID: 621f06f2a289d10289c57ceb9c5a4cace05562cf972111bfdef140ab6c5fb0be
                                                                        • Opcode Fuzzy Hash: 3ed45f339c8c002eab9b665f8468a7d6672470220fe7fd7aec0b4e39f8eb7c09
                                                                        • Instruction Fuzzy Hash: 42514B32B19B41C9EB54DFB8E4502EC33B5EF44B48F044439EB4DA6B9AEE38D9259344
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _get_daylight$_invalid_parameter_noinfo
                                                                        • String ID: ?
                                                                        • API String ID: 1286766494-1684325040
                                                                        • Opcode ID: 8cc10c94a39c9ff88641584515667495cb56c14fac55e8e90be5500fd08faa51
                                                                        • Instruction ID: 86bd87c774263690aa102022ca53e8167c0d2bcf008c6acce5129b0793699f63
                                                                        • Opcode Fuzzy Hash: 8cc10c94a39c9ff88641584515667495cb56c14fac55e8e90be5500fd08faa51
                                                                        • Instruction Fuzzy Hash: 7241D512A287A246FB64972D98453BA5650EB91FA4F144235FF9C86BDAFF3CD8418700
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: CreateFrameInfo__except_validate_context_record
                                                                        • String ID: csm
                                                                        • API String ID: 2558813199-1018135373
                                                                        • Opcode ID: 30dd612b4e4b9212e9166655247be16b5f23695bfc4863c6a6ebc2986465c29c
                                                                        • Instruction ID: 92e46716d0bffc9494a7886adfaff8ca239e2960e1f9a5b77e1da835c062e4a6
                                                                        • Opcode Fuzzy Hash: 30dd612b4e4b9212e9166655247be16b5f23695bfc4863c6a6ebc2986465c29c
                                                                        • Instruction Fuzzy Hash: CB51827666874586D660EF19E0402AD77B4F789F91F100534EB8D87B9AEF3CE851CB01
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID: iterator does not fit current value$iterator out of range
                                                                        • API String ID: 3668304517-1046077056
                                                                        • Opcode ID: c783f45f6ac9ed78e5ccc847484a86fd53dc522b74bb063e9fdd151bce9c54cb
                                                                        • Instruction ID: 4ed5491b5496bf9913f8dcf88afb1f6bf7ea4486c88dad62b2be51ecdfca4de4
                                                                        • Opcode Fuzzy Hash: c783f45f6ac9ed78e5ccc847484a86fd53dc522b74bb063e9fdd151bce9c54cb
                                                                        • Instruction Fuzzy Hash: 184181A3F18A8696E711DB68D4952EC27709B51B48F944076CB0D83BDFEE38995AC340
                                                                        APIs
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: _invalid_parameter_noinfo_noreturn
                                                                        • String ID: iterator does not fit current value$iterator out of range
                                                                        • API String ID: 3668304517-1046077056
                                                                        • Opcode ID: 5241b744fb5bd14edf4650fb39449879ec2e0fa76d064271e4a9ac59758b63dd
                                                                        • Instruction ID: 8aa206daad9a36f921f2965023db61ada799d3d07f9af12d7af04cc98a1879b8
                                                                        • Opcode Fuzzy Hash: 5241b744fb5bd14edf4650fb39449879ec2e0fa76d064271e4a9ac59758b63dd
                                                                        • Instruction Fuzzy Hash: 7D4194A3F19A8596FB11DB64D8952EC23709B50B48F94447ACB0D83BDFFE389969C340
                                                                        APIs
                                                                        • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,-2723E8D8DEBC5094,00007FF6B53DC3D2), ref: 00007FF6B53D0ED8
                                                                        • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,-2723E8D8DEBC5094,00007FF6B53DC3D2), ref: 00007FF6B53D0F19
                                                                        Strings
                                                                        Memory Dump Source
                                                                        • Source File: 00000000.00000002.2422055903.00007FF6B5321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6B5320000, based on PE: true
                                                                        • Associated: 00000000.00000002.2422031968.00007FF6B5320000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422144649.00007FF6B53F5000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422195982.00007FF6B5450000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422246901.00007FF6B5452000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422274890.00007FF6B5455000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                        • Associated: 00000000.00000002.2422302366.00007FF6B5458000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                        Joe Sandbox IDA Plugin
                                                                        • Snapshot File: hcaresult_0_2_7ff6b5320000_duschno.jbxd
                                                                        Similarity
                                                                        • API ID: ExceptionFileHeaderRaise
                                                                        • String ID: csm
                                                                        • API String ID: 2573137834-1018135373
                                                                        • Opcode ID: b70c8f01ca01e1ec4819aea0aadbf8579bb2f3e39c9b562f706c3da26c2f4cc1
                                                                        • Instruction ID: 218e00a383b2b73b96cbe0c24e609d267e10aa3dfc747220344325c8510dedaf
                                                                        • Opcode Fuzzy Hash: b70c8f01ca01e1ec4819aea0aadbf8579bb2f3e39c9b562f706c3da26c2f4cc1
                                                                        • Instruction Fuzzy Hash: 65112E32619B8582EB618F19F440299B7E4FB88F84F584235EB8D47B99EF3CD9518700