Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
j1gw88aHdL.exe

Overview

General Information

Sample name:j1gw88aHdL.exe
renamed because original name is a hash value
Original sample name:fd682a2c1ed42403a8e943010f660f79.exe
Analysis ID:1580957
MD5:fd682a2c1ed42403a8e943010f660f79
SHA1:0c20c808746dd38cffe1d474ade5031d1611f041
SHA256:131a0064f14f3bad96b0be6d61638f0ef51d110109d4242134af9261a191ffc1
Tags:exeuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query CPU information (cpuid)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Extensive use of GetProcAddress (often used to hide API calls)
Found evasive API chain checking for process token information
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
Program does not show much activity (idle)

Classification

  • System is w10x64
  • j1gw88aHdL.exe (PID: 7428 cmdline: "C:\Users\user\Desktop\j1gw88aHdL.exe" MD5: FD682A2C1ED42403A8E943010F660F79)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: j1gw88aHdL.exeVirustotal: Detection: 9%Perma Link
Source: j1gw88aHdL.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4BF9280 FindFirstFileExW,FindClose,0_2_00007FF7D4BF9280
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C11874 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF7D4C11874
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4BF83C0 FindFirstFileW,RemoveDirectoryW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,0_2_00007FF7D4BF83C0
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4BF10000_2_00007FF7D4BF1000
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C169640_2_00007FF7D4C16964
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C035A00_2_00007FF7D4C035A0
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C0E5700_2_00007FF7D4C0E570
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C05D300_2_00007FF7D4C05D30
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C01D540_2_00007FF7D4C01D54
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C0DEF00_2_00007FF7D4C0DEF0
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C09EA00_2_00007FF7D4C09EA0
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C15E7C0_2_00007FF7D4C15E7C
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4BF98000_2_00007FF7D4BF9800
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C01F600_2_00007FF7D4C01F60
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C087940_2_00007FF7D4C08794
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C197280_2_00007FF7D4C19728
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C017400_2_00007FF7D4C01740
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C080E40_2_00007FF7D4C080E4
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C140AC0_2_00007FF7D4C140AC
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C108C80_2_00007FF7D4C108C8
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C118740_2_00007FF7D4C11874
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4BF89E00_2_00007FF7D4BF89E0
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C039A40_2_00007FF7D4C039A4
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C021640_2_00007FF7D4C02164
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C019440_2_00007FF7D4C01944
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4BFA2DB0_2_00007FF7D4BFA2DB
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C0DA5C0_2_00007FF7D4C0DA5C
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C13C100_2_00007FF7D4C13C10
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C02C100_2_00007FF7D4C02C10
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C15C000_2_00007FF7D4C15C00
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C01B500_2_00007FF7D4C01B50
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4BFACAD0_2_00007FF7D4BFACAD
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4BFA47B0_2_00007FF7D4BFA47B
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C164180_2_00007FF7D4C16418
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C108C80_2_00007FF7D4C108C8
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: String function: 00007FF7D4BF2710 appears 52 times
Source: classification engineClassification label: mal48.winEXE@1/0@0/0
Source: j1gw88aHdL.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\j1gw88aHdL.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: j1gw88aHdL.exeVirustotal: Detection: 9%
Source: C:\Users\user\Desktop\j1gw88aHdL.exeFile read: C:\Users\user\Desktop\j1gw88aHdL.exeJump to behavior
Source: C:\Users\user\Desktop\j1gw88aHdL.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\j1gw88aHdL.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\j1gw88aHdL.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\j1gw88aHdL.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\j1gw88aHdL.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\j1gw88aHdL.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\j1gw88aHdL.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\j1gw88aHdL.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\j1gw88aHdL.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\j1gw88aHdL.exeSection loaded: wintypes.dllJump to behavior
Source: j1gw88aHdL.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: j1gw88aHdL.exeStatic file information: File size 17226969 > 1048576
Source: j1gw88aHdL.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: j1gw88aHdL.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: j1gw88aHdL.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: j1gw88aHdL.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: j1gw88aHdL.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: j1gw88aHdL.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: j1gw88aHdL.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: j1gw88aHdL.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: j1gw88aHdL.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: j1gw88aHdL.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: j1gw88aHdL.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: j1gw88aHdL.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: j1gw88aHdL.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4BF76C0 GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,0_2_00007FF7D4BF76C0
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCheck user administrative privileges: GetTokenInformation,DecisionNodesgraph_0-17914
Source: C:\Users\user\Desktop\j1gw88aHdL.exeAPI coverage: 5.2 %
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4BF9280 FindFirstFileExW,FindClose,0_2_00007FF7D4BF9280
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C11874 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF7D4C11874
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4BF83C0 FindFirstFileW,RemoveDirectoryW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,0_2_00007FF7D4BF83C0
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C0A614 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7D4C0A614
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C13480 GetProcessHeap,0_2_00007FF7D4C13480
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C0A614 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7D4C0A614
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4BFC8A0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF7D4BFC8A0
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4BFD12C IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7D4BFD12C
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4BFD30C SetUnhandledExceptionFilter,0_2_00007FF7D4BFD30C
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C19570 cpuid 0_2_00007FF7D4C19570
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4BFD010 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF7D4BFD010
Source: C:\Users\user\Desktop\j1gw88aHdL.exeCode function: 0_2_00007FF7D4C15E7C _get_daylight,_get_daylight,_get_daylight,GetTimeZoneInformation,0_2_00007FF7D4C15E7C
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
Native API
1
DLL Side-Loading
1
DLL Side-Loading
1
Deobfuscate/Decode Files or Information
OS Credential Dumping2
System Time Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
DLL Side-Loading
LSASS Memory2
Security Software Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Obfuscated Files or Information
Security Account Manager1
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDS13
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
j1gw88aHdL.exe10%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1580957
Start date and time:2024-12-26 14:13:16 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 2m 25s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:2
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:j1gw88aHdL.exe
renamed because original name is a hash value
Original Sample Name:fd682a2c1ed42403a8e943010f660f79.exe
Detection:MAL
Classification:mal48.winEXE@1/0@0/0
EGA Information:
  • Successful, ratio: 100%
HCA Information:
  • Successful, ratio: 98%
  • Number of executed functions: 21
  • Number of non-executed functions: 86
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Stop behavior analysis, all processes terminated
  • Exclude process from analysis (whitelisted): dllhost.exe
  • Excluded IPs from analysis (whitelisted): 13.107.246.63
  • Excluded domains from analysis (whitelisted): otelrules.azureedge.net, time.windows.com
  • Report size getting too big, too many NtSetInformationFile calls found.
No simulations
No context
No context
No context
No context
No context
No created / dropped files found
File type:PE32+ executable (GUI) x86-64, for MS Windows
Entropy (8bit):7.991484004709739
TrID:
  • Win64 Executable GUI (202006/5) 92.65%
  • Win64 Executable (generic) (12005/4) 5.51%
  • Generic Win/DOS Executable (2004/3) 0.92%
  • DOS Executable Generic (2002/1) 0.92%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:j1gw88aHdL.exe
File size:17'226'969 bytes
MD5:fd682a2c1ed42403a8e943010f660f79
SHA1:0c20c808746dd38cffe1d474ade5031d1611f041
SHA256:131a0064f14f3bad96b0be6d61638f0ef51d110109d4242134af9261a191ffc1
SHA512:3fdb186d1d8f3a2ba0e50803640083775c5db690e51c426acc944d6571e5c58dcc69dc73374013b9f0b53a7f102ade72eb9d84c5f6813d03355a599490e9b196
SSDEEP:393216:wEkQc5SEaB1+TtIiFxcijMOGEt0V8IPSbLYY60XlimW:w9Sd1QtI4jMOi8IkLYYo
TLSH:9E071274830BAA9EE32354B44B2067D7271122E6D543B87D23717CDF566B073F6E2A22
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........Zpc.Zpc.Zpc...`.]pc...f..pc...g.Ppc.....Ypc...`.Spc...g.Kpc...f.rpc...b.Qpc.Zpb..pc.O.g.Cpc.O.a.[pc.RichZpc.........PE..d..
Icon Hash:4a464cd47461e179
Entrypoint:0x14000cdb0
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x140000000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Time Stamp:0x670BD14D [Sun Oct 13 13:55:25 2024 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:6
OS Version Minor:0
File Version Major:6
File Version Minor:0
Subsystem Version Major:6
Subsystem Version Minor:0
Import Hash:72c4e339b7af8ab1ed2eb3821c98713a
Instruction
dec eax
sub esp, 28h
call 00007FD52CDEA0FCh
dec eax
add esp, 28h
jmp 00007FD52CDE9D1Fh
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
dec eax
sub esp, 28h
call 00007FD52CDEA4C8h
test eax, eax
je 00007FD52CDE9EC3h
dec eax
mov eax, dword ptr [00000030h]
dec eax
mov ecx, dword ptr [eax+08h]
jmp 00007FD52CDE9EA7h
dec eax
cmp ecx, eax
je 00007FD52CDE9EB6h
xor eax, eax
dec eax
cmpxchg dword ptr [0003577Ch], ecx
jne 00007FD52CDE9E90h
xor al, al
dec eax
add esp, 28h
ret
mov al, 01h
jmp 00007FD52CDE9E99h
int3
int3
int3
dec eax
sub esp, 28h
test ecx, ecx
jne 00007FD52CDE9EA9h
mov byte ptr [00035765h], 00000001h
call 00007FD52CDE95F5h
call 00007FD52CDEA8E0h
test al, al
jne 00007FD52CDE9EA6h
xor al, al
jmp 00007FD52CDE9EB6h
call 00007FD52CDF73FFh
test al, al
jne 00007FD52CDE9EABh
xor ecx, ecx
call 00007FD52CDEA8F0h
jmp 00007FD52CDE9E8Ch
mov al, 01h
dec eax
add esp, 28h
ret
int3
int3
inc eax
push ebx
dec eax
sub esp, 20h
cmp byte ptr [0003572Ch], 00000000h
mov ebx, ecx
jne 00007FD52CDE9F09h
cmp ecx, 01h
jnbe 00007FD52CDE9F0Ch
call 00007FD52CDEA43Eh
test eax, eax
je 00007FD52CDE9ECAh
test ebx, ebx
jne 00007FD52CDE9EC6h
dec eax
lea ecx, dword ptr [00035716h]
call 00007FD52CDF71F2h
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0x3ca5c0x78.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0x470000xf41c.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x440000x2250.pdata
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x570000x764.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x3a0800x1c.rdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x39f400x140.rdata
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x2b0000x4a0.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x29f000x2a000a6c3b829cc8eaabb1a474c227e90407fFalse0.5514206659226191data6.487493643901088IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rdata0x2b0000x12a500x12c00bd1b0c418cef6d86056268b7be16a1dfFalse0.52453125data5.752794169758469IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0x3e0000x53f80xe00dba0caeecab624a0ccc0d577241601d1False0.134765625data1.8392217063172436IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.pdata0x440000x22500x2400181312260a85d10a1454ba38901c499bFalse0.4705946180555556data5.290347578351011IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.rsrc0x470000xf41c0xf600455788c285fcfdcb4008bc77e762818aFalse0.803099593495935data7.5549760623589695IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0x570000x7640x800816c68eeb419ee2c08656c31c06a0fffFalse0.5576171875data5.2809528666624175IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
RT_ICON0x472080xea8Device independent bitmap graphic, 48 x 96 x 8, image size 00.585820895522388
RT_ICON0x480b00x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 00.7360108303249098
RT_ICON0x489580x568Device independent bitmap graphic, 16 x 32 x 8, image size 00.755057803468208
RT_ICON0x48ec00x952cPNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced0.9975384937676757
RT_ICON0x523ec0x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 00.3887966804979253
RT_ICON0x549940x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 00.49530956848030017
RT_ICON0x55a3c0x468Device independent bitmap graphic, 16 x 32 x 32, image size 00.7207446808510638
RT_GROUP_ICON0x55ea40x68data0.7019230769230769
RT_MANIFEST0x55f0c0x50dXML 1.0 document, ASCII text0.4694508894044857
DLLImport
USER32.dllCreateWindowExW, ShutdownBlockReasonCreate, MsgWaitForMultipleObjects, ShowWindow, DestroyWindow, RegisterClassW, DefWindowProcW, PeekMessageW, DispatchMessageW, TranslateMessage, PostMessageW, GetMessageW, MessageBoxW, MessageBoxA, SystemParametersInfoW, DestroyIcon, SetWindowLongPtrW, GetWindowLongPtrW, GetClientRect, InvalidateRect, ReleaseDC, GetDC, DrawTextW, GetDialogBaseUnits, EndDialog, DialogBoxIndirectParamW, MoveWindow, SendMessageW
COMCTL32.dll
KERNEL32.dllGetACP, IsValidCodePage, GetStringTypeW, GetFileAttributesExW, SetEnvironmentVariableW, FlushFileBuffers, GetCurrentDirectoryW, LCMapStringW, CompareStringW, FlsFree, GetOEMCP, GetCPInfo, GetModuleHandleW, MulDiv, FormatMessageW, GetLastError, GetModuleFileNameW, LoadLibraryExW, SetDllDirectoryW, CreateSymbolicLinkW, GetProcAddress, GetEnvironmentStringsW, GetCommandLineW, GetEnvironmentVariableW, ExpandEnvironmentStringsW, DeleteFileW, FindClose, FindFirstFileW, FindNextFileW, GetDriveTypeW, RemoveDirectoryW, GetTempPathW, CloseHandle, QueryPerformanceCounter, QueryPerformanceFrequency, WaitForSingleObject, Sleep, GetCurrentProcess, TerminateProcess, GetExitCodeProcess, CreateProcessW, GetStartupInfoW, FreeLibrary, LocalFree, SetConsoleCtrlHandler, K32EnumProcessModules, K32GetModuleFileNameExW, CreateFileW, FindFirstFileExW, GetFinalPathNameByHandleW, MultiByteToWideChar, WideCharToMultiByte, FlsSetValue, FreeEnvironmentStringsW, GetProcessHeap, GetTimeZoneInformation, HeapSize, HeapReAlloc, WriteConsoleW, SetEndOfFile, CreateDirectoryW, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsProcessorFeaturePresent, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, IsDebuggerPresent, RtlUnwindEx, SetLastError, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, EncodePointer, RaiseException, RtlPcToFileHeader, GetCommandLineA, GetFileInformationByHandle, GetFileType, PeekNamedPipe, SystemTimeToTzSpecificLocalTime, FileTimeToSystemTime, ReadFile, GetFullPathNameW, SetStdHandle, GetStdHandle, WriteFile, ExitProcess, GetModuleHandleExW, HeapFree, GetConsoleMode, ReadConsoleW, SetFilePointerEx, GetConsoleOutputCP, GetFileSizeEx, HeapAlloc, FlsAlloc, FlsGetValue
ADVAPI32.dllOpenProcessToken, GetTokenInformation, ConvertStringSecurityDescriptorToSecurityDescriptorW, ConvertSidToStringSidW
GDI32.dllSelectObject, DeleteObject, CreateFontIndirectW
No network behavior found

Click to jump to process

Click to jump to process

Target ID:0
Start time:08:14:21
Start date:26/12/2024
Path:C:\Users\user\Desktop\j1gw88aHdL.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\j1gw88aHdL.exe"
Imagebase:0x7ff7d4bf0000
File size:17'226'969 bytes
MD5 hash:FD682A2C1ED42403A8E943010F660F79
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

Reset < >

    Execution Graph

    Execution Coverage:5.2%
    Dynamic/Decrypted Code Coverage:0%
    Signature Coverage:20.2%
    Total number of Nodes:2000
    Total number of Limit Nodes:26
    execution_graph 16248 7ff7d4c00adc 16249 7ff7d4c00b0c 16248->16249 16252 7ff7d4c0082c 16249->16252 16251 7ff7d4c00b2a 16253 7ff7d4c0084c 16252->16253 16258 7ff7d4c00879 16252->16258 16254 7ff7d4c00856 16253->16254 16255 7ff7d4c00881 16253->16255 16253->16258 16256 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 16254->16256 16259 7ff7d4c0076c 16255->16259 16256->16258 16258->16251 16266 7ff7d4c0546c EnterCriticalSection 16259->16266 16035 7ff7d4c09961 16047 7ff7d4c0a3d8 16035->16047 16052 7ff7d4c0b150 GetLastError 16047->16052 16053 7ff7d4c0b191 FlsSetValue 16052->16053 16054 7ff7d4c0b174 FlsGetValue 16052->16054 16056 7ff7d4c0b1a3 16053->16056 16071 7ff7d4c0b181 SetLastError 16053->16071 16055 7ff7d4c0b18b 16054->16055 16054->16071 16055->16053 16083 7ff7d4c0eb98 16056->16083 16059 7ff7d4c0b1b2 16062 7ff7d4c0b1d0 FlsSetValue 16059->16062 16063 7ff7d4c0b1c0 FlsSetValue 16059->16063 16060 7ff7d4c0a3e1 16074 7ff7d4c0a504 16060->16074 16061 7ff7d4c0b21d 16064 7ff7d4c0a504 __CxxCallCatchBlock 38 API calls 16061->16064 16067 7ff7d4c0b1dc FlsSetValue 16062->16067 16068 7ff7d4c0b1ee 16062->16068 16066 7ff7d4c0b1c9 16063->16066 16065 7ff7d4c0b222 16064->16065 16090 7ff7d4c0a948 16066->16090 16067->16066 16096 7ff7d4c0aef4 16068->16096 16071->16060 16071->16061 16144 7ff7d4c13650 16074->16144 16088 7ff7d4c0eba9 _get_daylight 16083->16088 16084 7ff7d4c0ebfa 16104 7ff7d4c04f08 16084->16104 16085 7ff7d4c0ebde HeapAlloc 16087 7ff7d4c0ebf8 16085->16087 16085->16088 16087->16059 16088->16084 16088->16085 16101 7ff7d4c13590 16088->16101 16091 7ff7d4c0a94d HeapFree 16090->16091 16092 7ff7d4c0a97c 16090->16092 16091->16092 16093 7ff7d4c0a968 GetLastError 16091->16093 16092->16071 16094 7ff7d4c0a975 Concurrency::details::SchedulerProxy::DeleteThis 16093->16094 16095 7ff7d4c04f08 _get_daylight 9 API calls 16094->16095 16095->16092 16130 7ff7d4c0adcc 16096->16130 16107 7ff7d4c135d0 16101->16107 16113 7ff7d4c0b2c8 GetLastError 16104->16113 16106 7ff7d4c04f11 16106->16087 16112 7ff7d4c102d8 EnterCriticalSection 16107->16112 16114 7ff7d4c0b309 FlsSetValue 16113->16114 16119 7ff7d4c0b2ec 16113->16119 16115 7ff7d4c0b31b 16114->16115 16118 7ff7d4c0b2f9 16114->16118 16117 7ff7d4c0eb98 _get_daylight 5 API calls 16115->16117 16116 7ff7d4c0b375 SetLastError 16116->16106 16120 7ff7d4c0b32a 16117->16120 16118->16116 16119->16114 16119->16118 16121 7ff7d4c0b348 FlsSetValue 16120->16121 16122 7ff7d4c0b338 FlsSetValue 16120->16122 16123 7ff7d4c0b354 FlsSetValue 16121->16123 16124 7ff7d4c0b366 16121->16124 16125 7ff7d4c0b341 16122->16125 16123->16125 16126 7ff7d4c0aef4 _get_daylight 5 API calls 16124->16126 16127 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 5 API calls 16125->16127 16128 7ff7d4c0b36e 16126->16128 16127->16118 16129 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 5 API calls 16128->16129 16129->16116 16142 7ff7d4c102d8 EnterCriticalSection 16130->16142 16178 7ff7d4c13608 16144->16178 16183 7ff7d4c102d8 EnterCriticalSection 16178->16183 19151 7ff7d4c0f98c 19152 7ff7d4c0fb7e 19151->19152 19154 7ff7d4c0f9ce _isindst 19151->19154 19153 7ff7d4c04f08 _get_daylight 11 API calls 19152->19153 19171 7ff7d4c0fb6e 19153->19171 19154->19152 19157 7ff7d4c0fa4e _isindst 19154->19157 19155 7ff7d4bfc550 _log10_special 8 API calls 19156 7ff7d4c0fb99 19155->19156 19172 7ff7d4c16194 19157->19172 19162 7ff7d4c0fbaa 19164 7ff7d4c0a900 _isindst 17 API calls 19162->19164 19166 7ff7d4c0fbbe 19164->19166 19169 7ff7d4c0faab 19169->19171 19197 7ff7d4c161d8 19169->19197 19171->19155 19173 7ff7d4c0fa6c 19172->19173 19174 7ff7d4c161a3 19172->19174 19179 7ff7d4c15598 19173->19179 19204 7ff7d4c102d8 EnterCriticalSection 19174->19204 19180 7ff7d4c0fa81 19179->19180 19181 7ff7d4c155a1 19179->19181 19180->19162 19185 7ff7d4c155c8 19180->19185 19182 7ff7d4c04f08 _get_daylight 11 API calls 19181->19182 19183 7ff7d4c155a6 19182->19183 19184 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 19183->19184 19184->19180 19186 7ff7d4c0fa92 19185->19186 19187 7ff7d4c155d1 19185->19187 19186->19162 19191 7ff7d4c155f8 19186->19191 19188 7ff7d4c04f08 _get_daylight 11 API calls 19187->19188 19189 7ff7d4c155d6 19188->19189 19190 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 19189->19190 19190->19186 19192 7ff7d4c0faa3 19191->19192 19193 7ff7d4c15601 19191->19193 19192->19162 19192->19169 19194 7ff7d4c04f08 _get_daylight 11 API calls 19193->19194 19195 7ff7d4c15606 19194->19195 19196 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 19195->19196 19196->19192 19205 7ff7d4c102d8 EnterCriticalSection 19197->19205 18966 7ff7d4c1adfe 18967 7ff7d4c1ae0d 18966->18967 18969 7ff7d4c1ae17 18966->18969 18970 7ff7d4c10338 LeaveCriticalSection 18967->18970 18971 7ff7d4c05410 18972 7ff7d4c0541b 18971->18972 18980 7ff7d4c0f2a4 18972->18980 18993 7ff7d4c102d8 EnterCriticalSection 18980->18993 19401 7ff7d4c116b0 19412 7ff7d4c173e4 19401->19412 19413 7ff7d4c173f1 19412->19413 19414 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19413->19414 19415 7ff7d4c1740d 19413->19415 19414->19413 19416 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19415->19416 19417 7ff7d4c116b9 19415->19417 19416->19415 19418 7ff7d4c102d8 EnterCriticalSection 19417->19418 19240 7ff7d4c0c520 19251 7ff7d4c102d8 EnterCriticalSection 19240->19251 19455 7ff7d4c108c8 19456 7ff7d4c108ec 19455->19456 19459 7ff7d4c108fc 19455->19459 19457 7ff7d4c04f08 _get_daylight 11 API calls 19456->19457 19480 7ff7d4c108f1 19457->19480 19458 7ff7d4c10bdc 19460 7ff7d4c04f08 _get_daylight 11 API calls 19458->19460 19459->19458 19461 7ff7d4c1091e 19459->19461 19462 7ff7d4c10be1 19460->19462 19463 7ff7d4c1093f 19461->19463 19586 7ff7d4c10f84 19461->19586 19464 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19462->19464 19466 7ff7d4c109b1 19463->19466 19468 7ff7d4c10965 19463->19468 19472 7ff7d4c109a5 19463->19472 19464->19480 19470 7ff7d4c0eb98 _get_daylight 11 API calls 19466->19470 19485 7ff7d4c10974 19466->19485 19467 7ff7d4c10a5e 19479 7ff7d4c10a7b 19467->19479 19486 7ff7d4c10acd 19467->19486 19601 7ff7d4c096c0 19468->19601 19473 7ff7d4c109c7 19470->19473 19472->19467 19472->19485 19607 7ff7d4c1712c 19472->19607 19476 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19473->19476 19475 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19475->19480 19481 7ff7d4c109d5 19476->19481 19477 7ff7d4c1098d 19477->19472 19484 7ff7d4c10f84 45 API calls 19477->19484 19478 7ff7d4c1096f 19482 7ff7d4c04f08 _get_daylight 11 API calls 19478->19482 19483 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19479->19483 19481->19472 19481->19485 19489 7ff7d4c0eb98 _get_daylight 11 API calls 19481->19489 19482->19485 19487 7ff7d4c10a84 19483->19487 19484->19472 19485->19475 19486->19485 19488 7ff7d4c133dc 40 API calls 19486->19488 19495 7ff7d4c10a89 19487->19495 19643 7ff7d4c133dc 19487->19643 19490 7ff7d4c10b0a 19488->19490 19492 7ff7d4c109f7 19489->19492 19493 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19490->19493 19498 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19492->19498 19494 7ff7d4c10b14 19493->19494 19494->19485 19494->19495 19496 7ff7d4c10bd0 19495->19496 19501 7ff7d4c0eb98 _get_daylight 11 API calls 19495->19501 19500 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19496->19500 19497 7ff7d4c10ab5 19499 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19497->19499 19498->19472 19499->19495 19500->19480 19502 7ff7d4c10b58 19501->19502 19503 7ff7d4c10b69 19502->19503 19504 7ff7d4c10b60 19502->19504 19506 7ff7d4c0a4a4 __std_exception_copy 37 API calls 19503->19506 19505 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19504->19505 19507 7ff7d4c10b67 19505->19507 19508 7ff7d4c10b78 19506->19508 19513 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19507->19513 19509 7ff7d4c10c0b 19508->19509 19510 7ff7d4c10b80 19508->19510 19512 7ff7d4c0a900 _isindst 17 API calls 19509->19512 19652 7ff7d4c17244 19510->19652 19515 7ff7d4c10c1f 19512->19515 19513->19480 19518 7ff7d4c10c48 19515->19518 19526 7ff7d4c10c58 19515->19526 19516 7ff7d4c10ba7 19519 7ff7d4c04f08 _get_daylight 11 API calls 19516->19519 19517 7ff7d4c10bc8 19521 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19517->19521 19520 7ff7d4c04f08 _get_daylight 11 API calls 19518->19520 19522 7ff7d4c10bac 19519->19522 19523 7ff7d4c10c4d 19520->19523 19521->19496 19524 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19522->19524 19524->19507 19525 7ff7d4c10f3b 19527 7ff7d4c04f08 _get_daylight 11 API calls 19525->19527 19526->19525 19528 7ff7d4c10c7a 19526->19528 19530 7ff7d4c10f40 19527->19530 19529 7ff7d4c10c97 19528->19529 19671 7ff7d4c1106c 19528->19671 19533 7ff7d4c10d0b 19529->19533 19535 7ff7d4c10cbf 19529->19535 19539 7ff7d4c10cff 19529->19539 19532 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19530->19532 19532->19523 19537 7ff7d4c10d33 19533->19537 19540 7ff7d4c0eb98 _get_daylight 11 API calls 19533->19540 19555 7ff7d4c10cce 19533->19555 19534 7ff7d4c10dbe 19548 7ff7d4c10ddb 19534->19548 19556 7ff7d4c10e2e 19534->19556 19686 7ff7d4c096fc 19535->19686 19537->19539 19542 7ff7d4c0eb98 _get_daylight 11 API calls 19537->19542 19537->19555 19539->19534 19539->19555 19692 7ff7d4c16fec 19539->19692 19544 7ff7d4c10d25 19540->19544 19547 7ff7d4c10d55 19542->19547 19543 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19543->19523 19549 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19544->19549 19545 7ff7d4c10ce7 19545->19539 19554 7ff7d4c1106c 45 API calls 19545->19554 19546 7ff7d4c10cc9 19550 7ff7d4c04f08 _get_daylight 11 API calls 19546->19550 19551 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19547->19551 19552 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19548->19552 19549->19537 19550->19555 19551->19539 19553 7ff7d4c10de4 19552->19553 19560 7ff7d4c133dc 40 API calls 19553->19560 19566 7ff7d4c10dea 19553->19566 19554->19539 19555->19543 19556->19555 19557 7ff7d4c133dc 40 API calls 19556->19557 19558 7ff7d4c10e6c 19557->19558 19559 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19558->19559 19561 7ff7d4c10e76 19559->19561 19563 7ff7d4c10e16 19560->19563 19561->19555 19561->19566 19562 7ff7d4c10f2f 19565 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19562->19565 19564 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19563->19564 19564->19566 19565->19523 19566->19562 19567 7ff7d4c0eb98 _get_daylight 11 API calls 19566->19567 19568 7ff7d4c10ebb 19567->19568 19569 7ff7d4c10ecc 19568->19569 19570 7ff7d4c10ec3 19568->19570 19572 7ff7d4c10474 37 API calls 19569->19572 19571 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19570->19571 19574 7ff7d4c10eca 19571->19574 19573 7ff7d4c10eda 19572->19573 19575 7ff7d4c10f6f 19573->19575 19576 7ff7d4c10ee2 SetEnvironmentVariableW 19573->19576 19580 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19574->19580 19579 7ff7d4c0a900 _isindst 17 API calls 19575->19579 19577 7ff7d4c10f27 19576->19577 19578 7ff7d4c10f06 19576->19578 19583 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19577->19583 19581 7ff7d4c04f08 _get_daylight 11 API calls 19578->19581 19582 7ff7d4c10f83 19579->19582 19580->19523 19584 7ff7d4c10f0b 19581->19584 19583->19562 19585 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19584->19585 19585->19574 19587 7ff7d4c10fb9 19586->19587 19593 7ff7d4c10fa1 19586->19593 19588 7ff7d4c0eb98 _get_daylight 11 API calls 19587->19588 19596 7ff7d4c10fdd 19588->19596 19589 7ff7d4c1103e 19591 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19589->19591 19590 7ff7d4c0a504 __CxxCallCatchBlock 45 API calls 19592 7ff7d4c11068 19590->19592 19591->19593 19593->19463 19594 7ff7d4c0eb98 _get_daylight 11 API calls 19594->19596 19595 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19595->19596 19596->19589 19596->19594 19596->19595 19597 7ff7d4c0a4a4 __std_exception_copy 37 API calls 19596->19597 19598 7ff7d4c1104d 19596->19598 19600 7ff7d4c11062 19596->19600 19597->19596 19599 7ff7d4c0a900 _isindst 17 API calls 19598->19599 19599->19600 19600->19590 19602 7ff7d4c096d0 19601->19602 19604 7ff7d4c096d9 19601->19604 19602->19604 19716 7ff7d4c09198 19602->19716 19604->19477 19604->19478 19608 7ff7d4c17139 19607->19608 19609 7ff7d4c16254 19607->19609 19611 7ff7d4c04f4c 45 API calls 19608->19611 19610 7ff7d4c16261 19609->19610 19615 7ff7d4c16297 19609->19615 19614 7ff7d4c04f08 _get_daylight 11 API calls 19610->19614 19631 7ff7d4c16208 19610->19631 19612 7ff7d4c1716d 19611->19612 19616 7ff7d4c17172 19612->19616 19621 7ff7d4c17183 19612->19621 19625 7ff7d4c1719a 19612->19625 19613 7ff7d4c162c1 19617 7ff7d4c04f08 _get_daylight 11 API calls 19613->19617 19618 7ff7d4c1626b 19614->19618 19615->19613 19620 7ff7d4c162e6 19615->19620 19616->19472 19622 7ff7d4c162c6 19617->19622 19619 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 19618->19619 19624 7ff7d4c16276 19619->19624 19630 7ff7d4c04f4c 45 API calls 19620->19630 19634 7ff7d4c162d1 19620->19634 19626 7ff7d4c04f08 _get_daylight 11 API calls 19621->19626 19623 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 19622->19623 19623->19634 19624->19472 19628 7ff7d4c171a4 19625->19628 19629 7ff7d4c171b6 19625->19629 19627 7ff7d4c17188 19626->19627 19632 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 19627->19632 19633 7ff7d4c04f08 _get_daylight 11 API calls 19628->19633 19635 7ff7d4c171c7 19629->19635 19636 7ff7d4c171de 19629->19636 19630->19634 19631->19472 19632->19616 19637 7ff7d4c171a9 19633->19637 19634->19472 19948 7ff7d4c162a4 19635->19948 19957 7ff7d4c18f4c 19636->19957 19640 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 19637->19640 19640->19616 19642 7ff7d4c04f08 _get_daylight 11 API calls 19642->19616 19644 7ff7d4c1341b 19643->19644 19645 7ff7d4c133fe 19643->19645 19647 7ff7d4c13425 19644->19647 19997 7ff7d4c17c38 19644->19997 19645->19644 19646 7ff7d4c1340c 19645->19646 19648 7ff7d4c04f08 _get_daylight 11 API calls 19646->19648 20004 7ff7d4c17c74 19647->20004 19651 7ff7d4c13411 __scrt_get_show_window_mode 19648->19651 19651->19497 19653 7ff7d4c04f4c 45 API calls 19652->19653 19654 7ff7d4c172aa 19653->19654 19655 7ff7d4c172b8 19654->19655 20016 7ff7d4c0ef24 19654->20016 20019 7ff7d4c054ac 19655->20019 19659 7ff7d4c173a4 19662 7ff7d4c173b5 19659->19662 19664 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19659->19664 19660 7ff7d4c04f4c 45 API calls 19661 7ff7d4c17327 19660->19661 19666 7ff7d4c0ef24 5 API calls 19661->19666 19667 7ff7d4c17330 19661->19667 19663 7ff7d4c10ba3 19662->19663 19665 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19662->19665 19663->19516 19663->19517 19664->19662 19665->19663 19666->19667 19668 7ff7d4c054ac 14 API calls 19667->19668 19669 7ff7d4c1738b 19668->19669 19669->19659 19670 7ff7d4c17393 SetEnvironmentVariableW 19669->19670 19670->19659 19672 7ff7d4c110ac 19671->19672 19673 7ff7d4c1108f 19671->19673 19674 7ff7d4c0eb98 _get_daylight 11 API calls 19672->19674 19673->19529 19680 7ff7d4c110d0 19674->19680 19675 7ff7d4c11131 19677 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19675->19677 19676 7ff7d4c0a504 __CxxCallCatchBlock 45 API calls 19678 7ff7d4c1115a 19676->19678 19677->19673 19679 7ff7d4c0eb98 _get_daylight 11 API calls 19679->19680 19680->19675 19680->19679 19681 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19680->19681 19682 7ff7d4c10474 37 API calls 19680->19682 19683 7ff7d4c11140 19680->19683 19685 7ff7d4c11154 19680->19685 19681->19680 19682->19680 19684 7ff7d4c0a900 _isindst 17 API calls 19683->19684 19684->19685 19685->19676 19687 7ff7d4c0970c 19686->19687 19688 7ff7d4c09715 19686->19688 19687->19688 20041 7ff7d4c0920c 19687->20041 19688->19545 19688->19546 19693 7ff7d4c16ff9 19692->19693 19697 7ff7d4c17026 19692->19697 19694 7ff7d4c16ffe 19693->19694 19693->19697 19695 7ff7d4c04f08 _get_daylight 11 API calls 19694->19695 19698 7ff7d4c17003 19695->19698 19696 7ff7d4c1706a 19699 7ff7d4c04f08 _get_daylight 11 API calls 19696->19699 19697->19696 19700 7ff7d4c17089 19697->19700 19714 7ff7d4c1705e __crtLCMapStringW 19697->19714 19701 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 19698->19701 19702 7ff7d4c1706f 19699->19702 19703 7ff7d4c17093 19700->19703 19704 7ff7d4c170a5 19700->19704 19705 7ff7d4c1700e 19701->19705 19706 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 19702->19706 19707 7ff7d4c04f08 _get_daylight 11 API calls 19703->19707 19708 7ff7d4c04f4c 45 API calls 19704->19708 19705->19539 19706->19714 19710 7ff7d4c17098 19707->19710 19709 7ff7d4c170b2 19708->19709 19709->19714 20088 7ff7d4c18b08 19709->20088 19711 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 19710->19711 19711->19714 19714->19539 19715 7ff7d4c04f08 _get_daylight 11 API calls 19715->19714 19717 7ff7d4c091ad 19716->19717 19718 7ff7d4c091b1 19716->19718 19717->19604 19731 7ff7d4c094ec 19717->19731 19739 7ff7d4c125f0 19718->19739 19723 7ff7d4c091cf 19765 7ff7d4c0927c 19723->19765 19724 7ff7d4c091c3 19725 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19724->19725 19725->19717 19728 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19729 7ff7d4c091f6 19728->19729 19730 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19729->19730 19730->19717 19732 7ff7d4c09515 19731->19732 19734 7ff7d4c0952e 19731->19734 19732->19604 19733 7ff7d4c107e8 WideCharToMultiByte 19733->19734 19734->19732 19734->19733 19735 7ff7d4c0eb98 _get_daylight 11 API calls 19734->19735 19736 7ff7d4c095be 19734->19736 19738 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19734->19738 19735->19734 19737 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19736->19737 19737->19732 19738->19734 19740 7ff7d4c091b6 19739->19740 19741 7ff7d4c125fd 19739->19741 19745 7ff7d4c1292c GetEnvironmentStringsW 19740->19745 19784 7ff7d4c0b224 19741->19784 19746 7ff7d4c1295c 19745->19746 19747 7ff7d4c091bb 19745->19747 19748 7ff7d4c107e8 WideCharToMultiByte 19746->19748 19747->19723 19747->19724 19749 7ff7d4c129ad 19748->19749 19750 7ff7d4c129b4 FreeEnvironmentStringsW 19749->19750 19751 7ff7d4c0d5fc _fread_nolock 12 API calls 19749->19751 19750->19747 19752 7ff7d4c129c7 19751->19752 19753 7ff7d4c129d8 19752->19753 19754 7ff7d4c129cf 19752->19754 19756 7ff7d4c107e8 WideCharToMultiByte 19753->19756 19755 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19754->19755 19757 7ff7d4c129d6 19755->19757 19758 7ff7d4c129fb 19756->19758 19757->19750 19759 7ff7d4c12a09 19758->19759 19760 7ff7d4c129ff 19758->19760 19761 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19759->19761 19762 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19760->19762 19763 7ff7d4c12a07 FreeEnvironmentStringsW 19761->19763 19762->19763 19763->19747 19766 7ff7d4c092a1 19765->19766 19767 7ff7d4c0eb98 _get_daylight 11 API calls 19766->19767 19779 7ff7d4c092d7 19767->19779 19768 7ff7d4c092df 19769 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19768->19769 19770 7ff7d4c091d7 19769->19770 19770->19728 19771 7ff7d4c09352 19772 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19771->19772 19772->19770 19773 7ff7d4c0eb98 _get_daylight 11 API calls 19773->19779 19774 7ff7d4c09341 19942 7ff7d4c094a8 19774->19942 19775 7ff7d4c0a4a4 __std_exception_copy 37 API calls 19775->19779 19778 7ff7d4c09377 19781 7ff7d4c0a900 _isindst 17 API calls 19778->19781 19779->19768 19779->19771 19779->19773 19779->19774 19779->19775 19779->19778 19782 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19779->19782 19780 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19780->19768 19783 7ff7d4c0938a 19781->19783 19782->19779 19785 7ff7d4c0b250 FlsSetValue 19784->19785 19786 7ff7d4c0b235 FlsGetValue 19784->19786 19787 7ff7d4c0b25d 19785->19787 19788 7ff7d4c0b242 19785->19788 19786->19788 19789 7ff7d4c0b24a 19786->19789 19791 7ff7d4c0eb98 _get_daylight 11 API calls 19787->19791 19790 7ff7d4c0a504 __CxxCallCatchBlock 45 API calls 19788->19790 19792 7ff7d4c0b248 19788->19792 19789->19785 19793 7ff7d4c0b2c5 19790->19793 19794 7ff7d4c0b26c 19791->19794 19804 7ff7d4c122c4 19792->19804 19795 7ff7d4c0b28a FlsSetValue 19794->19795 19796 7ff7d4c0b27a FlsSetValue 19794->19796 19798 7ff7d4c0b2a8 19795->19798 19799 7ff7d4c0b296 FlsSetValue 19795->19799 19797 7ff7d4c0b283 19796->19797 19800 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19797->19800 19801 7ff7d4c0aef4 _get_daylight 11 API calls 19798->19801 19799->19797 19800->19788 19802 7ff7d4c0b2b0 19801->19802 19803 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19802->19803 19803->19792 19827 7ff7d4c12534 19804->19827 19806 7ff7d4c122f9 19842 7ff7d4c11fc4 19806->19842 19809 7ff7d4c0d5fc _fread_nolock 12 API calls 19810 7ff7d4c12327 19809->19810 19811 7ff7d4c1232f 19810->19811 19813 7ff7d4c1233e 19810->19813 19812 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19811->19812 19824 7ff7d4c12316 19812->19824 19813->19813 19849 7ff7d4c1266c 19813->19849 19816 7ff7d4c1243a 19817 7ff7d4c04f08 _get_daylight 11 API calls 19816->19817 19818 7ff7d4c1243f 19817->19818 19820 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19818->19820 19819 7ff7d4c12495 19822 7ff7d4c124fc 19819->19822 19860 7ff7d4c11df4 19819->19860 19820->19824 19821 7ff7d4c12454 19821->19819 19825 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19821->19825 19823 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19822->19823 19823->19824 19824->19740 19825->19819 19828 7ff7d4c12557 19827->19828 19831 7ff7d4c12561 19828->19831 19875 7ff7d4c102d8 EnterCriticalSection 19828->19875 19830 7ff7d4c125d3 19830->19806 19831->19830 19834 7ff7d4c0a504 __CxxCallCatchBlock 45 API calls 19831->19834 19835 7ff7d4c125eb 19834->19835 19838 7ff7d4c12642 19835->19838 19839 7ff7d4c0b224 50 API calls 19835->19839 19838->19806 19840 7ff7d4c1262c 19839->19840 19841 7ff7d4c122c4 65 API calls 19840->19841 19841->19838 19843 7ff7d4c04f4c 45 API calls 19842->19843 19844 7ff7d4c11fd8 19843->19844 19845 7ff7d4c11fe4 GetOEMCP 19844->19845 19846 7ff7d4c11ff6 19844->19846 19847 7ff7d4c1200b 19845->19847 19846->19847 19848 7ff7d4c11ffb GetACP 19846->19848 19847->19809 19847->19824 19848->19847 19850 7ff7d4c11fc4 47 API calls 19849->19850 19851 7ff7d4c12699 19850->19851 19852 7ff7d4c127ef 19851->19852 19854 7ff7d4c126d6 IsValidCodePage 19851->19854 19859 7ff7d4c126f0 __scrt_get_show_window_mode 19851->19859 19853 7ff7d4bfc550 _log10_special 8 API calls 19852->19853 19855 7ff7d4c12431 19853->19855 19854->19852 19856 7ff7d4c126e7 19854->19856 19855->19816 19855->19821 19857 7ff7d4c12716 GetCPInfo 19856->19857 19856->19859 19857->19852 19857->19859 19876 7ff7d4c120dc 19859->19876 19941 7ff7d4c102d8 EnterCriticalSection 19860->19941 19877 7ff7d4c12119 GetCPInfo 19876->19877 19878 7ff7d4c1220f 19876->19878 19877->19878 19883 7ff7d4c1212c 19877->19883 19879 7ff7d4bfc550 _log10_special 8 API calls 19878->19879 19880 7ff7d4c122ae 19879->19880 19880->19852 19881 7ff7d4c12e40 48 API calls 19882 7ff7d4c121a3 19881->19882 19887 7ff7d4c17b84 19882->19887 19883->19881 19886 7ff7d4c17b84 54 API calls 19886->19878 19888 7ff7d4c04f4c 45 API calls 19887->19888 19889 7ff7d4c17ba9 19888->19889 19892 7ff7d4c17850 19889->19892 19893 7ff7d4c17891 19892->19893 19894 7ff7d4c0f8a0 _fread_nolock MultiByteToWideChar 19893->19894 19897 7ff7d4c178db 19894->19897 19895 7ff7d4c17b59 19896 7ff7d4bfc550 _log10_special 8 API calls 19895->19896 19898 7ff7d4c121d6 19896->19898 19897->19895 19899 7ff7d4c0d5fc _fread_nolock 12 API calls 19897->19899 19900 7ff7d4c17913 19897->19900 19913 7ff7d4c17a11 19897->19913 19898->19886 19899->19900 19902 7ff7d4c0f8a0 _fread_nolock MultiByteToWideChar 19900->19902 19900->19913 19901 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19901->19895 19903 7ff7d4c17986 19902->19903 19903->19913 19923 7ff7d4c0f0e4 19903->19923 19906 7ff7d4c179d1 19909 7ff7d4c0f0e4 __crtLCMapStringW 6 API calls 19906->19909 19906->19913 19907 7ff7d4c17a22 19908 7ff7d4c0d5fc _fread_nolock 12 API calls 19907->19908 19910 7ff7d4c17af4 19907->19910 19912 7ff7d4c17a40 19907->19912 19908->19912 19909->19913 19911 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19910->19911 19910->19913 19911->19913 19912->19913 19914 7ff7d4c0f0e4 __crtLCMapStringW 6 API calls 19912->19914 19913->19895 19913->19901 19915 7ff7d4c17ac0 19914->19915 19915->19910 19916 7ff7d4c17ae0 19915->19916 19917 7ff7d4c17af6 19915->19917 19918 7ff7d4c107e8 WideCharToMultiByte 19916->19918 19919 7ff7d4c107e8 WideCharToMultiByte 19917->19919 19920 7ff7d4c17aee 19918->19920 19919->19920 19920->19910 19921 7ff7d4c17b0e 19920->19921 19921->19913 19922 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19921->19922 19922->19913 19929 7ff7d4c0ed10 19923->19929 19927 7ff7d4c0f193 LCMapStringW 19928 7ff7d4c0f12a 19927->19928 19928->19906 19928->19907 19928->19913 19930 7ff7d4c0ed68 __vcrt_InitializeCriticalSectionEx 19929->19930 19931 7ff7d4c0ed6d 19929->19931 19930->19931 19932 7ff7d4c0ed9d LoadLibraryExW 19930->19932 19933 7ff7d4c0ee92 GetProcAddress 19930->19933 19937 7ff7d4c0edfc LoadLibraryExW 19930->19937 19931->19928 19938 7ff7d4c0f1d0 19931->19938 19934 7ff7d4c0ee72 19932->19934 19935 7ff7d4c0edc2 GetLastError 19932->19935 19933->19931 19934->19933 19936 7ff7d4c0ee89 FreeLibrary 19934->19936 19935->19930 19936->19933 19937->19930 19937->19934 19939 7ff7d4c0ed10 __crtLCMapStringW 5 API calls 19938->19939 19940 7ff7d4c0f1fe __crtLCMapStringW 19939->19940 19940->19927 19943 7ff7d4c09349 19942->19943 19944 7ff7d4c094ad 19942->19944 19943->19780 19945 7ff7d4c094d6 19944->19945 19946 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19944->19946 19947 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19945->19947 19946->19944 19947->19943 19949 7ff7d4c162d8 19948->19949 19950 7ff7d4c162c1 19948->19950 19949->19950 19952 7ff7d4c162e6 19949->19952 19951 7ff7d4c04f08 _get_daylight 11 API calls 19950->19951 19953 7ff7d4c162c6 19951->19953 19955 7ff7d4c04f4c 45 API calls 19952->19955 19956 7ff7d4c162d1 19952->19956 19954 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 19953->19954 19954->19956 19955->19956 19956->19616 19958 7ff7d4c04f4c 45 API calls 19957->19958 19959 7ff7d4c18f71 19958->19959 19962 7ff7d4c18bc8 19959->19962 19964 7ff7d4c18c16 19962->19964 19963 7ff7d4bfc550 _log10_special 8 API calls 19965 7ff7d4c17205 19963->19965 19966 7ff7d4c18c9d 19964->19966 19968 7ff7d4c18c88 GetCPInfo 19964->19968 19989 7ff7d4c18ca1 19964->19989 19965->19616 19965->19642 19967 7ff7d4c0f8a0 _fread_nolock MultiByteToWideChar 19966->19967 19966->19989 19969 7ff7d4c18d35 19967->19969 19968->19966 19968->19989 19970 7ff7d4c18d6c 19969->19970 19971 7ff7d4c0d5fc _fread_nolock 12 API calls 19969->19971 19969->19989 19972 7ff7d4c0f8a0 _fread_nolock MultiByteToWideChar 19970->19972 19970->19989 19971->19970 19973 7ff7d4c18dda 19972->19973 19974 7ff7d4c18ebc 19973->19974 19975 7ff7d4c0f8a0 _fread_nolock MultiByteToWideChar 19973->19975 19976 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19974->19976 19974->19989 19977 7ff7d4c18e00 19975->19977 19976->19989 19977->19974 19978 7ff7d4c0d5fc _fread_nolock 12 API calls 19977->19978 19979 7ff7d4c18e2d 19977->19979 19978->19979 19979->19974 19980 7ff7d4c0f8a0 _fread_nolock MultiByteToWideChar 19979->19980 19981 7ff7d4c18ea4 19980->19981 19982 7ff7d4c18eaa 19981->19982 19983 7ff7d4c18ec4 19981->19983 19982->19974 19985 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19982->19985 19991 7ff7d4c0ef68 19983->19991 19985->19974 19987 7ff7d4c18f03 19987->19989 19990 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19987->19990 19988 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19988->19987 19989->19963 19990->19989 19992 7ff7d4c0ed10 __crtLCMapStringW 5 API calls 19991->19992 19993 7ff7d4c0efa6 19992->19993 19994 7ff7d4c0efae 19993->19994 19995 7ff7d4c0f1d0 __crtLCMapStringW 5 API calls 19993->19995 19994->19987 19994->19988 19996 7ff7d4c0f017 CompareStringW 19995->19996 19996->19994 19998 7ff7d4c17c5a HeapSize 19997->19998 19999 7ff7d4c17c41 19997->19999 20000 7ff7d4c04f08 _get_daylight 11 API calls 19999->20000 20001 7ff7d4c17c46 20000->20001 20002 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 20001->20002 20003 7ff7d4c17c51 20002->20003 20003->19647 20005 7ff7d4c17c89 20004->20005 20006 7ff7d4c17c93 20004->20006 20007 7ff7d4c0d5fc _fread_nolock 12 API calls 20005->20007 20008 7ff7d4c17c98 20006->20008 20014 7ff7d4c17c9f _get_daylight 20006->20014 20013 7ff7d4c17c91 20007->20013 20011 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20008->20011 20009 7ff7d4c17cd2 HeapReAlloc 20009->20013 20009->20014 20010 7ff7d4c17ca5 20012 7ff7d4c04f08 _get_daylight 11 API calls 20010->20012 20011->20013 20012->20013 20013->19651 20014->20009 20014->20010 20015 7ff7d4c13590 _get_daylight 2 API calls 20014->20015 20015->20014 20017 7ff7d4c0ed10 __crtLCMapStringW 5 API calls 20016->20017 20018 7ff7d4c0ef44 20017->20018 20018->19655 20020 7ff7d4c054d6 20019->20020 20021 7ff7d4c054fa 20019->20021 20024 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20020->20024 20040 7ff7d4c054e5 20020->20040 20022 7ff7d4c05554 20021->20022 20025 7ff7d4c054ff 20021->20025 20023 7ff7d4c0f8a0 _fread_nolock MultiByteToWideChar 20022->20023 20032 7ff7d4c05570 20023->20032 20024->20040 20026 7ff7d4c05514 20025->20026 20027 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20025->20027 20025->20040 20028 7ff7d4c0d5fc _fread_nolock 12 API calls 20026->20028 20027->20026 20028->20040 20029 7ff7d4c05577 GetLastError 20031 7ff7d4c04e7c _fread_nolock 11 API calls 20029->20031 20030 7ff7d4c055b2 20034 7ff7d4c0f8a0 _fread_nolock MultiByteToWideChar 20030->20034 20030->20040 20035 7ff7d4c05584 20031->20035 20032->20029 20032->20030 20033 7ff7d4c055a5 20032->20033 20036 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20032->20036 20037 7ff7d4c0d5fc _fread_nolock 12 API calls 20033->20037 20038 7ff7d4c055f6 20034->20038 20039 7ff7d4c04f08 _get_daylight 11 API calls 20035->20039 20036->20033 20037->20030 20038->20029 20038->20040 20039->20040 20040->19659 20040->19660 20042 7ff7d4c09225 20041->20042 20050 7ff7d4c09221 20041->20050 20062 7ff7d4c12a3c GetEnvironmentStringsW 20042->20062 20045 7ff7d4c0923e 20069 7ff7d4c0938c 20045->20069 20046 7ff7d4c09232 20048 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20046->20048 20048->20050 20050->19688 20054 7ff7d4c095cc 20050->20054 20051 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20052 7ff7d4c09265 20051->20052 20053 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20052->20053 20053->20050 20055 7ff7d4c095ef 20054->20055 20056 7ff7d4c09606 20054->20056 20055->19688 20056->20055 20057 7ff7d4c0eb98 _get_daylight 11 API calls 20056->20057 20058 7ff7d4c0967a 20056->20058 20059 7ff7d4c0f8a0 MultiByteToWideChar _fread_nolock 20056->20059 20061 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20056->20061 20057->20056 20060 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20058->20060 20059->20056 20060->20055 20061->20056 20063 7ff7d4c12a60 20062->20063 20064 7ff7d4c0922a 20062->20064 20065 7ff7d4c0d5fc _fread_nolock 12 API calls 20063->20065 20064->20045 20064->20046 20066 7ff7d4c12a97 memcpy_s 20065->20066 20067 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20066->20067 20068 7ff7d4c12ab7 FreeEnvironmentStringsW 20067->20068 20068->20064 20070 7ff7d4c093b4 20069->20070 20071 7ff7d4c0eb98 _get_daylight 11 API calls 20070->20071 20082 7ff7d4c093ef 20071->20082 20072 7ff7d4c093f7 20073 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20072->20073 20074 7ff7d4c09246 20073->20074 20074->20051 20075 7ff7d4c09471 20076 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20075->20076 20076->20074 20077 7ff7d4c0eb98 _get_daylight 11 API calls 20077->20082 20078 7ff7d4c09460 20080 7ff7d4c094a8 11 API calls 20078->20080 20079 7ff7d4c10474 37 API calls 20079->20082 20081 7ff7d4c09468 20080->20081 20084 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20081->20084 20082->20072 20082->20075 20082->20077 20082->20078 20082->20079 20083 7ff7d4c09494 20082->20083 20086 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20082->20086 20085 7ff7d4c0a900 _isindst 17 API calls 20083->20085 20084->20072 20087 7ff7d4c094a6 20085->20087 20086->20082 20089 7ff7d4c18b31 __crtLCMapStringW 20088->20089 20090 7ff7d4c170ee 20089->20090 20091 7ff7d4c0ef68 6 API calls 20089->20091 20090->19714 20090->19715 20091->20090 19050 7ff7d4c0afd0 19051 7ff7d4c0afea 19050->19051 19052 7ff7d4c0afd5 19050->19052 19056 7ff7d4c0aff0 19052->19056 19057 7ff7d4c0b03a 19056->19057 19058 7ff7d4c0b032 19056->19058 19060 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19057->19060 19059 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19058->19059 19059->19057 19061 7ff7d4c0b047 19060->19061 19062 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19061->19062 19063 7ff7d4c0b054 19062->19063 19064 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19063->19064 19065 7ff7d4c0b061 19064->19065 19066 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19065->19066 19067 7ff7d4c0b06e 19066->19067 19068 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19067->19068 19069 7ff7d4c0b07b 19068->19069 19070 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19069->19070 19071 7ff7d4c0b088 19070->19071 19072 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19071->19072 19073 7ff7d4c0b095 19072->19073 19074 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19073->19074 19075 7ff7d4c0b0a5 19074->19075 19076 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19075->19076 19077 7ff7d4c0b0b5 19076->19077 19082 7ff7d4c0ae94 19077->19082 19096 7ff7d4c102d8 EnterCriticalSection 19082->19096 19258 7ff7d4c09d50 19261 7ff7d4c09ccc 19258->19261 19268 7ff7d4c102d8 EnterCriticalSection 19261->19268 16267 7ff7d4bfcc3c 16288 7ff7d4bfce0c 16267->16288 16270 7ff7d4bfcd88 16447 7ff7d4bfd12c IsProcessorFeaturePresent 16270->16447 16271 7ff7d4bfcc58 __scrt_acquire_startup_lock 16273 7ff7d4bfcd92 16271->16273 16278 7ff7d4bfcc76 __scrt_release_startup_lock 16271->16278 16274 7ff7d4bfd12c 7 API calls 16273->16274 16276 7ff7d4bfcd9d __CxxCallCatchBlock 16274->16276 16275 7ff7d4bfcc9b 16277 7ff7d4bfcd21 16294 7ff7d4bfd274 16277->16294 16278->16275 16278->16277 16436 7ff7d4c09b2c 16278->16436 16280 7ff7d4bfcd26 16297 7ff7d4bf1000 16280->16297 16285 7ff7d4bfcd49 16285->16276 16443 7ff7d4bfcf90 16285->16443 16289 7ff7d4bfce14 16288->16289 16290 7ff7d4bfce20 __scrt_dllmain_crt_thread_attach 16289->16290 16291 7ff7d4bfce2d 16290->16291 16293 7ff7d4bfcc50 16290->16293 16291->16293 16454 7ff7d4bfd888 16291->16454 16293->16270 16293->16271 16481 7ff7d4c1a4d0 16294->16481 16296 7ff7d4bfd28b GetStartupInfoW 16296->16280 16298 7ff7d4bf1009 16297->16298 16483 7ff7d4c05484 16298->16483 16300 7ff7d4bf37fb 16490 7ff7d4bf36b0 16300->16490 16304 7ff7d4bfc550 _log10_special 8 API calls 16306 7ff7d4bf3ca7 16304->16306 16441 7ff7d4bfd2b8 GetModuleHandleW 16306->16441 16307 7ff7d4bf391b 16562 7ff7d4bf45c0 16307->16562 16308 7ff7d4bf383c 16596 7ff7d4bf1c80 16308->16596 16311 7ff7d4bf385b 16600 7ff7d4bf8830 16311->16600 16314 7ff7d4bf396a 16585 7ff7d4bf2710 16314->16585 16315 7ff7d4bf388e 16325 7ff7d4bf38bb __std_exception_copy 16315->16325 16613 7ff7d4bf89a0 16315->16613 16318 7ff7d4bf395d 16319 7ff7d4bf3984 16318->16319 16320 7ff7d4bf3962 16318->16320 16321 7ff7d4bf1c80 49 API calls 16319->16321 16581 7ff7d4c0004c 16320->16581 16324 7ff7d4bf39a3 16321->16324 16329 7ff7d4bf1950 115 API calls 16324->16329 16326 7ff7d4bf8830 14 API calls 16325->16326 16333 7ff7d4bf38de __std_exception_copy 16325->16333 16326->16333 16328 7ff7d4bf3a0b 16330 7ff7d4bf89a0 40 API calls 16328->16330 16332 7ff7d4bf39ce 16329->16332 16331 7ff7d4bf3a17 16330->16331 16334 7ff7d4bf89a0 40 API calls 16331->16334 16332->16311 16335 7ff7d4bf39de 16332->16335 16339 7ff7d4bf390e __std_exception_copy 16333->16339 16618 7ff7d4bf8940 16333->16618 16336 7ff7d4bf3a23 16334->16336 16337 7ff7d4bf2710 54 API calls 16335->16337 16338 7ff7d4bf89a0 40 API calls 16336->16338 16345 7ff7d4bf3808 __std_exception_copy 16337->16345 16338->16339 16340 7ff7d4bf8830 14 API calls 16339->16340 16341 7ff7d4bf3a3b 16340->16341 16342 7ff7d4bf3b2f 16341->16342 16343 7ff7d4bf3a60 __std_exception_copy 16341->16343 16344 7ff7d4bf2710 54 API calls 16342->16344 16346 7ff7d4bf8940 40 API calls 16343->16346 16351 7ff7d4bf3aab 16343->16351 16344->16345 16345->16304 16346->16351 16347 7ff7d4bf8830 14 API calls 16348 7ff7d4bf3bf4 __std_exception_copy 16347->16348 16349 7ff7d4bf3c46 16348->16349 16350 7ff7d4bf3d41 16348->16350 16352 7ff7d4bf3cd4 16349->16352 16353 7ff7d4bf3c50 16349->16353 16673 7ff7d4bf44e0 16350->16673 16351->16347 16356 7ff7d4bf8830 14 API calls 16352->16356 16625 7ff7d4bf90e0 16353->16625 16361 7ff7d4bf3ce0 16356->16361 16357 7ff7d4bf3d4f 16358 7ff7d4bf3d65 16357->16358 16359 7ff7d4bf3d71 16357->16359 16676 7ff7d4bf4630 16358->16676 16364 7ff7d4bf1c80 49 API calls 16359->16364 16362 7ff7d4bf3c61 16361->16362 16366 7ff7d4bf3ced 16361->16366 16368 7ff7d4bf2710 54 API calls 16362->16368 16377 7ff7d4bf3d2b __std_exception_copy 16364->16377 16365 7ff7d4bf3cb3 16642 7ff7d4bf8660 16365->16642 16369 7ff7d4bf1c80 49 API calls 16366->16369 16368->16345 16372 7ff7d4bf3d0b 16369->16372 16370 7ff7d4bf3dbc 16679 7ff7d4bf9390 16370->16679 16376 7ff7d4bf3d12 16372->16376 16372->16377 16374 7ff7d4bf3cbf 16374->16362 16375 7ff7d4bf3cc8 16375->16377 16380 7ff7d4bf2710 54 API calls 16376->16380 16377->16370 16378 7ff7d4bf3da7 LoadLibraryExW 16377->16378 16378->16370 16379 7ff7d4bf3dcf SetDllDirectoryW 16382 7ff7d4bf3e02 16379->16382 16424 7ff7d4bf3e52 16379->16424 16380->16345 16383 7ff7d4bf8830 14 API calls 16382->16383 16391 7ff7d4bf3e0e __std_exception_copy 16383->16391 16384 7ff7d4bf4000 16386 7ff7d4bf402d 16384->16386 16387 7ff7d4bf400a PostMessageW GetMessageW 16384->16387 16385 7ff7d4bf3f13 16758 7ff7d4bf33c0 16385->16758 16778 7ff7d4bf3360 16386->16778 16387->16386 16394 7ff7d4bf3eea 16391->16394 16399 7ff7d4bf3e46 16391->16399 16392 7ff7d4bf3f23 16777 7ff7d4bf90c0 LocalFree 16392->16777 16398 7ff7d4bf8940 40 API calls 16394->16398 16398->16424 16399->16424 16684 7ff7d4bf6dc0 16399->16684 16404 7ff7d4bf6fc0 FreeLibrary 16406 7ff7d4bf4053 16404->16406 16412 7ff7d4bf3e79 16415 7ff7d4bf3e9a 16412->16415 16427 7ff7d4bf3e7d 16412->16427 16705 7ff7d4bf6e00 16412->16705 16415->16427 16724 7ff7d4bf71b0 16415->16724 16424->16384 16424->16385 16427->16424 16740 7ff7d4bf2a50 16427->16740 16437 7ff7d4c09b43 16436->16437 16438 7ff7d4c09b64 16436->16438 16437->16277 16439 7ff7d4c0a3d8 45 API calls 16438->16439 16440 7ff7d4c09b69 16439->16440 16442 7ff7d4bfd2c9 16441->16442 16442->16285 16444 7ff7d4bfcfa1 16443->16444 16445 7ff7d4bfcd60 16444->16445 16446 7ff7d4bfd888 7 API calls 16444->16446 16445->16275 16446->16445 16448 7ff7d4bfd152 _isindst __scrt_get_show_window_mode 16447->16448 16449 7ff7d4bfd171 RtlCaptureContext RtlLookupFunctionEntry 16448->16449 16450 7ff7d4bfd1d6 __scrt_get_show_window_mode 16449->16450 16451 7ff7d4bfd19a RtlVirtualUnwind 16449->16451 16452 7ff7d4bfd208 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 16450->16452 16451->16450 16453 7ff7d4bfd256 _isindst 16452->16453 16453->16273 16455 7ff7d4bfd890 16454->16455 16456 7ff7d4bfd89a 16454->16456 16460 7ff7d4bfdc24 16455->16460 16456->16293 16461 7ff7d4bfdc33 16460->16461 16462 7ff7d4bfd895 16460->16462 16468 7ff7d4bfde60 16461->16468 16464 7ff7d4bfdc90 16462->16464 16465 7ff7d4bfdcbb 16464->16465 16466 7ff7d4bfdcbf 16465->16466 16467 7ff7d4bfdc9e DeleteCriticalSection 16465->16467 16466->16456 16467->16465 16472 7ff7d4bfdcc8 16468->16472 16473 7ff7d4bfddb2 TlsFree 16472->16473 16478 7ff7d4bfdd0c __vcrt_InitializeCriticalSectionEx 16472->16478 16474 7ff7d4bfdd3a LoadLibraryExW 16476 7ff7d4bfdd5b GetLastError 16474->16476 16477 7ff7d4bfddd9 16474->16477 16475 7ff7d4bfddf9 GetProcAddress 16475->16473 16476->16478 16477->16475 16479 7ff7d4bfddf0 FreeLibrary 16477->16479 16478->16473 16478->16474 16478->16475 16480 7ff7d4bfdd7d LoadLibraryExW 16478->16480 16479->16475 16480->16477 16480->16478 16482 7ff7d4c1a4c0 16481->16482 16482->16296 16482->16482 16484 7ff7d4c0f480 16483->16484 16485 7ff7d4c0f4d3 16484->16485 16487 7ff7d4c0f526 16484->16487 16486 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 16485->16486 16489 7ff7d4c0f4fc 16486->16489 16791 7ff7d4c0f358 16487->16791 16489->16300 16799 7ff7d4bfc850 16490->16799 16493 7ff7d4bf3710 16801 7ff7d4bf9280 FindFirstFileExW 16493->16801 16494 7ff7d4bf36eb GetLastError 16806 7ff7d4bf2c50 16494->16806 16497 7ff7d4bf3706 16501 7ff7d4bfc550 _log10_special 8 API calls 16497->16501 16499 7ff7d4bf3723 16821 7ff7d4bf9300 CreateFileW 16499->16821 16500 7ff7d4bf377d 16832 7ff7d4bf9440 16500->16832 16504 7ff7d4bf37b5 16501->16504 16504->16345 16512 7ff7d4bf1950 16504->16512 16506 7ff7d4bf378b 16506->16497 16509 7ff7d4bf2810 49 API calls 16506->16509 16507 7ff7d4bf3734 16824 7ff7d4bf2810 16507->16824 16508 7ff7d4bf374c __vcrt_InitializeCriticalSectionEx 16508->16500 16509->16497 16513 7ff7d4bf45c0 108 API calls 16512->16513 16514 7ff7d4bf1985 16513->16514 16515 7ff7d4bf1c43 16514->16515 16516 7ff7d4bf7f90 83 API calls 16514->16516 16517 7ff7d4bfc550 _log10_special 8 API calls 16515->16517 16518 7ff7d4bf19cb 16516->16518 16519 7ff7d4bf1c5e 16517->16519 16520 7ff7d4bf1a03 16518->16520 17212 7ff7d4c006d4 16518->17212 16519->16307 16519->16308 16522 7ff7d4c0004c 74 API calls 16520->16522 16522->16515 16523 7ff7d4bf19e5 16524 7ff7d4bf19e9 16523->16524 16525 7ff7d4bf1a08 16523->16525 16526 7ff7d4c04f08 _get_daylight 11 API calls 16524->16526 17231 7ff7d4c0039c 16525->17231 16528 7ff7d4bf19ee 16526->16528 17216 7ff7d4bf2910 16528->17216 16530 7ff7d4bf1a45 16536 7ff7d4bf1a7b 16530->16536 16537 7ff7d4bf1a5c 16530->16537 16531 7ff7d4bf1a26 16533 7ff7d4c04f08 _get_daylight 11 API calls 16531->16533 16534 7ff7d4bf1a2b 16533->16534 16535 7ff7d4bf2910 54 API calls 16534->16535 16535->16520 16539 7ff7d4bf1c80 49 API calls 16536->16539 16538 7ff7d4c04f08 _get_daylight 11 API calls 16537->16538 16540 7ff7d4bf1a61 16538->16540 16541 7ff7d4bf1a92 16539->16541 16543 7ff7d4bf2910 54 API calls 16540->16543 16542 7ff7d4bf1c80 49 API calls 16541->16542 16544 7ff7d4bf1add 16542->16544 16543->16520 16545 7ff7d4c006d4 73 API calls 16544->16545 16546 7ff7d4bf1b01 16545->16546 16547 7ff7d4bf1b35 16546->16547 16548 7ff7d4bf1b16 16546->16548 16550 7ff7d4c0039c _fread_nolock 53 API calls 16547->16550 16549 7ff7d4c04f08 _get_daylight 11 API calls 16548->16549 16551 7ff7d4bf1b1b 16549->16551 16552 7ff7d4bf1b4a 16550->16552 16553 7ff7d4bf2910 54 API calls 16551->16553 16554 7ff7d4bf1b6f 16552->16554 16555 7ff7d4bf1b50 16552->16555 16553->16520 17234 7ff7d4c00110 16554->17234 16557 7ff7d4c04f08 _get_daylight 11 API calls 16555->16557 16558 7ff7d4bf1b55 16557->16558 16560 7ff7d4bf2910 54 API calls 16558->16560 16560->16520 16561 7ff7d4bf2710 54 API calls 16561->16520 16563 7ff7d4bf45cc 16562->16563 16564 7ff7d4bf9390 2 API calls 16563->16564 16565 7ff7d4bf45f4 16564->16565 16566 7ff7d4bf9390 2 API calls 16565->16566 16567 7ff7d4bf4607 16566->16567 17452 7ff7d4c05f94 16567->17452 16570 7ff7d4bfc550 _log10_special 8 API calls 16571 7ff7d4bf392b 16570->16571 16571->16314 16572 7ff7d4bf7f90 16571->16572 16573 7ff7d4bf7fb4 16572->16573 16574 7ff7d4c006d4 73 API calls 16573->16574 16579 7ff7d4bf808b __std_exception_copy 16573->16579 16575 7ff7d4bf7fd0 16574->16575 16575->16579 17868 7ff7d4c078c8 16575->17868 16577 7ff7d4c006d4 73 API calls 16580 7ff7d4bf7fe5 16577->16580 16578 7ff7d4c0039c _fread_nolock 53 API calls 16578->16580 16579->16318 16580->16577 16580->16578 16580->16579 16582 7ff7d4c0007c 16581->16582 17883 7ff7d4bffe28 16582->17883 16584 7ff7d4c00095 16584->16314 16586 7ff7d4bfc850 16585->16586 16587 7ff7d4bf2734 GetCurrentProcessId 16586->16587 16588 7ff7d4bf1c80 49 API calls 16587->16588 16589 7ff7d4bf2787 16588->16589 16590 7ff7d4c04984 49 API calls 16589->16590 16591 7ff7d4bf27cf 16590->16591 16592 7ff7d4bf2620 12 API calls 16591->16592 16593 7ff7d4bf27f1 16592->16593 16594 7ff7d4bfc550 _log10_special 8 API calls 16593->16594 16595 7ff7d4bf2801 16594->16595 16595->16345 16597 7ff7d4bf1ca5 16596->16597 16598 7ff7d4c04984 49 API calls 16597->16598 16599 7ff7d4bf1cc8 16598->16599 16599->16311 16601 7ff7d4bf883a 16600->16601 16602 7ff7d4bf9390 2 API calls 16601->16602 16603 7ff7d4bf8859 GetEnvironmentVariableW 16602->16603 16604 7ff7d4bf8876 ExpandEnvironmentStringsW 16603->16604 16605 7ff7d4bf88c2 16603->16605 16604->16605 16607 7ff7d4bf8898 16604->16607 16606 7ff7d4bfc550 _log10_special 8 API calls 16605->16606 16608 7ff7d4bf88d4 16606->16608 16609 7ff7d4bf9440 2 API calls 16607->16609 16608->16315 16610 7ff7d4bf88aa 16609->16610 16611 7ff7d4bfc550 _log10_special 8 API calls 16610->16611 16612 7ff7d4bf88ba 16611->16612 16612->16315 16614 7ff7d4bf9390 2 API calls 16613->16614 16615 7ff7d4bf89b4 16614->16615 17894 7ff7d4c08238 16615->17894 16617 7ff7d4bf89c6 __std_exception_copy 16617->16325 16619 7ff7d4bf9390 2 API calls 16618->16619 16620 7ff7d4bf895c 16619->16620 16621 7ff7d4bf9390 2 API calls 16620->16621 16622 7ff7d4bf896c 16621->16622 16623 7ff7d4c08238 38 API calls 16622->16623 16624 7ff7d4bf897a __std_exception_copy 16623->16624 16624->16328 16626 7ff7d4bf90f5 16625->16626 17912 7ff7d4bf8570 GetCurrentProcess OpenProcessToken 16626->17912 16629 7ff7d4bf8570 7 API calls 16630 7ff7d4bf9121 16629->16630 16631 7ff7d4bf9154 16630->16631 16632 7ff7d4bf913a 16630->16632 16633 7ff7d4bf26b0 48 API calls 16631->16633 16634 7ff7d4bf26b0 48 API calls 16632->16634 16635 7ff7d4bf9167 LocalFree LocalFree 16633->16635 16636 7ff7d4bf9152 16634->16636 16637 7ff7d4bf9183 16635->16637 16639 7ff7d4bf918f 16635->16639 16636->16635 17922 7ff7d4bf2b50 16637->17922 16640 7ff7d4bfc550 _log10_special 8 API calls 16639->16640 16641 7ff7d4bf3c55 16640->16641 16641->16362 16641->16365 16643 7ff7d4bf8678 16642->16643 16644 7ff7d4bf86fa GetTempPathW GetCurrentProcessId 16643->16644 16646 7ff7d4bf8830 14 API calls 16643->16646 17963 7ff7d4bf25c0 16644->17963 16647 7ff7d4bf86a8 16646->16647 17931 7ff7d4bf81d0 16647->17931 16652 7ff7d4bf8728 __std_exception_copy 16660 7ff7d4bf8765 __std_exception_copy 16652->16660 17967 7ff7d4c08b68 16652->17967 16654 7ff7d4c08238 38 API calls 16655 7ff7d4bf86ce __std_exception_copy 16654->16655 16655->16644 16662 7ff7d4bf86dc 16655->16662 16658 7ff7d4bf86e8 __std_exception_copy 16659 7ff7d4bfc550 _log10_special 8 API calls 16658->16659 16661 7ff7d4bf3cbb 16659->16661 16660->16658 16665 7ff7d4bf9390 2 API calls 16660->16665 16661->16374 16661->16375 16664 7ff7d4bf2810 49 API calls 16662->16664 16664->16658 16666 7ff7d4bf87b1 16665->16666 16667 7ff7d4bf87b6 16666->16667 16668 7ff7d4bf87e9 16666->16668 16669 7ff7d4bf9390 2 API calls 16667->16669 16670 7ff7d4c08238 38 API calls 16668->16670 16671 7ff7d4bf87c6 16669->16671 16670->16658 16672 7ff7d4c08238 38 API calls 16671->16672 16672->16658 16674 7ff7d4bf1c80 49 API calls 16673->16674 16675 7ff7d4bf44fd 16674->16675 16675->16357 16677 7ff7d4bf1c80 49 API calls 16676->16677 16678 7ff7d4bf4660 16677->16678 16678->16377 16680 7ff7d4bf93b2 MultiByteToWideChar 16679->16680 16681 7ff7d4bf93d6 16679->16681 16680->16681 16683 7ff7d4bf93ec __std_exception_copy 16680->16683 16682 7ff7d4bf93f3 MultiByteToWideChar 16681->16682 16681->16683 16682->16683 16683->16379 16685 7ff7d4bf6dd5 16684->16685 16686 7ff7d4bf3e64 16685->16686 16687 7ff7d4c04f08 _get_daylight 11 API calls 16685->16687 16690 7ff7d4bf7340 16686->16690 16688 7ff7d4bf6de2 16687->16688 16689 7ff7d4bf2910 54 API calls 16688->16689 16689->16686 18201 7ff7d4bf1470 16690->18201 16692 7ff7d4bf7368 16693 7ff7d4bf4630 49 API calls 16692->16693 16703 7ff7d4bf74b9 __std_exception_copy 16692->16703 16694 7ff7d4bf738a 16693->16694 16695 7ff7d4bf738f 16694->16695 16696 7ff7d4bf4630 49 API calls 16694->16696 16697 7ff7d4bf2a50 54 API calls 16695->16697 16698 7ff7d4bf73ae 16696->16698 16697->16703 16698->16695 16699 7ff7d4bf4630 49 API calls 16698->16699 16700 7ff7d4bf73ca 16699->16700 16700->16695 16701 7ff7d4bf73d3 16700->16701 16703->16412 16721 7ff7d4bf6e1c 16705->16721 16706 7ff7d4bf6f3f 16707 7ff7d4bfc550 _log10_special 8 API calls 16706->16707 16708 7ff7d4bf6f51 16707->16708 16708->16415 16710 7ff7d4bf6faa 16712 7ff7d4bf2710 54 API calls 16710->16712 16711 7ff7d4bf1c80 49 API calls 16711->16721 16712->16706 16713 7ff7d4bf6f97 16715 7ff7d4bf2710 54 API calls 16713->16715 16715->16706 16717 7ff7d4bf2a50 54 API calls 16717->16721 16718 7ff7d4bf6f84 16719 7ff7d4bf2710 54 API calls 16718->16719 16719->16706 16721->16706 16721->16710 16721->16711 16721->16713 16721->16717 16721->16718 16722 7ff7d4bf6f6d 16721->16722 18257 7ff7d4bf1840 16721->18257 18261 7ff7d4bf4560 16721->18261 18267 7ff7d4bf7e20 16721->18267 18278 7ff7d4bf1600 16721->18278 16723 7ff7d4bf2710 54 API calls 16722->16723 16723->16706 18386 7ff7d4bf8e80 16724->18386 16741 7ff7d4bfc850 16740->16741 16742 7ff7d4bf2a74 GetCurrentProcessId 16741->16742 16743 7ff7d4bf1c80 49 API calls 16742->16743 16774 7ff7d4bf33ce __scrt_get_show_window_mode 16758->16774 16759 7ff7d4bfc550 _log10_special 8 API calls 16761 7ff7d4bf3664 16759->16761 16760 7ff7d4bf35c7 16760->16759 16761->16345 16761->16392 16763 7ff7d4bf1c80 49 API calls 16763->16774 16764 7ff7d4bf35e2 16766 7ff7d4bf2710 54 API calls 16764->16766 16765 7ff7d4bf4560 10 API calls 16765->16774 16766->16760 16767 7ff7d4bf7e20 52 API calls 16767->16774 16769 7ff7d4bf35c9 16771 7ff7d4bf2710 54 API calls 16769->16771 16770 7ff7d4bf2a50 54 API calls 16770->16774 16771->16760 16773 7ff7d4bf1600 118 API calls 16773->16774 16774->16760 16774->16763 16774->16764 16774->16765 16774->16767 16774->16769 16774->16770 16774->16773 16775 7ff7d4bf35d0 16774->16775 18462 7ff7d4bf7120 16774->18462 18466 7ff7d4bf4190 16774->18466 18510 7ff7d4bf4450 16774->18510 16776 7ff7d4bf2710 54 API calls 16775->16776 16776->16760 18572 7ff7d4bf6360 16778->18572 16781 7ff7d4bf3399 16787 7ff7d4bf3670 16781->16787 16783 7ff7d4bf3381 16783->16781 16788 7ff7d4bf367e 16787->16788 16790 7ff7d4bf368f 16788->16790 18860 7ff7d4bf8e60 FreeLibrary 16788->18860 16790->16404 16798 7ff7d4c0546c EnterCriticalSection 16791->16798 16800 7ff7d4bf36bc GetModuleFileNameW 16799->16800 16800->16493 16800->16494 16802 7ff7d4bf92d2 16801->16802 16803 7ff7d4bf92bf FindClose 16801->16803 16804 7ff7d4bfc550 _log10_special 8 API calls 16802->16804 16803->16802 16805 7ff7d4bf371a 16804->16805 16805->16499 16805->16500 16807 7ff7d4bfc850 16806->16807 16808 7ff7d4bf2c70 GetCurrentProcessId 16807->16808 16837 7ff7d4bf26b0 16808->16837 16810 7ff7d4bf2cb9 16841 7ff7d4c04bd8 16810->16841 16813 7ff7d4bf26b0 48 API calls 16814 7ff7d4bf2d34 FormatMessageW 16813->16814 16816 7ff7d4bf2d7f MessageBoxW 16814->16816 16817 7ff7d4bf2d6d 16814->16817 16819 7ff7d4bfc550 _log10_special 8 API calls 16816->16819 16818 7ff7d4bf26b0 48 API calls 16817->16818 16818->16816 16820 7ff7d4bf2daf 16819->16820 16820->16497 16822 7ff7d4bf9340 GetFinalPathNameByHandleW CloseHandle 16821->16822 16823 7ff7d4bf3730 16821->16823 16822->16823 16823->16507 16823->16508 16825 7ff7d4bf2834 16824->16825 16826 7ff7d4bf26b0 48 API calls 16825->16826 16827 7ff7d4bf2887 16826->16827 16828 7ff7d4c04bd8 48 API calls 16827->16828 16829 7ff7d4bf28d0 MessageBoxW 16828->16829 16830 7ff7d4bfc550 _log10_special 8 API calls 16829->16830 16831 7ff7d4bf2900 16830->16831 16831->16497 16833 7ff7d4bf946a WideCharToMultiByte 16832->16833 16835 7ff7d4bf9495 16832->16835 16833->16835 16836 7ff7d4bf94ab __std_exception_copy 16833->16836 16834 7ff7d4bf94b2 WideCharToMultiByte 16834->16836 16835->16834 16835->16836 16836->16506 16838 7ff7d4bf26d5 16837->16838 16839 7ff7d4c04bd8 48 API calls 16838->16839 16840 7ff7d4bf26f8 16839->16840 16840->16810 16842 7ff7d4c04c32 16841->16842 16843 7ff7d4c04c57 16842->16843 16845 7ff7d4c04c93 16842->16845 16844 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 16843->16844 16847 7ff7d4c04c81 16844->16847 16859 7ff7d4c02f90 16845->16859 16849 7ff7d4bfc550 _log10_special 8 API calls 16847->16849 16848 7ff7d4c04d74 16850 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16848->16850 16851 7ff7d4bf2d04 16849->16851 16850->16847 16851->16813 16853 7ff7d4c04d9a 16853->16848 16855 7ff7d4c04da4 16853->16855 16854 7ff7d4c04d49 16856 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16854->16856 16858 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16855->16858 16856->16847 16857 7ff7d4c04d40 16857->16848 16857->16854 16858->16847 16860 7ff7d4c02fce 16859->16860 16861 7ff7d4c02fbe 16859->16861 16862 7ff7d4c02fd7 16860->16862 16866 7ff7d4c03005 16860->16866 16863 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 16861->16863 16864 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 16862->16864 16865 7ff7d4c02ffd 16863->16865 16864->16865 16865->16848 16865->16853 16865->16854 16865->16857 16866->16861 16866->16865 16870 7ff7d4c039a4 16866->16870 16903 7ff7d4c033f0 16866->16903 16940 7ff7d4c02b80 16866->16940 16871 7ff7d4c039e6 16870->16871 16872 7ff7d4c03a57 16870->16872 16873 7ff7d4c039ec 16871->16873 16880 7ff7d4c03a81 16871->16880 16874 7ff7d4c03ab0 16872->16874 16875 7ff7d4c03a5c 16872->16875 16876 7ff7d4c039f1 16873->16876 16877 7ff7d4c03a20 16873->16877 16882 7ff7d4c03ac7 16874->16882 16884 7ff7d4c03aba 16874->16884 16888 7ff7d4c03abf 16874->16888 16878 7ff7d4c03a91 16875->16878 16879 7ff7d4c03a5e 16875->16879 16876->16882 16885 7ff7d4c039f7 16876->16885 16877->16885 16877->16888 16970 7ff7d4c01944 16878->16970 16883 7ff7d4c03a00 16879->16883 16892 7ff7d4c03a6d 16879->16892 16963 7ff7d4c01d54 16880->16963 16977 7ff7d4c046ac 16882->16977 16901 7ff7d4c03af0 16883->16901 16943 7ff7d4c04158 16883->16943 16884->16880 16884->16888 16885->16883 16891 7ff7d4c03a32 16885->16891 16899 7ff7d4c03a1b 16885->16899 16888->16901 16981 7ff7d4c02164 16888->16981 16891->16901 16953 7ff7d4c04494 16891->16953 16892->16880 16893 7ff7d4c03a72 16892->16893 16893->16901 16959 7ff7d4c04558 16893->16959 16895 7ff7d4bfc550 _log10_special 8 API calls 16896 7ff7d4c03dea 16895->16896 16896->16866 16899->16901 16902 7ff7d4c03cdc 16899->16902 16988 7ff7d4c047c0 16899->16988 16901->16895 16902->16901 16994 7ff7d4c0ea08 16902->16994 16904 7ff7d4c03414 16903->16904 16905 7ff7d4c033fe 16903->16905 16906 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 16904->16906 16907 7ff7d4c03454 16904->16907 16905->16907 16908 7ff7d4c039e6 16905->16908 16909 7ff7d4c03a57 16905->16909 16906->16907 16907->16866 16910 7ff7d4c03a81 16908->16910 16911 7ff7d4c039ec 16908->16911 16912 7ff7d4c03ab0 16909->16912 16913 7ff7d4c03a5c 16909->16913 16918 7ff7d4c01d54 38 API calls 16910->16918 16914 7ff7d4c039f1 16911->16914 16915 7ff7d4c03a20 16911->16915 16919 7ff7d4c03ac7 16912->16919 16921 7ff7d4c03aba 16912->16921 16925 7ff7d4c03abf 16912->16925 16916 7ff7d4c03a91 16913->16916 16917 7ff7d4c03a5e 16913->16917 16914->16919 16922 7ff7d4c039f7 16914->16922 16915->16922 16915->16925 16923 7ff7d4c01944 38 API calls 16916->16923 16920 7ff7d4c03a00 16917->16920 16928 7ff7d4c03a6d 16917->16928 16935 7ff7d4c03a1b 16918->16935 16926 7ff7d4c046ac 45 API calls 16919->16926 16924 7ff7d4c04158 47 API calls 16920->16924 16938 7ff7d4c03af0 16920->16938 16921->16910 16921->16925 16922->16920 16929 7ff7d4c03a32 16922->16929 16922->16935 16923->16935 16924->16935 16927 7ff7d4c02164 38 API calls 16925->16927 16925->16938 16926->16935 16927->16935 16928->16910 16930 7ff7d4c03a72 16928->16930 16931 7ff7d4c04494 46 API calls 16929->16931 16929->16938 16933 7ff7d4c04558 37 API calls 16930->16933 16930->16938 16931->16935 16932 7ff7d4bfc550 _log10_special 8 API calls 16934 7ff7d4c03dea 16932->16934 16933->16935 16934->16866 16936 7ff7d4c047c0 45 API calls 16935->16936 16935->16938 16939 7ff7d4c03cdc 16935->16939 16936->16939 16937 7ff7d4c0ea08 46 API calls 16937->16939 16938->16932 16939->16937 16939->16938 17195 7ff7d4c00fc8 16940->17195 16944 7ff7d4c0417e 16943->16944 17006 7ff7d4c00b80 16944->17006 16949 7ff7d4c047c0 45 API calls 16951 7ff7d4c042c3 16949->16951 16950 7ff7d4c047c0 45 API calls 16952 7ff7d4c04351 16950->16952 16951->16950 16951->16951 16951->16952 16952->16899 16954 7ff7d4c044c9 16953->16954 16955 7ff7d4c0450e 16954->16955 16956 7ff7d4c044e7 16954->16956 16957 7ff7d4c047c0 45 API calls 16954->16957 16955->16899 16958 7ff7d4c0ea08 46 API calls 16956->16958 16957->16956 16958->16955 16960 7ff7d4c04579 16959->16960 16961 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 16960->16961 16962 7ff7d4c045aa 16960->16962 16961->16962 16962->16899 16965 7ff7d4c01d87 16963->16965 16964 7ff7d4c01db6 16969 7ff7d4c01df3 16964->16969 17149 7ff7d4c00c28 16964->17149 16965->16964 16967 7ff7d4c01e73 16965->16967 16968 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 16967->16968 16968->16969 16969->16899 16971 7ff7d4c01977 16970->16971 16972 7ff7d4c019a6 16971->16972 16974 7ff7d4c01a63 16971->16974 16973 7ff7d4c00c28 12 API calls 16972->16973 16976 7ff7d4c019e3 16972->16976 16973->16976 16975 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 16974->16975 16975->16976 16976->16899 16978 7ff7d4c046ef 16977->16978 16980 7ff7d4c046f3 __crtLCMapStringW 16978->16980 17157 7ff7d4c04748 16978->17157 16980->16899 16982 7ff7d4c02197 16981->16982 16983 7ff7d4c021c6 16982->16983 16985 7ff7d4c02283 16982->16985 16984 7ff7d4c00c28 12 API calls 16983->16984 16987 7ff7d4c02203 16983->16987 16984->16987 16986 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 16985->16986 16986->16987 16987->16899 16989 7ff7d4c047d7 16988->16989 17161 7ff7d4c0d9b8 16989->17161 16996 7ff7d4c0ea39 16994->16996 17004 7ff7d4c0ea47 16994->17004 16995 7ff7d4c0ea67 16998 7ff7d4c0ea78 16995->16998 16999 7ff7d4c0ea9f 16995->16999 16996->16995 16997 7ff7d4c047c0 45 API calls 16996->16997 16996->17004 16997->16995 17185 7ff7d4c100a0 16998->17185 17001 7ff7d4c0eac9 16999->17001 17002 7ff7d4c0eb2a 16999->17002 16999->17004 17001->17004 17188 7ff7d4c0f8a0 17001->17188 17003 7ff7d4c0f8a0 _fread_nolock MultiByteToWideChar 17002->17003 17003->17004 17004->16902 17007 7ff7d4c00ba6 17006->17007 17008 7ff7d4c00bb7 17006->17008 17014 7ff7d4c0e570 17007->17014 17008->17007 17036 7ff7d4c0d5fc 17008->17036 17011 7ff7d4c00bf8 17013 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17011->17013 17012 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17012->17011 17013->17007 17015 7ff7d4c0e58d 17014->17015 17016 7ff7d4c0e5c0 17014->17016 17017 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17015->17017 17016->17015 17018 7ff7d4c0e5f2 17016->17018 17033 7ff7d4c042a1 17017->17033 17023 7ff7d4c0e705 17018->17023 17025 7ff7d4c0e63a 17018->17025 17019 7ff7d4c0e7f7 17076 7ff7d4c0da5c 17019->17076 17021 7ff7d4c0e7bd 17069 7ff7d4c0ddf4 17021->17069 17023->17019 17023->17021 17024 7ff7d4c0e78c 17023->17024 17026 7ff7d4c0e74f 17023->17026 17028 7ff7d4c0e745 17023->17028 17062 7ff7d4c0e0d4 17024->17062 17025->17033 17043 7ff7d4c0a4a4 17025->17043 17052 7ff7d4c0e304 17026->17052 17028->17021 17030 7ff7d4c0e74a 17028->17030 17030->17024 17030->17026 17033->16949 17033->16951 17034 7ff7d4c0a900 _isindst 17 API calls 17035 7ff7d4c0e854 17034->17035 17037 7ff7d4c0d647 17036->17037 17041 7ff7d4c0d60b _get_daylight 17036->17041 17038 7ff7d4c04f08 _get_daylight 11 API calls 17037->17038 17040 7ff7d4c00be4 17038->17040 17039 7ff7d4c0d62e HeapAlloc 17039->17040 17039->17041 17040->17011 17040->17012 17041->17037 17041->17039 17042 7ff7d4c13590 _get_daylight 2 API calls 17041->17042 17042->17041 17044 7ff7d4c0a4b1 17043->17044 17046 7ff7d4c0a4bb 17043->17046 17044->17046 17050 7ff7d4c0a4d6 17044->17050 17045 7ff7d4c04f08 _get_daylight 11 API calls 17047 7ff7d4c0a4c2 17045->17047 17046->17045 17048 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 17047->17048 17049 7ff7d4c0a4ce 17048->17049 17049->17033 17049->17034 17050->17049 17051 7ff7d4c04f08 _get_daylight 11 API calls 17050->17051 17051->17047 17085 7ff7d4c140ac 17052->17085 17056 7ff7d4c0e401 17138 7ff7d4c0def0 17056->17138 17057 7ff7d4c0e3ac 17057->17056 17059 7ff7d4c0e3cc 17057->17059 17061 7ff7d4c0e3b0 17057->17061 17134 7ff7d4c0e1ac 17059->17134 17061->17033 17063 7ff7d4c140ac 38 API calls 17062->17063 17064 7ff7d4c0e11e 17063->17064 17065 7ff7d4c13af4 37 API calls 17064->17065 17066 7ff7d4c0e16e 17065->17066 17067 7ff7d4c0e172 17066->17067 17068 7ff7d4c0e1ac 45 API calls 17066->17068 17067->17033 17068->17067 17070 7ff7d4c140ac 38 API calls 17069->17070 17071 7ff7d4c0de3f 17070->17071 17072 7ff7d4c13af4 37 API calls 17071->17072 17073 7ff7d4c0de97 17072->17073 17074 7ff7d4c0def0 45 API calls 17073->17074 17075 7ff7d4c0de9b 17073->17075 17074->17075 17075->17033 17077 7ff7d4c0daa1 17076->17077 17078 7ff7d4c0dad4 17076->17078 17079 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17077->17079 17080 7ff7d4c0daec 17078->17080 17082 7ff7d4c0db6d 17078->17082 17084 7ff7d4c0dacd __scrt_get_show_window_mode 17079->17084 17081 7ff7d4c0ddf4 46 API calls 17080->17081 17081->17084 17083 7ff7d4c047c0 45 API calls 17082->17083 17082->17084 17083->17084 17084->17033 17086 7ff7d4c140ff fegetenv 17085->17086 17087 7ff7d4c17e2c 37 API calls 17086->17087 17092 7ff7d4c14152 17087->17092 17088 7ff7d4c1417f 17091 7ff7d4c0a4a4 __std_exception_copy 37 API calls 17088->17091 17089 7ff7d4c14242 17090 7ff7d4c17e2c 37 API calls 17089->17090 17093 7ff7d4c1426c 17090->17093 17094 7ff7d4c141fd 17091->17094 17092->17089 17095 7ff7d4c1416d 17092->17095 17096 7ff7d4c1421c 17092->17096 17097 7ff7d4c17e2c 37 API calls 17093->17097 17098 7ff7d4c15324 17094->17098 17104 7ff7d4c14205 17094->17104 17095->17088 17095->17089 17099 7ff7d4c0a4a4 __std_exception_copy 37 API calls 17096->17099 17100 7ff7d4c1427d 17097->17100 17101 7ff7d4c0a900 _isindst 17 API calls 17098->17101 17099->17094 17102 7ff7d4c18020 20 API calls 17100->17102 17103 7ff7d4c15339 17101->17103 17108 7ff7d4c142e6 __scrt_get_show_window_mode 17102->17108 17105 7ff7d4bfc550 _log10_special 8 API calls 17104->17105 17106 7ff7d4c0e351 17105->17106 17130 7ff7d4c13af4 17106->17130 17107 7ff7d4c1468f __scrt_get_show_window_mode 17108->17107 17109 7ff7d4c14327 memcpy_s 17108->17109 17114 7ff7d4c04f08 _get_daylight 11 API calls 17108->17114 17123 7ff7d4c14c6b memcpy_s __scrt_get_show_window_mode 17109->17123 17129 7ff7d4c14783 memcpy_s __scrt_get_show_window_mode 17109->17129 17110 7ff7d4c13c10 37 API calls 17116 7ff7d4c150e7 17110->17116 17111 7ff7d4c149cf 17111->17110 17112 7ff7d4c1533c memcpy_s 37 API calls 17112->17111 17113 7ff7d4c1497b 17113->17111 17113->17112 17115 7ff7d4c14760 17114->17115 17117 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 17115->17117 17119 7ff7d4c1533c memcpy_s 37 API calls 17116->17119 17127 7ff7d4c15142 17116->17127 17117->17109 17118 7ff7d4c152c8 17121 7ff7d4c17e2c 37 API calls 17118->17121 17119->17127 17120 7ff7d4c04f08 11 API calls _get_daylight 17120->17129 17121->17104 17122 7ff7d4c04f08 11 API calls _get_daylight 17122->17123 17123->17111 17123->17113 17123->17122 17128 7ff7d4c0a8e0 37 API calls _invalid_parameter_noinfo 17123->17128 17124 7ff7d4c13c10 37 API calls 17124->17127 17125 7ff7d4c0a8e0 37 API calls _invalid_parameter_noinfo 17125->17129 17126 7ff7d4c1533c memcpy_s 37 API calls 17126->17127 17127->17118 17127->17124 17127->17126 17128->17123 17129->17113 17129->17120 17129->17125 17131 7ff7d4c13b13 17130->17131 17132 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17131->17132 17133 7ff7d4c13b3e memcpy_s 17131->17133 17132->17133 17133->17057 17135 7ff7d4c0e1d8 memcpy_s 17134->17135 17136 7ff7d4c047c0 45 API calls 17135->17136 17137 7ff7d4c0e292 memcpy_s __scrt_get_show_window_mode 17135->17137 17136->17137 17137->17061 17139 7ff7d4c0df2b 17138->17139 17142 7ff7d4c0df78 memcpy_s 17138->17142 17140 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17139->17140 17141 7ff7d4c0df57 17140->17141 17141->17061 17143 7ff7d4c0dfe3 17142->17143 17145 7ff7d4c047c0 45 API calls 17142->17145 17144 7ff7d4c0a4a4 __std_exception_copy 37 API calls 17143->17144 17148 7ff7d4c0e025 memcpy_s 17144->17148 17145->17143 17146 7ff7d4c0a900 _isindst 17 API calls 17147 7ff7d4c0e0d0 17146->17147 17148->17146 17150 7ff7d4c00c5f 17149->17150 17156 7ff7d4c00c4e 17149->17156 17151 7ff7d4c0d5fc _fread_nolock 12 API calls 17150->17151 17150->17156 17152 7ff7d4c00c90 17151->17152 17153 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17152->17153 17155 7ff7d4c00ca4 17152->17155 17153->17155 17154 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17154->17156 17155->17154 17156->16969 17158 7ff7d4c04766 17157->17158 17159 7ff7d4c0476e 17157->17159 17160 7ff7d4c047c0 45 API calls 17158->17160 17159->16980 17160->17159 17162 7ff7d4c047ff 17161->17162 17163 7ff7d4c0d9d1 17161->17163 17165 7ff7d4c0da24 17162->17165 17163->17162 17169 7ff7d4c13304 17163->17169 17166 7ff7d4c0da3d 17165->17166 17168 7ff7d4c0480f 17165->17168 17166->17168 17182 7ff7d4c12650 17166->17182 17168->16902 17170 7ff7d4c0b150 __CxxCallCatchBlock 45 API calls 17169->17170 17171 7ff7d4c13313 17170->17171 17172 7ff7d4c1335e 17171->17172 17181 7ff7d4c102d8 EnterCriticalSection 17171->17181 17172->17162 17183 7ff7d4c0b150 __CxxCallCatchBlock 45 API calls 17182->17183 17184 7ff7d4c12659 17183->17184 17191 7ff7d4c16d88 17185->17191 17190 7ff7d4c0f8a9 MultiByteToWideChar 17188->17190 17194 7ff7d4c16dec 17191->17194 17192 7ff7d4bfc550 _log10_special 8 API calls 17193 7ff7d4c100bd 17192->17193 17193->17004 17194->17192 17196 7ff7d4c0100f 17195->17196 17197 7ff7d4c00ffd 17195->17197 17200 7ff7d4c0101d 17196->17200 17204 7ff7d4c01059 17196->17204 17198 7ff7d4c04f08 _get_daylight 11 API calls 17197->17198 17199 7ff7d4c01002 17198->17199 17201 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 17199->17201 17202 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17200->17202 17209 7ff7d4c0100d 17201->17209 17202->17209 17203 7ff7d4c013d5 17205 7ff7d4c04f08 _get_daylight 11 API calls 17203->17205 17203->17209 17204->17203 17206 7ff7d4c04f08 _get_daylight 11 API calls 17204->17206 17207 7ff7d4c01669 17205->17207 17208 7ff7d4c013ca 17206->17208 17210 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 17207->17210 17211 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 17208->17211 17209->16866 17210->17209 17211->17203 17213 7ff7d4c00704 17212->17213 17240 7ff7d4c00464 17213->17240 17215 7ff7d4c0071d 17215->16523 17217 7ff7d4bfc850 17216->17217 17218 7ff7d4bf2930 GetCurrentProcessId 17217->17218 17219 7ff7d4bf1c80 49 API calls 17218->17219 17220 7ff7d4bf2979 17219->17220 17252 7ff7d4c04984 17220->17252 17225 7ff7d4bf1c80 49 API calls 17226 7ff7d4bf29ff 17225->17226 17282 7ff7d4bf2620 17226->17282 17229 7ff7d4bfc550 _log10_special 8 API calls 17230 7ff7d4bf2a31 17229->17230 17230->16520 17438 7ff7d4c003bc 17231->17438 17235 7ff7d4c00119 17234->17235 17237 7ff7d4bf1b89 17234->17237 17236 7ff7d4c04f08 _get_daylight 11 API calls 17235->17236 17238 7ff7d4c0011e 17236->17238 17237->16520 17237->16561 17239 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 17238->17239 17239->17237 17241 7ff7d4c004ce 17240->17241 17242 7ff7d4c0048e 17240->17242 17241->17242 17244 7ff7d4c004da 17241->17244 17243 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17242->17243 17245 7ff7d4c004b5 17243->17245 17251 7ff7d4c0546c EnterCriticalSection 17244->17251 17245->17215 17256 7ff7d4c049de 17252->17256 17253 7ff7d4c04a03 17254 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17253->17254 17269 7ff7d4c04a2d 17254->17269 17255 7ff7d4c04a3f 17291 7ff7d4c02c10 17255->17291 17256->17253 17256->17255 17259 7ff7d4bfc550 _log10_special 8 API calls 17261 7ff7d4bf29c3 17259->17261 17260 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17260->17269 17270 7ff7d4c05160 17261->17270 17262 7ff7d4c04b1c 17262->17260 17263 7ff7d4c04af1 17266 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17263->17266 17264 7ff7d4c04b40 17264->17262 17265 7ff7d4c04b4a 17264->17265 17268 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17265->17268 17266->17269 17267 7ff7d4c04ae8 17267->17262 17267->17263 17268->17269 17269->17259 17271 7ff7d4c0b2c8 _get_daylight 11 API calls 17270->17271 17272 7ff7d4c05177 17271->17272 17273 7ff7d4bf29e5 17272->17273 17274 7ff7d4c0eb98 _get_daylight 11 API calls 17272->17274 17277 7ff7d4c051b7 17272->17277 17273->17225 17275 7ff7d4c051ac 17274->17275 17276 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17275->17276 17276->17277 17277->17273 17429 7ff7d4c0ec20 17277->17429 17280 7ff7d4c0a900 _isindst 17 API calls 17281 7ff7d4c051fc 17280->17281 17283 7ff7d4bf262f 17282->17283 17284 7ff7d4bf9390 2 API calls 17283->17284 17285 7ff7d4bf2660 17284->17285 17286 7ff7d4bf2683 MessageBoxA 17285->17286 17287 7ff7d4bf266f MessageBoxW 17285->17287 17288 7ff7d4bf2690 17286->17288 17287->17288 17289 7ff7d4bfc550 _log10_special 8 API calls 17288->17289 17290 7ff7d4bf26a0 17289->17290 17290->17229 17292 7ff7d4c02c4e 17291->17292 17293 7ff7d4c02c3e 17291->17293 17294 7ff7d4c02c57 17292->17294 17298 7ff7d4c02c85 17292->17298 17296 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17293->17296 17297 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17294->17297 17295 7ff7d4c02c7d 17295->17262 17295->17263 17295->17264 17295->17267 17296->17295 17297->17295 17298->17293 17298->17295 17299 7ff7d4c047c0 45 API calls 17298->17299 17301 7ff7d4c02f34 17298->17301 17305 7ff7d4c035a0 17298->17305 17331 7ff7d4c03268 17298->17331 17361 7ff7d4c02af0 17298->17361 17299->17298 17303 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17301->17303 17303->17293 17306 7ff7d4c03655 17305->17306 17307 7ff7d4c035e2 17305->17307 17308 7ff7d4c036af 17306->17308 17309 7ff7d4c0365a 17306->17309 17310 7ff7d4c0367f 17307->17310 17311 7ff7d4c035e8 17307->17311 17308->17310 17320 7ff7d4c036be 17308->17320 17329 7ff7d4c03618 17308->17329 17312 7ff7d4c0368f 17309->17312 17313 7ff7d4c0365c 17309->17313 17378 7ff7d4c01b50 17310->17378 17317 7ff7d4c035ed 17311->17317 17311->17320 17385 7ff7d4c01740 17312->17385 17319 7ff7d4c0366b 17313->17319 17322 7ff7d4c035fd 17313->17322 17321 7ff7d4c03630 17317->17321 17317->17322 17317->17329 17319->17310 17323 7ff7d4c03670 17319->17323 17330 7ff7d4c036ed 17320->17330 17392 7ff7d4c01f60 17320->17392 17321->17330 17374 7ff7d4c043c0 17321->17374 17322->17330 17364 7ff7d4c03f04 17322->17364 17326 7ff7d4c04558 37 API calls 17323->17326 17323->17330 17325 7ff7d4bfc550 _log10_special 8 API calls 17327 7ff7d4c03983 17325->17327 17326->17329 17327->17298 17329->17330 17399 7ff7d4c0e858 17329->17399 17330->17325 17332 7ff7d4c03273 17331->17332 17333 7ff7d4c03289 17331->17333 17334 7ff7d4c03655 17332->17334 17335 7ff7d4c035e2 17332->17335 17351 7ff7d4c032c7 17332->17351 17336 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17333->17336 17333->17351 17337 7ff7d4c0365a 17334->17337 17342 7ff7d4c036af 17334->17342 17338 7ff7d4c035e8 17335->17338 17343 7ff7d4c0367f 17335->17343 17336->17351 17340 7ff7d4c0368f 17337->17340 17341 7ff7d4c0365c 17337->17341 17339 7ff7d4c035ed 17338->17339 17352 7ff7d4c036be 17338->17352 17344 7ff7d4c035fd 17339->17344 17350 7ff7d4c03630 17339->17350 17359 7ff7d4c03618 17339->17359 17346 7ff7d4c01740 38 API calls 17340->17346 17341->17344 17349 7ff7d4c0366b 17341->17349 17342->17343 17342->17352 17342->17359 17345 7ff7d4c01b50 38 API calls 17343->17345 17347 7ff7d4c03f04 47 API calls 17344->17347 17360 7ff7d4c036ed 17344->17360 17345->17359 17346->17359 17347->17359 17348 7ff7d4c01f60 38 API calls 17348->17359 17349->17343 17353 7ff7d4c03670 17349->17353 17354 7ff7d4c043c0 47 API calls 17350->17354 17350->17360 17351->17298 17352->17348 17352->17360 17356 7ff7d4c04558 37 API calls 17353->17356 17353->17360 17354->17359 17355 7ff7d4bfc550 _log10_special 8 API calls 17357 7ff7d4c03983 17355->17357 17356->17359 17357->17298 17358 7ff7d4c0e858 47 API calls 17358->17359 17359->17358 17359->17360 17360->17355 17412 7ff7d4c00d14 17361->17412 17365 7ff7d4c03f26 17364->17365 17366 7ff7d4c00b80 12 API calls 17365->17366 17367 7ff7d4c03f6e 17366->17367 17368 7ff7d4c0e570 46 API calls 17367->17368 17369 7ff7d4c04041 17368->17369 17370 7ff7d4c047c0 45 API calls 17369->17370 17372 7ff7d4c04063 17369->17372 17370->17372 17371 7ff7d4c040ec 17371->17329 17372->17371 17373 7ff7d4c047c0 45 API calls 17372->17373 17373->17371 17375 7ff7d4c04440 17374->17375 17376 7ff7d4c043d8 17374->17376 17375->17329 17376->17375 17377 7ff7d4c0e858 47 API calls 17376->17377 17377->17375 17379 7ff7d4c01b83 17378->17379 17380 7ff7d4c01bb2 17379->17380 17382 7ff7d4c01c6f 17379->17382 17381 7ff7d4c00b80 12 API calls 17380->17381 17384 7ff7d4c01bef 17380->17384 17381->17384 17383 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17382->17383 17383->17384 17384->17329 17386 7ff7d4c01773 17385->17386 17387 7ff7d4c017a2 17386->17387 17389 7ff7d4c0185f 17386->17389 17388 7ff7d4c00b80 12 API calls 17387->17388 17391 7ff7d4c017df 17387->17391 17388->17391 17390 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17389->17390 17390->17391 17391->17329 17393 7ff7d4c01f93 17392->17393 17394 7ff7d4c01fc2 17393->17394 17396 7ff7d4c0207f 17393->17396 17395 7ff7d4c00b80 12 API calls 17394->17395 17398 7ff7d4c01fff 17394->17398 17395->17398 17397 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17396->17397 17397->17398 17398->17329 17400 7ff7d4c0e880 17399->17400 17401 7ff7d4c0e8c5 17400->17401 17403 7ff7d4c047c0 45 API calls 17400->17403 17404 7ff7d4c0e8ae __scrt_get_show_window_mode 17400->17404 17406 7ff7d4c0e885 __scrt_get_show_window_mode 17400->17406 17401->17404 17401->17406 17409 7ff7d4c107e8 17401->17409 17402 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17402->17406 17403->17401 17404->17402 17404->17406 17406->17329 17411 7ff7d4c1080c WideCharToMultiByte 17409->17411 17413 7ff7d4c00d53 17412->17413 17414 7ff7d4c00d41 17412->17414 17416 7ff7d4c00d60 17413->17416 17420 7ff7d4c00d9d 17413->17420 17415 7ff7d4c04f08 _get_daylight 11 API calls 17414->17415 17417 7ff7d4c00d46 17415->17417 17418 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17416->17418 17419 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 17417->17419 17426 7ff7d4c00d51 17418->17426 17419->17426 17421 7ff7d4c00e46 17420->17421 17422 7ff7d4c04f08 _get_daylight 11 API calls 17420->17422 17423 7ff7d4c04f08 _get_daylight 11 API calls 17421->17423 17421->17426 17424 7ff7d4c00e3b 17422->17424 17425 7ff7d4c00ef0 17423->17425 17427 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 17424->17427 17428 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 17425->17428 17426->17298 17427->17421 17428->17426 17433 7ff7d4c0ec3d 17429->17433 17430 7ff7d4c0ec42 17431 7ff7d4c051dd 17430->17431 17432 7ff7d4c04f08 _get_daylight 11 API calls 17430->17432 17431->17273 17431->17280 17434 7ff7d4c0ec4c 17432->17434 17433->17430 17433->17431 17436 7ff7d4c0ec8c 17433->17436 17435 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 17434->17435 17435->17431 17436->17431 17437 7ff7d4c04f08 _get_daylight 11 API calls 17436->17437 17437->17434 17439 7ff7d4c003e6 17438->17439 17440 7ff7d4bf1a20 17438->17440 17439->17440 17441 7ff7d4c003f5 __scrt_get_show_window_mode 17439->17441 17442 7ff7d4c00432 17439->17442 17440->16530 17440->16531 17445 7ff7d4c04f08 _get_daylight 11 API calls 17441->17445 17451 7ff7d4c0546c EnterCriticalSection 17442->17451 17447 7ff7d4c0040a 17445->17447 17449 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 17447->17449 17449->17440 17453 7ff7d4c05ec8 17452->17453 17454 7ff7d4c05eee 17453->17454 17457 7ff7d4c05f21 17453->17457 17455 7ff7d4c04f08 _get_daylight 11 API calls 17454->17455 17456 7ff7d4c05ef3 17455->17456 17460 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 17456->17460 17458 7ff7d4c05f34 17457->17458 17459 7ff7d4c05f27 17457->17459 17471 7ff7d4c0ac28 17458->17471 17461 7ff7d4c04f08 _get_daylight 11 API calls 17459->17461 17463 7ff7d4bf4616 17460->17463 17461->17463 17463->16570 17484 7ff7d4c102d8 EnterCriticalSection 17471->17484 17869 7ff7d4c078f8 17868->17869 17872 7ff7d4c073d4 17869->17872 17871 7ff7d4c07911 17871->16580 17873 7ff7d4c073ef 17872->17873 17874 7ff7d4c0741e 17872->17874 17875 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17873->17875 17882 7ff7d4c0546c EnterCriticalSection 17874->17882 17881 7ff7d4c0740f 17875->17881 17881->17871 17884 7ff7d4bffe43 17883->17884 17885 7ff7d4bffe71 17883->17885 17886 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 17884->17886 17889 7ff7d4bffe63 17885->17889 17893 7ff7d4c0546c EnterCriticalSection 17885->17893 17886->17889 17889->16584 17895 7ff7d4c08258 17894->17895 17896 7ff7d4c08245 17894->17896 17904 7ff7d4c07ebc 17895->17904 17897 7ff7d4c04f08 _get_daylight 11 API calls 17896->17897 17899 7ff7d4c0824a 17897->17899 17902 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 17899->17902 17901 7ff7d4c08256 17901->16617 17902->17901 17911 7ff7d4c102d8 EnterCriticalSection 17904->17911 17913 7ff7d4bf8633 __std_exception_copy 17912->17913 17914 7ff7d4bf85b1 GetTokenInformation 17912->17914 17917 7ff7d4bf8646 CloseHandle 17913->17917 17918 7ff7d4bf864c 17913->17918 17915 7ff7d4bf85d2 GetLastError 17914->17915 17916 7ff7d4bf85dd 17914->17916 17915->17913 17915->17916 17916->17913 17919 7ff7d4bf85f9 GetTokenInformation 17916->17919 17917->17918 17918->16629 17919->17913 17920 7ff7d4bf861c 17919->17920 17920->17913 17921 7ff7d4bf8626 ConvertSidToStringSidW 17920->17921 17921->17913 17923 7ff7d4bfc850 17922->17923 17924 7ff7d4bf2b74 GetCurrentProcessId 17923->17924 17925 7ff7d4bf26b0 48 API calls 17924->17925 17926 7ff7d4bf2bc7 17925->17926 17927 7ff7d4c04bd8 48 API calls 17926->17927 17928 7ff7d4bf2c10 MessageBoxW 17927->17928 17929 7ff7d4bfc550 _log10_special 8 API calls 17928->17929 17930 7ff7d4bf2c40 17929->17930 17930->16639 17932 7ff7d4bf81dc 17931->17932 17933 7ff7d4bf9390 2 API calls 17932->17933 17934 7ff7d4bf81fb 17933->17934 17935 7ff7d4bf8216 ExpandEnvironmentStringsW 17934->17935 17936 7ff7d4bf8203 17934->17936 17938 7ff7d4bf823c __std_exception_copy 17935->17938 17937 7ff7d4bf2810 49 API calls 17936->17937 17962 7ff7d4bf820f __std_exception_copy 17937->17962 17939 7ff7d4bf8253 17938->17939 17940 7ff7d4bf8240 17938->17940 17944 7ff7d4bf8261 GetDriveTypeW 17939->17944 17945 7ff7d4bf82bf 17939->17945 17941 7ff7d4bf2810 49 API calls 17940->17941 17941->17962 17942 7ff7d4bfc550 _log10_special 8 API calls 17943 7ff7d4bf83af 17942->17943 17943->16654 17943->16658 17949 7ff7d4bf8295 17944->17949 17950 7ff7d4bf82b0 17944->17950 17977 7ff7d4c07e08 17945->17977 17952 7ff7d4bf2810 49 API calls 17949->17952 17970 7ff7d4c0796c 17950->17970 17952->17962 17962->17942 17964 7ff7d4bf25e5 17963->17964 17965 7ff7d4c04bd8 48 API calls 17964->17965 17966 7ff7d4bf2604 17965->17966 17966->16652 18078 7ff7d4c08794 17967->18078 17971 7ff7d4c0798a 17970->17971 17974 7ff7d4c079bd 17970->17974 17971->17974 17989 7ff7d4c10474 17971->17989 17974->17962 17975 7ff7d4c0a900 _isindst 17 API calls 17978 7ff7d4c07e24 17977->17978 17979 7ff7d4c07e92 17977->17979 17978->17979 17981 7ff7d4c07e29 17978->17981 18023 7ff7d4c107c0 17979->18023 17983 7ff7d4c07e41 17981->17983 17984 7ff7d4c07e5e 17981->17984 17998 7ff7d4c07bd8 GetFullPathNameW 17983->17998 18006 7ff7d4c07c4c GetFullPathNameW 17984->18006 17990 7ff7d4c1048b 17989->17990 17991 7ff7d4c10481 17989->17991 17992 7ff7d4c04f08 _get_daylight 11 API calls 17990->17992 17991->17990 17995 7ff7d4c104a7 17991->17995 17997 7ff7d4c10493 17992->17997 17994 7ff7d4c079b9 17994->17974 17994->17975 17995->17994 17996 7ff7d4c04f08 _get_daylight 11 API calls 17995->17996 17996->17997 17999 7ff7d4c07bfe GetLastError 17998->17999 18002 7ff7d4c07c14 17998->18002 18000 7ff7d4c04e7c _fread_nolock 11 API calls 17999->18000 18001 7ff7d4c07c10 18002->18001 18004 7ff7d4c04f08 _get_daylight 11 API calls 18002->18004 18004->18001 18007 7ff7d4c07c7f GetLastError 18006->18007 18011 7ff7d4c07c95 __std_exception_copy 18006->18011 18008 7ff7d4c04e7c _fread_nolock 11 API calls 18007->18008 18012 7ff7d4c07c91 18011->18012 18013 7ff7d4c07cef GetFullPathNameW 18011->18013 18013->18007 18013->18012 18026 7ff7d4c105d0 18023->18026 18027 7ff7d4c105fb 18026->18027 18028 7ff7d4c10612 18026->18028 18031 7ff7d4c04f08 _get_daylight 11 API calls 18027->18031 18029 7ff7d4c10637 18028->18029 18030 7ff7d4c10616 18028->18030 18064 7ff7d4c0f5b8 18029->18064 18052 7ff7d4c1073c 18030->18052 18034 7ff7d4c10600 18031->18034 18053 7ff7d4c10786 18052->18053 18054 7ff7d4c10756 18052->18054 18119 7ff7d4c11558 18078->18119 18178 7ff7d4c112d0 18119->18178 18199 7ff7d4c102d8 EnterCriticalSection 18178->18199 18202 7ff7d4bf45c0 108 API calls 18201->18202 18203 7ff7d4bf1493 18202->18203 18204 7ff7d4bf149b 18203->18204 18205 7ff7d4bf14bc 18203->18205 18206 7ff7d4bf2710 54 API calls 18204->18206 18207 7ff7d4c006d4 73 API calls 18205->18207 18208 7ff7d4bf14ab 18206->18208 18209 7ff7d4bf14d1 18207->18209 18208->16692 18210 7ff7d4bf14d5 18209->18210 18211 7ff7d4bf14f8 18209->18211 18212 7ff7d4c04f08 _get_daylight 11 API calls 18210->18212 18215 7ff7d4bf1532 18211->18215 18216 7ff7d4bf1508 18211->18216 18213 7ff7d4bf14da 18212->18213 18214 7ff7d4bf2910 54 API calls 18213->18214 18224 7ff7d4bf14f3 __std_exception_copy 18214->18224 18217 7ff7d4bf1538 18215->18217 18223 7ff7d4bf154b 18215->18223 18218 7ff7d4c04f08 _get_daylight 11 API calls 18216->18218 18231 7ff7d4bf1210 18217->18231 18219 7ff7d4bf1510 18218->18219 18221 7ff7d4bf2910 54 API calls 18219->18221 18221->18224 18222 7ff7d4c0004c 74 API calls 18225 7ff7d4bf15c4 18222->18225 18223->18224 18226 7ff7d4c0039c _fread_nolock 53 API calls 18223->18226 18227 7ff7d4bf15d6 18223->18227 18224->18222 18225->16692 18226->18223 18228 7ff7d4c04f08 _get_daylight 11 API calls 18227->18228 18229 7ff7d4bf15db 18228->18229 18230 7ff7d4bf2910 54 API calls 18229->18230 18230->18224 18232 7ff7d4bf1268 18231->18232 18233 7ff7d4bf126f 18232->18233 18234 7ff7d4bf1297 18232->18234 18235 7ff7d4bf2710 54 API calls 18233->18235 18237 7ff7d4bf12d4 18234->18237 18238 7ff7d4bf12b1 18234->18238 18236 7ff7d4bf1282 18235->18236 18236->18224 18241 7ff7d4bf12e6 18237->18241 18251 7ff7d4bf1309 memcpy_s 18237->18251 18239 7ff7d4c04f08 _get_daylight 11 API calls 18238->18239 18243 7ff7d4c04f08 _get_daylight 11 API calls 18241->18243 18259 7ff7d4bf18d5 18257->18259 18260 7ff7d4bf1865 18257->18260 18259->16721 18260->18259 18326 7ff7d4c05024 18260->18326 18262 7ff7d4bf456a 18261->18262 18263 7ff7d4bf9390 2 API calls 18262->18263 18269 7ff7d4bf7e2e 18267->18269 18268 7ff7d4bf7f52 18269->18268 18270 7ff7d4bf1c80 49 API calls 18269->18270 18279 7ff7d4bf1613 18278->18279 18280 7ff7d4bf1637 18278->18280 18341 7ff7d4bf1050 18279->18341 18282 7ff7d4bf45c0 108 API calls 18280->18282 18387 7ff7d4bf9390 2 API calls 18386->18387 18388 7ff7d4bf8e94 LoadLibraryExW 18387->18388 18463 7ff7d4bf718b 18462->18463 18465 7ff7d4bf7144 18462->18465 18463->16774 18464 7ff7d4c05024 45 API calls 18464->18465 18465->18463 18465->18464 18467 7ff7d4bf41a1 18466->18467 18468 7ff7d4bf44e0 49 API calls 18467->18468 18469 7ff7d4bf41db 18468->18469 18470 7ff7d4bf44e0 49 API calls 18469->18470 18471 7ff7d4bf41eb 18470->18471 18472 7ff7d4bf420d 18471->18472 18473 7ff7d4bf423c 18471->18473 18513 7ff7d4bf4110 18472->18513 18474 7ff7d4bf4110 51 API calls 18473->18474 18476 7ff7d4bf423a 18474->18476 18477 7ff7d4bf429c 18476->18477 18478 7ff7d4bf4267 18476->18478 18480 7ff7d4bf4110 51 API calls 18477->18480 18520 7ff7d4bf7cf0 18478->18520 18482 7ff7d4bf42c0 18480->18482 18485 7ff7d4bf4110 51 API calls 18482->18485 18491 7ff7d4bf4312 18482->18491 18483 7ff7d4bf4393 18486 7ff7d4bf1950 115 API calls 18483->18486 18484 7ff7d4bf2710 54 API calls 18488 7ff7d4bf4297 18484->18488 18489 7ff7d4bf42e9 18485->18489 18490 7ff7d4bf439d 18486->18490 18487 7ff7d4bfc550 _log10_special 8 API calls 18492 7ff7d4bf4435 18487->18492 18488->18487 18489->18491 18493 7ff7d4bf4110 51 API calls 18489->18493 18494 7ff7d4bf43a5 18490->18494 18495 7ff7d4bf43fe 18490->18495 18491->18483 18497 7ff7d4bf438c 18491->18497 18499 7ff7d4bf4317 18491->18499 18501 7ff7d4bf437b 18491->18501 18492->16774 18493->18491 18498 7ff7d4bf1840 45 API calls 18494->18498 18496 7ff7d4bf2710 54 API calls 18495->18496 18496->18499 18497->18494 18497->18499 18500 7ff7d4bf43b7 18498->18500 18502 7ff7d4bf2710 54 API calls 18499->18502 18503 7ff7d4bf43d2 18500->18503 18504 7ff7d4bf43bc 18500->18504 18505 7ff7d4bf2710 54 API calls 18501->18505 18502->18488 18507 7ff7d4bf1600 118 API calls 18503->18507 18506 7ff7d4bf2710 54 API calls 18504->18506 18505->18499 18506->18488 18511 7ff7d4bf1c80 49 API calls 18510->18511 18512 7ff7d4bf4474 18511->18512 18512->16774 18514 7ff7d4bf4136 18513->18514 18515 7ff7d4c04984 49 API calls 18514->18515 18516 7ff7d4bf415c 18515->18516 18517 7ff7d4bf416d 18516->18517 18518 7ff7d4bf4560 10 API calls 18516->18518 18517->18476 18519 7ff7d4bf417f 18518->18519 18519->18476 18521 7ff7d4bf7d05 18520->18521 18522 7ff7d4bf45c0 108 API calls 18521->18522 18523 7ff7d4bf7d2b 18522->18523 18524 7ff7d4bf45c0 108 API calls 18523->18524 18537 7ff7d4bf7d52 18523->18537 18525 7ff7d4bf7d42 18524->18525 18527 7ff7d4bf7d4d 18525->18527 18528 7ff7d4bf7d5c 18525->18528 18526 7ff7d4bfc550 _log10_special 8 API calls 18529 7ff7d4bf4277 18526->18529 18530 7ff7d4c0004c 74 API calls 18527->18530 18546 7ff7d4c000e4 18528->18546 18529->18484 18529->18488 18530->18537 18537->18526 18573 7ff7d4bf6375 18572->18573 18574 7ff7d4bf1c80 49 API calls 18573->18574 18575 7ff7d4bf63b1 18574->18575 18576 7ff7d4bf63dd 18575->18576 18577 7ff7d4bf63ba 18575->18577 18578 7ff7d4bf4630 49 API calls 18576->18578 18579 7ff7d4bf2710 54 API calls 18577->18579 18581 7ff7d4bf63f5 18578->18581 18582 7ff7d4bf63d3 18579->18582 18580 7ff7d4bf6413 18584 7ff7d4bf4560 10 API calls 18580->18584 18581->18580 18583 7ff7d4bf2710 54 API calls 18581->18583 18585 7ff7d4bfc550 _log10_special 8 API calls 18582->18585 18583->18580 18586 7ff7d4bf641d 18584->18586 18587 7ff7d4bf336e 18585->18587 18588 7ff7d4bf642b 18586->18588 18589 7ff7d4bf8e80 3 API calls 18586->18589 18587->16781 18603 7ff7d4bf6500 18587->18603 18590 7ff7d4bf4630 49 API calls 18588->18590 18589->18588 18591 7ff7d4bf6444 18590->18591 18592 7ff7d4bf6469 18591->18592 18593 7ff7d4bf6449 18591->18593 18594 7ff7d4bf8e80 3 API calls 18592->18594 18595 7ff7d4bf2710 54 API calls 18593->18595 18596 7ff7d4bf6476 18594->18596 18595->18582 18597 7ff7d4bf64c1 18596->18597 18598 7ff7d4bf6482 18596->18598 18662 7ff7d4bf5830 GetProcAddress 18597->18662 18599 7ff7d4bf9390 2 API calls 18598->18599 18752 7ff7d4bf5400 18603->18752 18605 7ff7d4bf6526 18606 7ff7d4bf653f 18605->18606 18607 7ff7d4bf652e 18605->18607 18759 7ff7d4bf4c90 18606->18759 18608 7ff7d4bf2710 54 API calls 18607->18608 18614 7ff7d4bf653a 18608->18614 18614->16783 18754 7ff7d4bf542c 18752->18754 18753 7ff7d4bf5434 18753->18605 18754->18753 18757 7ff7d4bf55d4 18754->18757 18783 7ff7d4c06aa4 18754->18783 18755 7ff7d4bf5797 __std_exception_copy 18755->18605 18756 7ff7d4bf47d0 47 API calls 18756->18757 18757->18755 18757->18756 18760 7ff7d4bf4cc0 18759->18760 18761 7ff7d4bfc550 _log10_special 8 API calls 18760->18761 18762 7ff7d4bf4d2a 18761->18762 18784 7ff7d4c06ad4 18783->18784 18787 7ff7d4c05fa0 18784->18787 18788 7ff7d4c05fd1 18787->18788 18790 7ff7d4c05fe3 18787->18790 18791 7ff7d4c04f08 _get_daylight 11 API calls 18788->18791 18789 7ff7d4c0602d 18793 7ff7d4c06048 18789->18793 18796 7ff7d4c047c0 45 API calls 18789->18796 18790->18789 18792 7ff7d4c05ff0 18790->18792 18794 7ff7d4c05fd6 18791->18794 18795 7ff7d4c0a814 _invalid_parameter_noinfo 37 API calls 18792->18795 18796->18793 18860->16790 19269 7ff7d4bfcb50 19270 7ff7d4bfcb60 19269->19270 19286 7ff7d4c09ba8 19270->19286 19272 7ff7d4bfcb6c 19292 7ff7d4bfce48 19272->19292 19274 7ff7d4bfd12c 7 API calls 19276 7ff7d4bfcc05 19274->19276 19275 7ff7d4bfcb84 _RTC_Initialize 19284 7ff7d4bfcbd9 19275->19284 19297 7ff7d4bfcff8 19275->19297 19278 7ff7d4bfcb99 19300 7ff7d4c09014 19278->19300 19284->19274 19285 7ff7d4bfcbf5 19284->19285 19287 7ff7d4c09bb9 19286->19287 19288 7ff7d4c09bc1 19287->19288 19289 7ff7d4c04f08 _get_daylight 11 API calls 19287->19289 19288->19272 19290 7ff7d4c09bd0 19289->19290 19291 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 19290->19291 19291->19288 19293 7ff7d4bfce59 19292->19293 19296 7ff7d4bfce5e __scrt_release_startup_lock 19292->19296 19294 7ff7d4bfd12c 7 API calls 19293->19294 19293->19296 19295 7ff7d4bfced2 19294->19295 19296->19275 19325 7ff7d4bfcfbc 19297->19325 19299 7ff7d4bfd001 19299->19278 19301 7ff7d4c09034 19300->19301 19323 7ff7d4bfcba5 19300->19323 19302 7ff7d4c0903c 19301->19302 19303 7ff7d4c09052 GetModuleFileNameW 19301->19303 19304 7ff7d4c04f08 _get_daylight 11 API calls 19302->19304 19307 7ff7d4c0907d 19303->19307 19305 7ff7d4c09041 19304->19305 19306 7ff7d4c0a8e0 _invalid_parameter_noinfo 37 API calls 19305->19306 19306->19323 19340 7ff7d4c08fb4 19307->19340 19310 7ff7d4c090c5 19311 7ff7d4c04f08 _get_daylight 11 API calls 19310->19311 19312 7ff7d4c090ca 19311->19312 19315 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19312->19315 19313 7ff7d4c090ff 19316 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19313->19316 19314 7ff7d4c090dd 19314->19313 19317 7ff7d4c0912b 19314->19317 19318 7ff7d4c09144 19314->19318 19315->19323 19316->19323 19319 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19317->19319 19321 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19318->19321 19320 7ff7d4c09134 19319->19320 19322 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19320->19322 19321->19313 19322->19323 19323->19284 19324 7ff7d4bfd0cc InitializeSListHead 19323->19324 19326 7ff7d4bfcfd6 19325->19326 19328 7ff7d4bfcfcf 19325->19328 19329 7ff7d4c0a1ec 19326->19329 19328->19299 19332 7ff7d4c09e28 19329->19332 19339 7ff7d4c102d8 EnterCriticalSection 19332->19339 19341 7ff7d4c09004 19340->19341 19342 7ff7d4c08fcc 19340->19342 19341->19310 19341->19314 19342->19341 19343 7ff7d4c0eb98 _get_daylight 11 API calls 19342->19343 19344 7ff7d4c08ffa 19343->19344 19345 7ff7d4c0a948 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 19344->19345 19345->19341

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 0 7ff7d4bf1000-7ff7d4bf3806 call 7ff7d4bffe18 call 7ff7d4bffe20 call 7ff7d4bfc850 call 7ff7d4c053f0 call 7ff7d4c05484 call 7ff7d4bf36b0 14 7ff7d4bf3814-7ff7d4bf3836 call 7ff7d4bf1950 0->14 15 7ff7d4bf3808-7ff7d4bf380f 0->15 21 7ff7d4bf391b-7ff7d4bf3931 call 7ff7d4bf45c0 14->21 22 7ff7d4bf383c-7ff7d4bf3856 call 7ff7d4bf1c80 14->22 16 7ff7d4bf3c97-7ff7d4bf3cb2 call 7ff7d4bfc550 15->16 28 7ff7d4bf3933-7ff7d4bf3960 call 7ff7d4bf7f90 21->28 29 7ff7d4bf396a-7ff7d4bf3978 call 7ff7d4bf2710 21->29 25 7ff7d4bf385b-7ff7d4bf389b call 7ff7d4bf8830 22->25 33 7ff7d4bf38c1-7ff7d4bf38cc call 7ff7d4c04f30 25->33 34 7ff7d4bf389d-7ff7d4bf38a3 25->34 41 7ff7d4bf3984-7ff7d4bf39a6 call 7ff7d4bf1c80 28->41 42 7ff7d4bf3962-7ff7d4bf3965 call 7ff7d4c0004c 28->42 36 7ff7d4bf397d-7ff7d4bf397f 29->36 49 7ff7d4bf38d2-7ff7d4bf38e1 call 7ff7d4bf8830 33->49 50 7ff7d4bf39fc-7ff7d4bf3a2a call 7ff7d4bf8940 call 7ff7d4bf89a0 * 3 33->50 38 7ff7d4bf38a5-7ff7d4bf38ad 34->38 39 7ff7d4bf38af-7ff7d4bf38bd call 7ff7d4bf89a0 34->39 37 7ff7d4bf3c8f 36->37 37->16 38->39 39->33 51 7ff7d4bf39b0-7ff7d4bf39b9 41->51 42->29 58 7ff7d4bf39f4-7ff7d4bf39f7 call 7ff7d4c04f30 49->58 59 7ff7d4bf38e7-7ff7d4bf38ed 49->59 76 7ff7d4bf3a2f-7ff7d4bf3a3e call 7ff7d4bf8830 50->76 51->51 54 7ff7d4bf39bb-7ff7d4bf39d8 call 7ff7d4bf1950 51->54 54->25 68 7ff7d4bf39de-7ff7d4bf39ef call 7ff7d4bf2710 54->68 58->50 64 7ff7d4bf38f0-7ff7d4bf38fc 59->64 65 7ff7d4bf3905-7ff7d4bf3908 64->65 66 7ff7d4bf38fe-7ff7d4bf3903 64->66 65->58 69 7ff7d4bf390e-7ff7d4bf3916 call 7ff7d4c04f30 65->69 66->64 66->65 68->37 69->76 79 7ff7d4bf3b45-7ff7d4bf3b53 76->79 80 7ff7d4bf3a44-7ff7d4bf3a47 76->80 81 7ff7d4bf3b59-7ff7d4bf3b5d 79->81 82 7ff7d4bf3a67 79->82 80->79 83 7ff7d4bf3a4d-7ff7d4bf3a50 80->83 84 7ff7d4bf3a6b-7ff7d4bf3a90 call 7ff7d4c04f30 81->84 82->84 85 7ff7d4bf3a56-7ff7d4bf3a5a 83->85 86 7ff7d4bf3b14-7ff7d4bf3b17 83->86 95 7ff7d4bf3a92-7ff7d4bf3aa6 call 7ff7d4bf8940 84->95 96 7ff7d4bf3aab-7ff7d4bf3ac0 84->96 85->86 87 7ff7d4bf3a60 85->87 88 7ff7d4bf3b2f-7ff7d4bf3b40 call 7ff7d4bf2710 86->88 89 7ff7d4bf3b19-7ff7d4bf3b1d 86->89 87->82 97 7ff7d4bf3c7f-7ff7d4bf3c87 88->97 89->88 91 7ff7d4bf3b1f-7ff7d4bf3b2a 89->91 91->84 95->96 99 7ff7d4bf3ac6-7ff7d4bf3aca 96->99 100 7ff7d4bf3be8-7ff7d4bf3bfa call 7ff7d4bf8830 96->100 97->37 102 7ff7d4bf3ad0-7ff7d4bf3ae8 call 7ff7d4c05250 99->102 103 7ff7d4bf3bcd-7ff7d4bf3be2 call 7ff7d4bf1940 99->103 108 7ff7d4bf3c2e 100->108 109 7ff7d4bf3bfc-7ff7d4bf3c02 100->109 113 7ff7d4bf3b62-7ff7d4bf3b7a call 7ff7d4c05250 102->113 114 7ff7d4bf3aea-7ff7d4bf3b02 call 7ff7d4c05250 102->114 103->99 103->100 115 7ff7d4bf3c31-7ff7d4bf3c40 call 7ff7d4c04f30 108->115 111 7ff7d4bf3c04-7ff7d4bf3c1c 109->111 112 7ff7d4bf3c1e-7ff7d4bf3c2c 109->112 111->115 112->115 122 7ff7d4bf3b7c-7ff7d4bf3b80 113->122 123 7ff7d4bf3b87-7ff7d4bf3b9f call 7ff7d4c05250 113->123 114->103 124 7ff7d4bf3b08-7ff7d4bf3b0f 114->124 125 7ff7d4bf3c46-7ff7d4bf3c4a 115->125 126 7ff7d4bf3d41-7ff7d4bf3d63 call 7ff7d4bf44e0 115->126 122->123 137 7ff7d4bf3ba1-7ff7d4bf3ba5 123->137 138 7ff7d4bf3bac-7ff7d4bf3bc4 call 7ff7d4c05250 123->138 124->103 128 7ff7d4bf3cd4-7ff7d4bf3ce6 call 7ff7d4bf8830 125->128 129 7ff7d4bf3c50-7ff7d4bf3c5f call 7ff7d4bf90e0 125->129 135 7ff7d4bf3d65-7ff7d4bf3d6f call 7ff7d4bf4630 126->135 136 7ff7d4bf3d71-7ff7d4bf3d82 call 7ff7d4bf1c80 126->136 141 7ff7d4bf3d35-7ff7d4bf3d3c 128->141 142 7ff7d4bf3ce8-7ff7d4bf3ceb 128->142 146 7ff7d4bf3cb3-7ff7d4bf3cbd call 7ff7d4bf8660 129->146 147 7ff7d4bf3c61 129->147 151 7ff7d4bf3d87-7ff7d4bf3d96 135->151 136->151 137->138 138->103 159 7ff7d4bf3bc6 138->159 148 7ff7d4bf3c68 call 7ff7d4bf2710 141->148 142->141 149 7ff7d4bf3ced-7ff7d4bf3d10 call 7ff7d4bf1c80 142->149 164 7ff7d4bf3cbf-7ff7d4bf3cc6 146->164 165 7ff7d4bf3cc8-7ff7d4bf3ccf 146->165 147->148 160 7ff7d4bf3c6d-7ff7d4bf3c77 148->160 166 7ff7d4bf3d12-7ff7d4bf3d26 call 7ff7d4bf2710 call 7ff7d4c04f30 149->166 167 7ff7d4bf3d2b-7ff7d4bf3d33 call 7ff7d4c04f30 149->167 156 7ff7d4bf3dbc-7ff7d4bf3dd2 call 7ff7d4bf9390 151->156 157 7ff7d4bf3d98-7ff7d4bf3d9f 151->157 172 7ff7d4bf3dd4 156->172 173 7ff7d4bf3de0-7ff7d4bf3dfc SetDllDirectoryW 156->173 157->156 162 7ff7d4bf3da1-7ff7d4bf3da5 157->162 159->103 160->97 162->156 168 7ff7d4bf3da7-7ff7d4bf3db6 LoadLibraryExW 162->168 164->148 165->151 166->160 167->151 168->156 172->173 176 7ff7d4bf3e02-7ff7d4bf3e11 call 7ff7d4bf8830 173->176 177 7ff7d4bf3ef9-7ff7d4bf3f00 173->177 188 7ff7d4bf3e13-7ff7d4bf3e19 176->188 189 7ff7d4bf3e2a-7ff7d4bf3e34 call 7ff7d4c04f30 176->189 180 7ff7d4bf3f06-7ff7d4bf3f0d 177->180 181 7ff7d4bf4000-7ff7d4bf4008 177->181 180->181 184 7ff7d4bf3f13-7ff7d4bf3f1d call 7ff7d4bf33c0 180->184 185 7ff7d4bf402d-7ff7d4bf405f call 7ff7d4bf36a0 call 7ff7d4bf3360 call 7ff7d4bf3670 call 7ff7d4bf6fc0 call 7ff7d4bf6d70 181->185 186 7ff7d4bf400a-7ff7d4bf4027 PostMessageW GetMessageW 181->186 184->160 198 7ff7d4bf3f23-7ff7d4bf3f37 call 7ff7d4bf90c0 184->198 186->185 192 7ff7d4bf3e25-7ff7d4bf3e27 188->192 193 7ff7d4bf3e1b-7ff7d4bf3e23 188->193 200 7ff7d4bf3eea-7ff7d4bf3ef4 call 7ff7d4bf8940 189->200 201 7ff7d4bf3e3a-7ff7d4bf3e40 189->201 192->189 193->192 207 7ff7d4bf3f5c-7ff7d4bf3f9f call 7ff7d4bf8940 call 7ff7d4bf89e0 call 7ff7d4bf6fc0 call 7ff7d4bf6d70 call 7ff7d4bf88e0 198->207 208 7ff7d4bf3f39-7ff7d4bf3f56 PostMessageW GetMessageW 198->208 200->177 201->200 206 7ff7d4bf3e46-7ff7d4bf3e4c 201->206 210 7ff7d4bf3e4e-7ff7d4bf3e50 206->210 211 7ff7d4bf3e57-7ff7d4bf3e59 206->211 249 7ff7d4bf3fa1-7ff7d4bf3fb7 call 7ff7d4bf8ed0 call 7ff7d4bf88e0 207->249 250 7ff7d4bf3fed-7ff7d4bf3ffb call 7ff7d4bf1900 207->250 208->207 214 7ff7d4bf3e52 210->214 215 7ff7d4bf3e5f-7ff7d4bf3e7b call 7ff7d4bf6dc0 call 7ff7d4bf7340 210->215 211->177 211->215 214->177 227 7ff7d4bf3e86-7ff7d4bf3e8d 215->227 228 7ff7d4bf3e7d-7ff7d4bf3e84 215->228 231 7ff7d4bf3e8f-7ff7d4bf3e9c call 7ff7d4bf6e00 227->231 232 7ff7d4bf3ea7-7ff7d4bf3eb1 call 7ff7d4bf71b0 227->232 230 7ff7d4bf3ed3-7ff7d4bf3ee8 call 7ff7d4bf2a50 call 7ff7d4bf6fc0 call 7ff7d4bf6d70 228->230 230->177 231->232 243 7ff7d4bf3e9e-7ff7d4bf3ea5 231->243 244 7ff7d4bf3eb3-7ff7d4bf3eba 232->244 245 7ff7d4bf3ebc-7ff7d4bf3eca call 7ff7d4bf74f0 232->245 243->230 244->230 245->177 257 7ff7d4bf3ecc 245->257 249->250 261 7ff7d4bf3fb9-7ff7d4bf3fce 249->261 250->160 257->230 262 7ff7d4bf3fd0-7ff7d4bf3fe3 call 7ff7d4bf2710 call 7ff7d4bf1900 261->262 263 7ff7d4bf3fe8 call 7ff7d4bf2a50 261->263 262->160 263->250
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: ErrorFileLastModuleName
    • String ID: Could not create temporary directory!$Could not load PyInstaller's embedded PKG archive from the executable (%s)$Could not side-load PyInstaller's PKG archive from external file (%s)$Failed to convert DLL search path!$Failed to initialize security descriptor for temporary directory!$Failed to load Tcl/Tk shared libraries for splash screen!$Failed to load splash screen resources!$Failed to remove temporary directory: %s$Failed to start splash screen!$Failed to unpack splash screen dependencies from PKG archive!$Invalid value in _PYI_PARENT_PROCESS_LEVEL: %s$MEI$PYINSTALLER_RESET_ENVIRONMENT$PYINSTALLER_STRICT_UNPACK_MODE$PYINSTALLER_SUPPRESS_SPLASH_SCREEN$Path exceeds PYI_PATH_MAX limit.$Py_GIL_DISABLED$VCRUNTIME140.dll$_PYI_APPLICATION_HOME_DIR$_PYI_APPLICATION_HOME_DIR not set for onefile child process!$_PYI_ARCHIVE_FILE$_PYI_PARENT_PROCESS_LEVEL$_PYI_SPLASH_IPC$pkg$pyi-contents-directory$pyi-disable-windowed-traceback$pyi-python-flag$pyi-runtime-tmpdir
    • API String ID: 2776309574-4232158417
    • Opcode ID: b74e8a98c54593439aa0340caf117dbcfb421d7150a5ef4d5d09467beb1d2dd6
    • Instruction ID: fd92c4e30c75df0ffac35321b8ac0ce9a1a0ce83a28034a64f15812869731a74
    • Opcode Fuzzy Hash: b74e8a98c54593439aa0340caf117dbcfb421d7150a5ef4d5d09467beb1d2dd6
    • Instruction Fuzzy Hash: 9A328B21A0E68291FA18FF22D4D42BDA6E1AF64780FC45073DA4D436C6EF2EE559C730

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 347 7ff7d4c16964-7ff7d4c169d7 call 7ff7d4c16698 350 7ff7d4c169d9-7ff7d4c169e2 call 7ff7d4c04ee8 347->350 351 7ff7d4c169f1-7ff7d4c169fb call 7ff7d4c08520 347->351 356 7ff7d4c169e5-7ff7d4c169ec call 7ff7d4c04f08 350->356 357 7ff7d4c169fd-7ff7d4c16a14 call 7ff7d4c04ee8 call 7ff7d4c04f08 351->357 358 7ff7d4c16a16-7ff7d4c16a7f CreateFileW 351->358 374 7ff7d4c16d32-7ff7d4c16d52 356->374 357->356 359 7ff7d4c16afc-7ff7d4c16b07 GetFileType 358->359 360 7ff7d4c16a81-7ff7d4c16a87 358->360 367 7ff7d4c16b09-7ff7d4c16b44 GetLastError call 7ff7d4c04e7c CloseHandle 359->367 368 7ff7d4c16b5a-7ff7d4c16b61 359->368 364 7ff7d4c16ac9-7ff7d4c16af7 GetLastError call 7ff7d4c04e7c 360->364 365 7ff7d4c16a89-7ff7d4c16a8d 360->365 364->356 365->364 372 7ff7d4c16a8f-7ff7d4c16ac7 CreateFileW 365->372 367->356 382 7ff7d4c16b4a-7ff7d4c16b55 call 7ff7d4c04f08 367->382 370 7ff7d4c16b69-7ff7d4c16b6c 368->370 371 7ff7d4c16b63-7ff7d4c16b67 368->371 377 7ff7d4c16b72-7ff7d4c16bc7 call 7ff7d4c08438 370->377 378 7ff7d4c16b6e 370->378 371->377 372->359 372->364 386 7ff7d4c16bc9-7ff7d4c16bd5 call 7ff7d4c168a0 377->386 387 7ff7d4c16be6-7ff7d4c16c17 call 7ff7d4c16418 377->387 378->377 382->356 386->387 394 7ff7d4c16bd7 386->394 392 7ff7d4c16c19-7ff7d4c16c1b 387->392 393 7ff7d4c16c1d-7ff7d4c16c5f 387->393 395 7ff7d4c16bd9-7ff7d4c16be1 call 7ff7d4c0aac0 392->395 396 7ff7d4c16c81-7ff7d4c16c8c 393->396 397 7ff7d4c16c61-7ff7d4c16c65 393->397 394->395 395->374 399 7ff7d4c16d30 396->399 400 7ff7d4c16c92-7ff7d4c16c96 396->400 397->396 398 7ff7d4c16c67-7ff7d4c16c7c 397->398 398->396 399->374 400->399 402 7ff7d4c16c9c-7ff7d4c16ce1 CloseHandle CreateFileW 400->402 404 7ff7d4c16ce3-7ff7d4c16d11 GetLastError call 7ff7d4c04e7c call 7ff7d4c08660 402->404 405 7ff7d4c16d16-7ff7d4c16d2b 402->405 404->405 405->399
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type
    • String ID:
    • API String ID: 1617910340-0
    • Opcode ID: baaa1bd2bfcf3e8d87424e6061cd652f961a4b3dae6ad7eaae94581ee29caa63
    • Instruction ID: 1df3d2a87f81a99565f9fac19ed0c6a15e668d2e0c3b4dd94c6933c3d35e328d
    • Opcode Fuzzy Hash: baaa1bd2bfcf3e8d87424e6061cd652f961a4b3dae6ad7eaae94581ee29caa63
    • Instruction Fuzzy Hash: 2DC1BE36B28A4186EB10EF6AC4906AC7771EB49BD8F855237DE2E57794DF38E051C320

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Find$CloseFileFirst
    • String ID:
    • API String ID: 2295610775-0
    • Opcode ID: 3849ca1beccae91a12aeced599bc73bdbec409d6dd090ca7d2ec6d5d284a4285
    • Instruction ID: 4d6f1465760cd0638633aa90f1321f23fcdb8aad76469c25edad619bbb745b18
    • Opcode Fuzzy Hash: 3849ca1beccae91a12aeced599bc73bdbec409d6dd090ca7d2ec6d5d284a4285
    • Instruction Fuzzy Hash: 8BF0A422A1964186FB60AFA1F4C976EB3A0AB94368FC40237D96D02AD4DF3CD0498A10

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 269 7ff7d4bf1950-7ff7d4bf198b call 7ff7d4bf45c0 272 7ff7d4bf1991-7ff7d4bf19d1 call 7ff7d4bf7f90 269->272 273 7ff7d4bf1c4e-7ff7d4bf1c72 call 7ff7d4bfc550 269->273 278 7ff7d4bf1c3b-7ff7d4bf1c3e call 7ff7d4c0004c 272->278 279 7ff7d4bf19d7-7ff7d4bf19e7 call 7ff7d4c006d4 272->279 283 7ff7d4bf1c43-7ff7d4bf1c4b 278->283 284 7ff7d4bf19e9-7ff7d4bf1a03 call 7ff7d4c04f08 call 7ff7d4bf2910 279->284 285 7ff7d4bf1a08-7ff7d4bf1a24 call 7ff7d4c0039c 279->285 283->273 284->278 290 7ff7d4bf1a45-7ff7d4bf1a5a call 7ff7d4c04f28 285->290 291 7ff7d4bf1a26-7ff7d4bf1a40 call 7ff7d4c04f08 call 7ff7d4bf2910 285->291 299 7ff7d4bf1a7b-7ff7d4bf1b14 call 7ff7d4bf1c80 * 2 call 7ff7d4c006d4 call 7ff7d4c04f44 290->299 300 7ff7d4bf1a5c-7ff7d4bf1a76 call 7ff7d4c04f08 call 7ff7d4bf2910 290->300 291->278 314 7ff7d4bf1b35-7ff7d4bf1b4e call 7ff7d4c0039c 299->314 315 7ff7d4bf1b16-7ff7d4bf1b30 call 7ff7d4c04f08 call 7ff7d4bf2910 299->315 300->278 321 7ff7d4bf1b6f-7ff7d4bf1b8b call 7ff7d4c00110 314->321 322 7ff7d4bf1b50-7ff7d4bf1b6a call 7ff7d4c04f08 call 7ff7d4bf2910 314->322 315->278 329 7ff7d4bf1b8d-7ff7d4bf1b99 call 7ff7d4bf2710 321->329 330 7ff7d4bf1b9e-7ff7d4bf1bac 321->330 322->278 329->278 330->278 333 7ff7d4bf1bb2-7ff7d4bf1bb9 330->333 335 7ff7d4bf1bc1-7ff7d4bf1bc7 333->335 336 7ff7d4bf1be0-7ff7d4bf1bef 335->336 337 7ff7d4bf1bc9-7ff7d4bf1bd6 335->337 336->336 338 7ff7d4bf1bf1-7ff7d4bf1bfa 336->338 337->338 339 7ff7d4bf1c0f 338->339 340 7ff7d4bf1bfc-7ff7d4bf1bff 338->340 342 7ff7d4bf1c11-7ff7d4bf1c24 339->342 340->339 341 7ff7d4bf1c01-7ff7d4bf1c04 340->341 341->339 343 7ff7d4bf1c06-7ff7d4bf1c09 341->343 344 7ff7d4bf1c26 342->344 345 7ff7d4bf1c2d-7ff7d4bf1c39 342->345 343->339 346 7ff7d4bf1c0b-7ff7d4bf1c0d 343->346 344->345 345->278 345->335 346->342
    APIs
      • Part of subcall function 00007FF7D4BF7F90: _fread_nolock.LIBCMT ref: 00007FF7D4BF803A
    • _fread_nolock.LIBCMT ref: 00007FF7D4BF1A1B
      • Part of subcall function 00007FF7D4BF2910: GetCurrentProcessId.KERNEL32(?,?,?,?,00000000,00000000,?,00000000,00007FF7D4BF1B6A), ref: 00007FF7D4BF295E
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _fread_nolock$CurrentProcess
    • String ID: Could not allocate buffer for TOC!$Could not allocate memory for archive structure!$Could not read full TOC!$Error on file.$Failed to read cookie!$Failed to seek to cookie position!$MEI$calloc$fread$fseek$malloc
    • API String ID: 2397952137-3497178890
    • Opcode ID: 63c30398f30ea4f79a670da16c10e9057635e87f15f1424072537686b1cc1600
    • Instruction ID: e5fdcfdfa8beb01ca3a4201102eddda0513574a4708e32d40c790fbc3dc9fec5
    • Opcode Fuzzy Hash: 63c30398f30ea4f79a670da16c10e9057635e87f15f1424072537686b1cc1600
    • Instruction Fuzzy Hash: B3817171A0D68685EB20EF26D0C42BDA3E0EF58784FC45433D98D57786EE3EE9458B60

    Control-flow Graph

    APIs
    • GetModuleFileNameW.KERNEL32(?,00007FF7D4BF3804), ref: 00007FF7D4BF36E1
    • GetLastError.KERNEL32(?,00007FF7D4BF3804), ref: 00007FF7D4BF36EB
      • Part of subcall function 00007FF7D4BF2C50: GetCurrentProcessId.KERNEL32(?,?,?,?,?,?,?,?,00007FF7D4BF3706,?,00007FF7D4BF3804), ref: 00007FF7D4BF2C9E
      • Part of subcall function 00007FF7D4BF2C50: FormatMessageW.KERNEL32(?,?,?,?,?,?,?,?,00007FF7D4BF3706,?,00007FF7D4BF3804), ref: 00007FF7D4BF2D63
      • Part of subcall function 00007FF7D4BF2C50: MessageBoxW.USER32 ref: 00007FF7D4BF2D99
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Message$CurrentErrorFileFormatLastModuleNameProcess
    • String ID: Failed to convert executable path to UTF-8.$Failed to obtain executable path.$Failed to resolve full path to executable %ls.$GetModuleFileNameW$\\?\
    • API String ID: 3187769757-2863816727
    • Opcode ID: 7a7bb6314ef99d1ea6b5a99dff4d55fbb7227be169d5ba9e119ffda366a0a745
    • Instruction ID: f879f41508295897989f910ea3496c896e4f2d60f635bc9d34ab33585f245d7e
    • Opcode Fuzzy Hash: 7a7bb6314ef99d1ea6b5a99dff4d55fbb7227be169d5ba9e119ffda366a0a745
    • Instruction Fuzzy Hash: 64219761B1DA4241FA20BF26E8953FEE2A0BF68394FC05133E55D825E5EE2DE504C720

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 438 7ff7d4c0ba5c-7ff7d4c0ba82 439 7ff7d4c0ba9d-7ff7d4c0baa1 438->439 440 7ff7d4c0ba84-7ff7d4c0ba98 call 7ff7d4c04ee8 call 7ff7d4c04f08 438->440 441 7ff7d4c0be77-7ff7d4c0be83 call 7ff7d4c04ee8 call 7ff7d4c04f08 439->441 442 7ff7d4c0baa7-7ff7d4c0baae 439->442 454 7ff7d4c0be8e 440->454 461 7ff7d4c0be89 call 7ff7d4c0a8e0 441->461 442->441 444 7ff7d4c0bab4-7ff7d4c0bae2 442->444 444->441 448 7ff7d4c0bae8-7ff7d4c0baef 444->448 451 7ff7d4c0bb08-7ff7d4c0bb0b 448->451 452 7ff7d4c0baf1-7ff7d4c0bb03 call 7ff7d4c04ee8 call 7ff7d4c04f08 448->452 457 7ff7d4c0bb11-7ff7d4c0bb17 451->457 458 7ff7d4c0be73-7ff7d4c0be75 451->458 452->461 459 7ff7d4c0be91-7ff7d4c0bea8 454->459 457->458 462 7ff7d4c0bb1d-7ff7d4c0bb20 457->462 458->459 461->454 462->452 465 7ff7d4c0bb22-7ff7d4c0bb47 462->465 467 7ff7d4c0bb49-7ff7d4c0bb4b 465->467 468 7ff7d4c0bb7a-7ff7d4c0bb81 465->468 469 7ff7d4c0bb4d-7ff7d4c0bb54 467->469 470 7ff7d4c0bb72-7ff7d4c0bb78 467->470 471 7ff7d4c0bb83-7ff7d4c0bb8f call 7ff7d4c0d5fc 468->471 472 7ff7d4c0bb56-7ff7d4c0bb6d call 7ff7d4c04ee8 call 7ff7d4c04f08 call 7ff7d4c0a8e0 468->472 469->470 469->472 474 7ff7d4c0bbf8-7ff7d4c0bc0f 470->474 479 7ff7d4c0bb94-7ff7d4c0bbab call 7ff7d4c0a948 * 2 471->479 502 7ff7d4c0bd00 472->502 477 7ff7d4c0bc8a-7ff7d4c0bc94 call 7ff7d4c1391c 474->477 478 7ff7d4c0bc11-7ff7d4c0bc19 474->478 489 7ff7d4c0bc9a-7ff7d4c0bcaf 477->489 490 7ff7d4c0bd1e 477->490 478->477 482 7ff7d4c0bc1b-7ff7d4c0bc1d 478->482 498 7ff7d4c0bbc8-7ff7d4c0bbf3 call 7ff7d4c0c284 479->498 499 7ff7d4c0bbad-7ff7d4c0bbc3 call 7ff7d4c04f08 call 7ff7d4c04ee8 479->499 482->477 486 7ff7d4c0bc1f-7ff7d4c0bc35 482->486 486->477 491 7ff7d4c0bc37-7ff7d4c0bc43 486->491 489->490 496 7ff7d4c0bcb1-7ff7d4c0bcc3 GetConsoleMode 489->496 494 7ff7d4c0bd23-7ff7d4c0bd43 ReadFile 490->494 491->477 497 7ff7d4c0bc45-7ff7d4c0bc47 491->497 500 7ff7d4c0bd49-7ff7d4c0bd51 494->500 501 7ff7d4c0be3d-7ff7d4c0be46 GetLastError 494->501 496->490 503 7ff7d4c0bcc5-7ff7d4c0bccd 496->503 497->477 504 7ff7d4c0bc49-7ff7d4c0bc61 497->504 498->474 499->502 500->501 507 7ff7d4c0bd57 500->507 510 7ff7d4c0be48-7ff7d4c0be5e call 7ff7d4c04f08 call 7ff7d4c04ee8 501->510 511 7ff7d4c0be63-7ff7d4c0be66 501->511 512 7ff7d4c0bd03-7ff7d4c0bd0d call 7ff7d4c0a948 502->512 503->494 509 7ff7d4c0bccf-7ff7d4c0bcf1 ReadConsoleW 503->509 504->477 505 7ff7d4c0bc63-7ff7d4c0bc6f 504->505 505->477 513 7ff7d4c0bc71-7ff7d4c0bc73 505->513 517 7ff7d4c0bd5e-7ff7d4c0bd73 507->517 519 7ff7d4c0bd12-7ff7d4c0bd1c 509->519 520 7ff7d4c0bcf3 GetLastError 509->520 510->502 514 7ff7d4c0bcf9-7ff7d4c0bcfb call 7ff7d4c04e7c 511->514 515 7ff7d4c0be6c-7ff7d4c0be6e 511->515 512->459 513->477 524 7ff7d4c0bc75-7ff7d4c0bc85 513->524 514->502 515->512 517->512 526 7ff7d4c0bd75-7ff7d4c0bd80 517->526 519->517 520->514 524->477 530 7ff7d4c0bda7-7ff7d4c0bdaf 526->530 531 7ff7d4c0bd82-7ff7d4c0bd9b call 7ff7d4c0b674 526->531 535 7ff7d4c0be2b-7ff7d4c0be38 call 7ff7d4c0b4b4 530->535 536 7ff7d4c0bdb1-7ff7d4c0bdc3 530->536 538 7ff7d4c0bda0-7ff7d4c0bda2 531->538 535->538 539 7ff7d4c0be1e-7ff7d4c0be26 536->539 540 7ff7d4c0bdc5 536->540 538->512 539->512 542 7ff7d4c0bdca-7ff7d4c0bdd1 540->542 543 7ff7d4c0be0d-7ff7d4c0be18 542->543 544 7ff7d4c0bdd3-7ff7d4c0bdd7 542->544 543->539 545 7ff7d4c0bdd9-7ff7d4c0bde0 544->545 546 7ff7d4c0bdf3 544->546 545->546 547 7ff7d4c0bde2-7ff7d4c0bde6 545->547 548 7ff7d4c0bdf9-7ff7d4c0be09 546->548 547->546 549 7ff7d4c0bde8-7ff7d4c0bdf1 547->549 548->542 550 7ff7d4c0be0b 548->550 549->548 550->539
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: c3f57b6cd1f658b3a1cfdd45bc75f21d2f6c8be166295f0eb40444005b392bd6
    • Instruction ID: cbdb1429d93026cf417dadaf29fc13c423dd61328c31f7a3867daf1afdaa8a3c
    • Opcode Fuzzy Hash: c3f57b6cd1f658b3a1cfdd45bc75f21d2f6c8be166295f0eb40444005b392bd6
    • Instruction Fuzzy Hash: 04C1C32290C78692E660FF97D4882BDEB50EB81BC0FD54133EA5D27795EE7CE8458720

    Control-flow Graph

    APIs
    • GetCurrentProcessId.KERNEL32(?,00000000,00000000,?,00000000,00007FF7D4BF1B99), ref: 00007FF7D4BF2760
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CurrentProcess
    • String ID: ERROR$Error$Error [ANSI Fallback]$[PYI-%d:%s]
    • API String ID: 2050909247-1591803126
    • Opcode ID: a4fe537d534c2fb53088f6f6b76b448a80ccad2508d4dc842b27f1a8247accfc
    • Instruction ID: 87d32dd62996d86ff9e6e6f7de54d293b9b5e16de2a2160e54a1e4bebd6f69ef
    • Opcode Fuzzy Hash: a4fe537d534c2fb53088f6f6b76b448a80ccad2508d4dc842b27f1a8247accfc
    • Instruction Fuzzy Hash: F8217F72A19B8152E620EF52F8817EAA2A4FB883C4FC01137EE8C53659EF7DD5458B50

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_get_show_window_mode__scrt_release_startup_lock
    • String ID:
    • API String ID: 3251591375-0
    • Opcode ID: b3dd18574e8b698ea28c35ed35ed65a6730a16d6ac14c38d0a8ba428da0d66bc
    • Instruction ID: b920096afc64fbc52ed260e0bf488e3dd39e6be973b86fcd0aff6bd7b70c12cf
    • Opcode Fuzzy Hash: b3dd18574e8b698ea28c35ed35ed65a6730a16d6ac14c38d0a8ba428da0d66bc
    • Instruction Fuzzy Hash: 8C318B21E0A14341FA24BF67D4E53BD92E1AF61384FC44437EA4E472E3DE2EA9449A70

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Process$CurrentExitTerminate
    • String ID:
    • API String ID: 1703294689-0
    • Opcode ID: 148d460979eed4a43ebbf671c65dc2dc638c0d89c9c01e8e00358d5495882c84
    • Instruction ID: 69ec224c0ff19559d41d0ec7f977a1ea61f4af4fcef08c00d28f78942eb794f2
    • Opcode Fuzzy Hash: 148d460979eed4a43ebbf671c65dc2dc638c0d89c9c01e8e00358d5495882c84
    • Instruction Fuzzy Hash: 75D09E14B0870642EB143F72DCD92BD92656F48781FD5143BC81F16397ED2CA8594730

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 632 7ff7d4c0013c-7ff7d4c00169 633 7ff7d4c00185 632->633 634 7ff7d4c0016b-7ff7d4c0016e 632->634 636 7ff7d4c00187-7ff7d4c0019b 633->636 634->633 635 7ff7d4c00170-7ff7d4c00173 634->635 637 7ff7d4c00175-7ff7d4c0017a call 7ff7d4c04f08 635->637 638 7ff7d4c0019c-7ff7d4c0019f 635->638 649 7ff7d4c00180 call 7ff7d4c0a8e0 637->649 640 7ff7d4c001a1-7ff7d4c001ad 638->640 641 7ff7d4c001af-7ff7d4c001b3 638->641 640->641 643 7ff7d4c001da-7ff7d4c001e3 640->643 644 7ff7d4c001b5-7ff7d4c001bf call 7ff7d4c1a4d0 641->644 645 7ff7d4c001c7-7ff7d4c001ca 641->645 647 7ff7d4c001e5-7ff7d4c001e8 643->647 648 7ff7d4c001ea 643->648 644->645 645->637 646 7ff7d4c001cc-7ff7d4c001d8 645->646 646->637 646->643 652 7ff7d4c001ef-7ff7d4c0020e 647->652 648->652 649->633 654 7ff7d4c00355-7ff7d4c00358 652->654 655 7ff7d4c00214-7ff7d4c00222 652->655 654->636 656 7ff7d4c00224-7ff7d4c0022b 655->656 657 7ff7d4c0029a-7ff7d4c0029f 655->657 656->657 658 7ff7d4c0022d 656->658 659 7ff7d4c002a1-7ff7d4c002ad 657->659 660 7ff7d4c0030c-7ff7d4c0030f call 7ff7d4c0beac 657->660 662 7ff7d4c00233-7ff7d4c0023d 658->662 663 7ff7d4c00380 658->663 664 7ff7d4c002af-7ff7d4c002b6 659->664 665 7ff7d4c002b9-7ff7d4c002bf 659->665 667 7ff7d4c00314-7ff7d4c00317 660->667 668 7ff7d4c00243-7ff7d4c00249 662->668 669 7ff7d4c0035d-7ff7d4c00361 662->669 666 7ff7d4c00385-7ff7d4c00390 663->666 664->665 665->669 670 7ff7d4c002c5-7ff7d4c002e2 call 7ff7d4c0a47c call 7ff7d4c0ba5c 665->670 666->636 667->666 671 7ff7d4c00319-7ff7d4c0031c 667->671 672 7ff7d4c00281-7ff7d4c00295 668->672 673 7ff7d4c0024b-7ff7d4c0024e 668->673 674 7ff7d4c00363-7ff7d4c0036b call 7ff7d4c1a4d0 669->674 675 7ff7d4c00370-7ff7d4c0037b call 7ff7d4c04f08 669->675 690 7ff7d4c002e7-7ff7d4c002e9 670->690 671->669 678 7ff7d4c0031e-7ff7d4c00335 671->678 679 7ff7d4c0033c-7ff7d4c00347 672->679 680 7ff7d4c00250-7ff7d4c00256 673->680 681 7ff7d4c0026c-7ff7d4c00277 call 7ff7d4c04f08 call 7ff7d4c0a8e0 673->681 674->675 675->649 678->679 679->655 687 7ff7d4c0034d 679->687 688 7ff7d4c00262-7ff7d4c00267 call 7ff7d4c1a4d0 680->688 689 7ff7d4c00258-7ff7d4c00260 call 7ff7d4c19e30 680->689 698 7ff7d4c0027c 681->698 687->654 688->681 689->698 695 7ff7d4c00395-7ff7d4c0039a 690->695 696 7ff7d4c002ef 690->696 695->666 696->663 699 7ff7d4c002f5-7ff7d4c0030a 696->699 698->672 699->679
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: e80cfa20b6c7ebf2f27a6dba6ddb06cb01cda21135ba71ef9e2cf3b7629ca058
    • Instruction ID: 000d353d04f4e73b1310f7598f84d50b7f3af4907026d13c0020e0c9150f6771
    • Opcode Fuzzy Hash: e80cfa20b6c7ebf2f27a6dba6ddb06cb01cda21135ba71ef9e2cf3b7629ca058
    • Instruction Fuzzy Hash: 1451F421B0964186E729BE27E48867EA291BF44BE4FDA4737DD6D277C5CE3CE4018720

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: ErrorFileLastPointer
    • String ID:
    • API String ID: 2976181284-0
    • Opcode ID: 7d52f85de62641260209e8dbb28c5e1251e01e8bf24b4306ce9dcd9badf2c9c6
    • Instruction ID: 394cc1892ebd43eb298096cbc4606e54c311c9d8ed5eb8e6c8b3fbf85ee0cd96
    • Opcode Fuzzy Hash: 7d52f85de62641260209e8dbb28c5e1251e01e8bf24b4306ce9dcd9badf2c9c6
    • Instruction Fuzzy Hash: 0711B265608A8181DA20AF26E89816DE361AB45FF4FD44333EEBD177D9DE3CD0118B50

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Message$ByteCharMultiWide
    • String ID:
    • API String ID: 1878133881-0
    • Opcode ID: 516091698330144c171d35b2bbe34a92ef9056074b99cc756242dd1ed7aaaa5e
    • Instruction ID: 38b39917d7d7871007e440c7a70ceb881dfe09f641dd7775f1795c8e97772986
    • Opcode Fuzzy Hash: 516091698330144c171d35b2bbe34a92ef9056074b99cc756242dd1ed7aaaa5e
    • Instruction Fuzzy Hash: 4F01DF62B05B8184E624AF16E4892BDA3A5AF5DBC4FC44036DE4D07756EE2CE548CA20

    Control-flow Graph

    APIs
    • CloseHandle.KERNELBASE(?,?,?,00007FF7D4C0A9D5,?,?,00000000,00007FF7D4C0AA8A), ref: 00007FF7D4C0ABC6
    • GetLastError.KERNEL32(?,?,?,00007FF7D4C0A9D5,?,?,00000000,00007FF7D4C0AA8A), ref: 00007FF7D4C0ABD0
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CloseErrorHandleLast
    • String ID:
    • API String ID: 918212764-0
    • Opcode ID: ae1e15d82824e1a5fac1c7302ca2ff5641fe0b0e43db7728cd9339717749910c
    • Instruction ID: 9f99bf13b6b0e12cffb410bccd94a98c2e5c492e7393b97519af954777e1e0cb
    • Opcode Fuzzy Hash: ae1e15d82824e1a5fac1c7302ca2ff5641fe0b0e43db7728cd9339717749910c
    • Instruction Fuzzy Hash: C021F620B1868242FEA0BF57D4D837D92829F94BD0FC4423BEA6E577C5CE6DE4414320

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 5a303e376ae32d58fd1e52f1ac99a64fdc1cf63549abbe0bdd4da132c2ec767e
    • Instruction ID: a35ab1c50d09035511b2617995939811c03b502bdd00a376af881142ea00f137
    • Opcode Fuzzy Hash: 5a303e376ae32d58fd1e52f1ac99a64fdc1cf63549abbe0bdd4da132c2ec767e
    • Instruction Fuzzy Hash: 0941B23690824187EA34EE9AE58827DB3A0EF55BC0FD01133D68E676D1DF6DE502CB60

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _fread_nolock
    • String ID:
    • API String ID: 840049012-0
    • Opcode ID: 0748e9379ee1a24a6dd361f3a2547f707c71d81643cc4b02aa9d5a9a64da41ab
    • Instruction ID: bd3b038fc293a3a81580f39922753286c7cc4dd272be7a77e2034f215453b6e8
    • Opcode Fuzzy Hash: 0748e9379ee1a24a6dd361f3a2547f707c71d81643cc4b02aa9d5a9a64da41ab
    • Instruction Fuzzy Hash: 78219C21B5AA5246EA10BE33E8843BED691BF55BC4FC84432EE4C17786CF7EE041C220
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: c2d01373d3233558d420055387ebca2c39d1ce99b2c1a08127fa32cb0ba5fec2
    • Instruction ID: 44cb21c11f683ad79774b486704639e37c887eabec05c11203a314ceead8b6e0
    • Opcode Fuzzy Hash: c2d01373d3233558d420055387ebca2c39d1ce99b2c1a08127fa32cb0ba5fec2
    • Instruction Fuzzy Hash: F7316022A1861286E711BF97D88937DA6A0AF80BE5FC10137EA5D273D2DE7CA4418735
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: HandleModule$AddressFreeLibraryProc
    • String ID:
    • API String ID: 3947729631-0
    • Opcode ID: 42808d7c08696a35870eb95595f0ae95ff90971c005bfc8769c42bb91e99b0de
    • Instruction ID: 08ffea56a4cb63d576c0c8695b246619a9503eb498ded28f83e2d113501394e9
    • Opcode Fuzzy Hash: 42808d7c08696a35870eb95595f0ae95ff90971c005bfc8769c42bb91e99b0de
    • Instruction Fuzzy Hash: 53218B72A057458AEF24AFA5C4883AC73A0EB04758FC44637D76C26AD5DF38D584CB60
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: d0ecc1d4814c8292f6d285d86e9f4332b8d7141ecd04c52723bb65a1ba9d936a
    • Instruction ID: c1dd79dade2e7e78a7187928088ce11b1fe3c247361f9c4176f4d8c73f267baf
    • Opcode Fuzzy Hash: d0ecc1d4814c8292f6d285d86e9f4332b8d7141ecd04c52723bb65a1ba9d936a
    • Instruction Fuzzy Hash: 8D115E31A1C64283EA60FF52D48827EE664AF95BC4FC44433EA8C77A96CF7DE5418760
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 3765a10cee1e255344ee37f065f4be71d58868c9c9e645b3056c9746d3493235
    • Instruction ID: 47c8447b6a91996acdc512d3b708ed361d1805ea63cabdb3e6c1028433661735
    • Opcode Fuzzy Hash: 3765a10cee1e255344ee37f065f4be71d58868c9c9e645b3056c9746d3493235
    • Instruction Fuzzy Hash: 0B214132718A4187DB61AF19D48037DB6B0BB84B94FD84236E69D476D5DF3DD4118B20
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 8e9754deeba93abb4745aa2efb451e77357aefa8fb0fbddb16feb6c8c90fdd62
    • Instruction ID: d8c4958b7fee5446a2197512e02afc26466dc2d2439f70b2d49a283e1184e28e
    • Opcode Fuzzy Hash: 8e9754deeba93abb4745aa2efb451e77357aefa8fb0fbddb16feb6c8c90fdd62
    • Instruction Fuzzy Hash: F1018221A0874541E604EF93E9840ADE695AF95FE0FC94633DE5C27BD7CE3CD4014714
    APIs
    • HeapAlloc.KERNEL32(?,?,?,00007FF7D4C00C90,?,?,?,00007FF7D4C022FA,?,?,?,?,?,00007FF7D4C03AE9), ref: 00007FF7D4C0D63A
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: AllocHeap
    • String ID:
    • API String ID: 4292702814-0
    • Opcode ID: 510c613edcbd96140e332c46b5608733b20d975e117422ad796dc4540c81bb80
    • Instruction ID: 6799208c33ce761fef5978e9a02b0322fbec8fe477df07fbeade6896cd69cea0
    • Opcode Fuzzy Hash: 510c613edcbd96140e332c46b5608733b20d975e117422ad796dc4540c81bb80
    • Instruction Fuzzy Hash: CCF0FE10B1968645FE547F73D8D967D91905F84BE1FC80B33ED2E652D2EE2DA4808630
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: AddressErrorLastProc
    • String ID: Failed to get address for %hs$GetProcAddress$Tcl_Alloc$Tcl_ConditionFinalize$Tcl_ConditionNotify$Tcl_ConditionWait$Tcl_CreateInterp$Tcl_CreateObjCommand$Tcl_CreateThread$Tcl_DeleteInterp$Tcl_DoOneEvent$Tcl_EvalEx$Tcl_EvalFile$Tcl_EvalObjv$Tcl_Finalize$Tcl_FinalizeThread$Tcl_FindExecutable$Tcl_Free$Tcl_GetCurrentThread$Tcl_GetObjResult$Tcl_GetString$Tcl_GetVar2$Tcl_Init$Tcl_JoinThread$Tcl_MutexFinalize$Tcl_MutexLock$Tcl_MutexUnlock$Tcl_NewByteArrayObj$Tcl_NewStringObj$Tcl_SetVar2$Tcl_SetVar2Ex$Tcl_ThreadAlert$Tcl_ThreadQueueEvent$Tk_GetNumMainWindows$Tk_Init
    • API String ID: 199729137-3427451314
    • Opcode ID: 939c8a0ebf27c7f5789cd4a10996167767bc86255d761b2ba34a42bc6fc861e3
    • Instruction ID: 39245cd247208f4cd85973194ebfa16e5865a21863bd389fa04aea26950782f7
    • Opcode Fuzzy Hash: 939c8a0ebf27c7f5789cd4a10996167767bc86255d761b2ba34a42bc6fc861e3
    • Instruction Fuzzy Hash: A3029A64E0AB4791FA15FF57E8945BCA2B1AF197C5BC41077D82E022A0FF3CB5498670
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Message$ErrorLast$ObjectProcessSingleWait$CloseCreateHandlePeekWindow_invalid_parameter_noinfo$ByteCharClassCodeCommandConsoleCtrlCurrentDestroyDispatchExitFormatHandlerInfoLineMultiRegisterStartupTerminateTranslateWide
    • String ID: CreateProcessW$Failed to create child process!$PyInstaller Onefile Hidden Window$PyInstallerOnefileHiddenWindow
    • API String ID: 3832162212-3165540532
    • Opcode ID: 99838be411f58a84d89697932930ae4644c798f1dd42cd928399edbb9bf0e48e
    • Instruction ID: 755537664c515fe93d050d135a0079858969d4002174cfbc24b3c06379dee24a
    • Opcode Fuzzy Hash: 99838be411f58a84d89697932930ae4644c798f1dd42cd928399edbb9bf0e48e
    • Instruction Fuzzy Hash: F9D17431A09A8286EB10EF36E8942ADB7B0FF94798FD04137DA5D52A94EF3CD155C720
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo$memcpy_s$fegetenv
    • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
    • API String ID: 808467561-2761157908
    • Opcode ID: 7da0388417e7c773b0aab48e07e342724827a26e5879d16e5decf6c79e081c8c
    • Instruction ID: 0734f125faf5268d050807c82c41ff0777f2b1c3f8fcce1e79ffeff8261c13b1
    • Opcode Fuzzy Hash: 7da0388417e7c773b0aab48e07e342724827a26e5879d16e5decf6c79e081c8c
    • Instruction Fuzzy Hash: 30B2C772A182928BE7259F66D4807FDB7B1FB543C8FD05137DA0D67A88DB38A500CB64
    APIs
    • FindFirstFileW.KERNEL32(?,00007FF7D4BF8919,00007FF7D4BF3F9D), ref: 00007FF7D4BF842B
    • RemoveDirectoryW.KERNEL32(?,00007FF7D4BF8919,00007FF7D4BF3F9D), ref: 00007FF7D4BF84AE
    • DeleteFileW.KERNEL32(?,00007FF7D4BF8919,00007FF7D4BF3F9D), ref: 00007FF7D4BF84CD
    • FindNextFileW.KERNEL32(?,00007FF7D4BF8919,00007FF7D4BF3F9D), ref: 00007FF7D4BF84DB
    • FindClose.KERNEL32(?,00007FF7D4BF8919,00007FF7D4BF3F9D), ref: 00007FF7D4BF84EC
    • RemoveDirectoryW.KERNEL32(?,00007FF7D4BF8919,00007FF7D4BF3F9D), ref: 00007FF7D4BF84F5
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: FileFind$DirectoryRemove$CloseDeleteFirstNext
    • String ID: %s\*
    • API String ID: 1057558799-766152087
    • Opcode ID: 9215641a051a597ab69d89bbe09b444c24fb25eba6eed844fe9e008ab190e420
    • Instruction ID: 23dd78fdbc31c48d49440ea6188063e6fc4c4fdc65c5cfeba2f502776e06f1ea
    • Opcode Fuzzy Hash: 9215641a051a597ab69d89bbe09b444c24fb25eba6eed844fe9e008ab190e420
    • Instruction Fuzzy Hash: 4F415321A4D94285EA20BF66E4D41BEE3A0FBA4794FD00233E99D436D8EF3DE545C720
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID: invalid bit length repeat$invalid code -- missing end-of-block$invalid code lengths set$invalid distance code$invalid distance too far back$invalid distances set$invalid literal/length code$invalid literal/lengths set$too many length or distance symbols
    • API String ID: 0-2665694366
    • Opcode ID: 14409f6b5173d9f28888b9fb9c68bcc2b54b8e7def706e6c40ef53002486e1ba
    • Instruction ID: 0502953b82c674d1dd82427bcc92bb3551ae856a2eb7803f15ab6fa2c965c774
    • Opcode Fuzzy Hash: 14409f6b5173d9f28888b9fb9c68bcc2b54b8e7def706e6c40ef53002486e1ba
    • Instruction Fuzzy Hash: 57521772A196A54BD7A89F15C498B7DBBE9FB94340F81813AE74E87780DB3DD840CB10
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
    • String ID:
    • API String ID: 3140674995-0
    • Opcode ID: 357b26123f7cc0566be18cabbec560c6351d8abd4e8582c9dfa9d4018571b442
    • Instruction ID: 1cd44acb9bfd4df2cc606734ec479c20ae5cc0b05f7375f165a904c287af4a0d
    • Opcode Fuzzy Hash: 357b26123f7cc0566be18cabbec560c6351d8abd4e8582c9dfa9d4018571b442
    • Instruction Fuzzy Hash: 71311F72609B8186EB609F61E8803EDA3B4FB94744F84403BDA4E47B95EF7DD548C720
    APIs
    • _get_daylight.LIBCMT ref: 00007FF7D4C15C45
      • Part of subcall function 00007FF7D4C15598: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7D4C155AC
      • Part of subcall function 00007FF7D4C0A948: HeapFree.KERNEL32(?,?,?,00007FF7D4C12D22,?,?,?,00007FF7D4C12D5F,?,?,00000000,00007FF7D4C13225,?,?,?,00007FF7D4C13157), ref: 00007FF7D4C0A95E
      • Part of subcall function 00007FF7D4C0A948: GetLastError.KERNEL32(?,?,?,00007FF7D4C12D22,?,?,?,00007FF7D4C12D5F,?,?,00000000,00007FF7D4C13225,?,?,?,00007FF7D4C13157), ref: 00007FF7D4C0A968
      • Part of subcall function 00007FF7D4C0A900: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,00007FF7D4C0A8DF,?,?,?,?,?,00007FF7D4C0A7CA), ref: 00007FF7D4C0A909
      • Part of subcall function 00007FF7D4C0A900: GetCurrentProcess.KERNEL32(?,?,?,?,00007FF7D4C0A8DF,?,?,?,?,?,00007FF7D4C0A7CA), ref: 00007FF7D4C0A92E
    • _get_daylight.LIBCMT ref: 00007FF7D4C15C34
      • Part of subcall function 00007FF7D4C155F8: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7D4C1560C
    • _get_daylight.LIBCMT ref: 00007FF7D4C15EAA
    • _get_daylight.LIBCMT ref: 00007FF7D4C15EBB
    • _get_daylight.LIBCMT ref: 00007FF7D4C15ECC
    • GetTimeZoneInformation.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,?,00007FF7D4C1610C), ref: 00007FF7D4C15EF3
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _get_daylight$_invalid_parameter_noinfo$CurrentErrorFeatureFreeHeapInformationLastPresentProcessProcessorTimeZone
    • String ID:
    • API String ID: 4070488512-0
    • Opcode ID: 677ea417f3249c8bdb60afb6413c0575e0f743ff33606516b420b369f71394b1
    • Instruction ID: 03b4bac47291b463a54755cf3a3c9a6f0b6114b742e0bfe8261eb0a7c5243ac8
    • Opcode Fuzzy Hash: 677ea417f3249c8bdb60afb6413c0575e0f743ff33606516b420b369f71394b1
    • Instruction Fuzzy Hash: C3D19A26B0824286E720BF27D8C55BDA6A1EF947D4FC48037EA0D47AA6DF3DE4418770
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
    • String ID:
    • API String ID: 1239891234-0
    • Opcode ID: ae2d74aaff6e8c1310ec24f87c3395aa5518f909cdba62f6f822c67f0a9cc142
    • Instruction ID: d51236e140f59fb04270d79e997f907b86094c3f0f0f29d2d9d8dcb97fbcaa75
    • Opcode Fuzzy Hash: ae2d74aaff6e8c1310ec24f87c3395aa5518f909cdba62f6f822c67f0a9cc142
    • Instruction Fuzzy Hash: 7B317F32608B8186DB20DF26E8842AEB3B4FB98794F900137EA8D43B54EF3CC155CB10
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: FileFindFirst_invalid_parameter_noinfo
    • String ID:
    • API String ID: 2227656907-0
    • Opcode ID: 471de8175ffa50438b20796c5ba06e190623de8bcba55c14971da5e7bf2bc1ae
    • Instruction ID: 590360484a459faba2d279453d96bdc60181f7465a9a77616748bc2876396cf6
    • Opcode Fuzzy Hash: 471de8175ffa50438b20796c5ba06e190623de8bcba55c14971da5e7bf2bc1ae
    • Instruction Fuzzy Hash: 90B1C262B1869241EA60AF23D4945BDE7B1EB48BE4FC45133EA5D17B89EE3CE441C730
    APIs
    • _get_daylight.LIBCMT ref: 00007FF7D4C15EAA
      • Part of subcall function 00007FF7D4C155F8: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7D4C1560C
    • _get_daylight.LIBCMT ref: 00007FF7D4C15EBB
      • Part of subcall function 00007FF7D4C15598: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7D4C155AC
    • _get_daylight.LIBCMT ref: 00007FF7D4C15ECC
      • Part of subcall function 00007FF7D4C155C8: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7D4C155DC
      • Part of subcall function 00007FF7D4C0A948: HeapFree.KERNEL32(?,?,?,00007FF7D4C12D22,?,?,?,00007FF7D4C12D5F,?,?,00000000,00007FF7D4C13225,?,?,?,00007FF7D4C13157), ref: 00007FF7D4C0A95E
      • Part of subcall function 00007FF7D4C0A948: GetLastError.KERNEL32(?,?,?,00007FF7D4C12D22,?,?,?,00007FF7D4C12D5F,?,?,00000000,00007FF7D4C13225,?,?,?,00007FF7D4C13157), ref: 00007FF7D4C0A968
    • GetTimeZoneInformation.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,?,00007FF7D4C1610C), ref: 00007FF7D4C15EF3
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _get_daylight_invalid_parameter_noinfo$ErrorFreeHeapInformationLastTimeZone
    • String ID:
    • API String ID: 3458911817-0
    • Opcode ID: 179af59534a267e8b56f66eebf2dbf2058aebcf107c16e98e161f461d30bd41f
    • Instruction ID: d3dc03d76b6cb7a26f05f41d17c4320dfbd9d0e87d94f5aa38308331d77b9770
    • Opcode Fuzzy Hash: 179af59534a267e8b56f66eebf2dbf2058aebcf107c16e98e161f461d30bd41f
    • Instruction Fuzzy Hash: 1D516A22A0864286E710FF23D8C55ADE760BB987D4FC48137EA4E47AA6DF3DE4418770
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
    • String ID:
    • API String ID: 2933794660-0
    • Opcode ID: 884c9866f0db1ea4ea3e8c559fd458021c8c8106c035f87ab540984eb8a2d97e
    • Instruction ID: 25004a2437947bf3dd39038b02e7556ac077153b6cb1a1dc1a183f643ed8da8f
    • Opcode Fuzzy Hash: 884c9866f0db1ea4ea3e8c559fd458021c8c8106c035f87ab540984eb8a2d97e
    • Instruction Fuzzy Hash: FA114C26B14B058AEB00DF71E8942BD73B4FB19798F840E32DA2D46BA4EF7CD1598350
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: memcpy_s
    • String ID:
    • API String ID: 1502251526-0
    • Opcode ID: 723df14fe8405c9280d13974b9e0b256372cd2939c4def8ecbac686ef57d643c
    • Instruction ID: af608285285afcd6478307b3643bc455f8ca752feb9b34af7441f5de9a3c2571
    • Opcode Fuzzy Hash: 723df14fe8405c9280d13974b9e0b256372cd2939c4def8ecbac686ef57d643c
    • Instruction Fuzzy Hash: 9BC1C372B1868687EB24DF16E08466EF7A1F784BC8FC48136DB4E53794DA3DE9018B50
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID: $header crc mismatch$unknown header flags set
    • API String ID: 0-1127688429
    • Opcode ID: e32b299fc273864699ec3bddfbf8fc958dab4a7742ffdf8f0166f3b43fcc42d1
    • Instruction ID: 3e823eadd1d3eda3cb2441113fe83f18fedb725bdf34e5fe6349986d4185b3ca
    • Opcode Fuzzy Hash: e32b299fc273864699ec3bddfbf8fc958dab4a7742ffdf8f0166f3b43fcc42d1
    • Instruction Fuzzy Hash: EEF19472A193C54BE7A9AF16C0C8A3EBAE9EF98740FC54136DA4D07790CB39E441C750
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: ExceptionRaise_clrfp
    • String ID:
    • API String ID: 15204871-0
    • Opcode ID: a4cc0e8a2f7e024105bf8074fef1866164229a93701b52dcf00f6f20498becf3
    • Instruction ID: 9e8bbae426dddccc33b5fcf74ba6a4667cd9e5e8503f8d00f30bdc767980773a
    • Opcode Fuzzy Hash: a4cc0e8a2f7e024105bf8074fef1866164229a93701b52dcf00f6f20498becf3
    • Instruction Fuzzy Hash: 3AB15E73A04B858BEB15DF2AC88636CBBB0F744B88F558923DA5D837A4CB39D451C720
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID: $
    • API String ID: 0-227171996
    • Opcode ID: e57f1980f4491aea9eb328a1e81193c2bccc9a7e68d1918bb9b7207cf9600634
    • Instruction ID: 984a1acdc10b4a6048e98aa5497d8c552a7962071335ce189283eafb7ddd5dbb
    • Opcode Fuzzy Hash: e57f1980f4491aea9eb328a1e81193c2bccc9a7e68d1918bb9b7207cf9600634
    • Instruction Fuzzy Hash: 8DE1A432A1864685EB78AF66C0D813DB360FF45BC8FD45237DA0E676A4DF29E851C720
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID: incorrect header check$invalid window size
    • API String ID: 0-900081337
    • Opcode ID: e8ec78490181e4ccec650f854842bb3e08bcfae3bf2db5596c2af0d8e2ff5899
    • Instruction ID: f2777ad79ea9835017cf5fa42e18a82e6965e5db43294bc6757a5cac5446f29c
    • Opcode Fuzzy Hash: e8ec78490181e4ccec650f854842bb3e08bcfae3bf2db5596c2af0d8e2ff5899
    • Instruction Fuzzy Hash: 63919972A192C587E7A49E16C4D8B3EBAE9FB64350FD1813ADA4E46790CB39E540CB10
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID: e+000$gfff
    • API String ID: 0-3030954782
    • Opcode ID: c8a24eaff8c968987b4d031b15ae93849e98bcf9eddb8930961e84febef9b5bc
    • Instruction ID: 4ca50e0e95a6df380c8fc98c34520072e824e40e4b9a8c32c86b5b623c1bbb98
    • Opcode Fuzzy Hash: c8a24eaff8c968987b4d031b15ae93849e98bcf9eddb8930961e84febef9b5bc
    • Instruction Fuzzy Hash: 3A515522B182C186E7259E36D88876DAB92E744BD4FC8C233DBAC47AC5DE7DD000C711
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CurrentFeaturePresentProcessProcessor
    • String ID:
    • API String ID: 1010374628-0
    • Opcode ID: 1f02906f64a0705243f8a934690fc57de62aec8e174562db1634478312f225fa
    • Instruction ID: 05e17d3c2eb0fb12adf7cd296fce26f3a5956d4ca0030ffaab9b918e304e6385
    • Opcode Fuzzy Hash: 1f02906f64a0705243f8a934690fc57de62aec8e174562db1634478312f225fa
    • Instruction Fuzzy Hash: E402DA21B1E64241FE51BF13E49827DA6A0AF41BE4FC58637EE6D56BD2DE3DA4018330
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID: gfffffff
    • API String ID: 0-1523873471
    • Opcode ID: bcab6200947a377332474fa44b4677218d40dcace4b26705986274372b0e4f91
    • Instruction ID: 5baaafeb9a4d6c90c0fe8ccf0868e53a51cfd3587e28b0e4ec3e59136f6fa454
    • Opcode Fuzzy Hash: bcab6200947a377332474fa44b4677218d40dcace4b26705986274372b0e4f91
    • Instruction Fuzzy Hash: FFA15762B087C546EB21DF26E4847ADBB91AB51BC4F848133EE4D57785EE3DD401C721
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: TMP
    • API String ID: 3215553584-3125297090
    • Opcode ID: 405b9769b8a986946faf73e500ffb4ce1780379e6f9b934ce1cdce4b063a5bb7
    • Instruction ID: 1922835609f86ef23b3cbdb8c050034351323b532e389592380127fb43c810b5
    • Opcode Fuzzy Hash: 405b9769b8a986946faf73e500ffb4ce1780379e6f9b934ce1cdce4b063a5bb7
    • Instruction Fuzzy Hash: 4B518C11B0861241FA74BE27D98917ED290AF54BD4FC88537DE8E67796EE3CE4428230
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: HeapProcess
    • String ID:
    • API String ID: 54951025-0
    • Opcode ID: 1f9e0516fd534d967cb731c121838b59470578846d262458ea046ba55ab40ebf
    • Instruction ID: 1b891e8e86e14f4309ae6926570764f94dec0e72cf2251cc58f1de1a5af51596
    • Opcode Fuzzy Hash: 1f9e0516fd534d967cb731c121838b59470578846d262458ea046ba55ab40ebf
    • Instruction Fuzzy Hash: 3DB09220E07A02C2EA087F22ACCA22C62A47F48741FD8013BC40C40331EE2C20E99B20
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 5eca4e5ff3e7205525bf20f3b63783aa462e3e7adb0228d62bb7e98ab9f5e9bb
    • Instruction ID: b44c713324fb85c4dd662f82fa19551a0c9c5275755f3adf4f6d44cb6ad3dc72
    • Opcode Fuzzy Hash: 5eca4e5ff3e7205525bf20f3b63783aa462e3e7adb0228d62bb7e98ab9f5e9bb
    • Instruction Fuzzy Hash: A7D1C662A0864245EB78AE2BC58827DA7A0BB45BC8FD44237CE0D277E5DF3DD845C760
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: e75d751cc15dfd510e55d83c6141b0e8cb11d18cbed01e0c543b372a0114c593
    • Instruction ID: a0916d99f21e7611a9bd7d0f72ac5ffccf3f4c6b7d4dedacf0559699c063812e
    • Opcode Fuzzy Hash: e75d751cc15dfd510e55d83c6141b0e8cb11d18cbed01e0c543b372a0114c593
    • Instruction Fuzzy Hash: 24C18D762181E08BD289EB29E8B947A73D1F78934DBD5406BEF8747685C73CA414DB20
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: aa73bfa000bc8cd66a05f12d530b76a597660d7bda6a6781f52cf2f49ffced0b
    • Instruction ID: c5dfc646a65553e7d3c0116e8bb34303bb3967b54b814f4c338e8729ca7ecaa6
    • Opcode Fuzzy Hash: aa73bfa000bc8cd66a05f12d530b76a597660d7bda6a6781f52cf2f49ffced0b
    • Instruction Fuzzy Hash: 34B16D7290879586EB649F2AC09823CBBA0E749F89FE44137CA4E67395CF39DC41C764
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 9611c2e0762efa78d7f6da3d8515592aa8d86601c49200b7335873453b670326
    • Instruction ID: 0d7887d7a80040c217f937edead7f8f11bbf5f2f1cb64cf4ccec76ff303a4264
    • Opcode Fuzzy Hash: 9611c2e0762efa78d7f6da3d8515592aa8d86601c49200b7335873453b670326
    • Instruction Fuzzy Hash: E381D272A4878186E774EF1AE48836EAA91FB557D4FD04237DB8D53B89DE3DE4008B10
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 21aaab296e2e64a79b20cf98ea2699a9ab0529386423cc159892306e5cd43e00
    • Instruction ID: c2c01a06538262e907c4d6ffceadcf437ab9d1b865f5ee28087639ec0d0140a3
    • Opcode Fuzzy Hash: 21aaab296e2e64a79b20cf98ea2699a9ab0529386423cc159892306e5cd43e00
    • Instruction Fuzzy Hash: 1961E662F0825247F764AE6AD4D463DE6A0AF507E0FDD423BD61E42AC5DE7DE8018730
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 27099d1c67046ba5536a5c52bb1b19252402c8bb4a5167aa336477e7b6d5f807
    • Instruction ID: 8dbf74f8d11ed2d92f2a72d11a545299cb7d87d49506f2857b2ffa3a39d32efd
    • Opcode Fuzzy Hash: 27099d1c67046ba5536a5c52bb1b19252402c8bb4a5167aa336477e7b6d5f807
    • Instruction Fuzzy Hash: 84517436A1865186E7259F2AC08822CF3A0EB45B98FE44133DE4D27798CF3BE853C750
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 8e69dfdcc94a0aa650623f7423aa354004c1f2fa01d5c1268249020d4c21f447
    • Instruction ID: 224aa51299025f02853dc0653a1481b299ace41515650258e84e643a1259cc37
    • Opcode Fuzzy Hash: 8e69dfdcc94a0aa650623f7423aa354004c1f2fa01d5c1268249020d4c21f447
    • Instruction Fuzzy Hash: B7518576A1865182E7649F6AC48833CB3A5EB54BA9FE44133CE4D27794CB3AEC43C750
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 68a3f5aab59b2fac328bd6ba34d5b1cd1fa94c6914f84dc4a79da3b9d8ff9a98
    • Instruction ID: 968827b063c6f939831a866aebc063840d7c3a06f671f64676fb2278f4c9a50a
    • Opcode Fuzzy Hash: 68a3f5aab59b2fac328bd6ba34d5b1cd1fa94c6914f84dc4a79da3b9d8ff9a98
    • Instruction Fuzzy Hash: C6514676A1865185E7249F1AC08822CF7A0EB45B98FE44233DA8D2779CDF3BE853C750
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: e734bc54909bdf7d9c6fd1772be64da5dc64d4f5bf3044a39ac3ba7850561882
    • Instruction ID: 4c57a4d982c3647ece7f21241dade05f85df970b198034fc404ab6edad905189
    • Opcode Fuzzy Hash: e734bc54909bdf7d9c6fd1772be64da5dc64d4f5bf3044a39ac3ba7850561882
    • Instruction Fuzzy Hash: 97517236A1865585E7249F2AC08833CA7A1EB45B99FE44133CE4D277A9CF3AEC43C750
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 3943df286285c50b07f09d339b53caaa0afa34ddfac4fad96d8a3f7ffd6ad23b
    • Instruction ID: f431553d5af4d48e0ea6410b3bcd17a66a428e6b2cd643762b666a364dea5a16
    • Opcode Fuzzy Hash: 3943df286285c50b07f09d339b53caaa0afa34ddfac4fad96d8a3f7ffd6ad23b
    • Instruction Fuzzy Hash: C3517236A1865186E7349F2AC08832CE7A1EB45B98FE54133CE4D67799CF3BE942C750
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: dc981bf603441a130e1c6ba5e96f77be0c3c60e19ec03e3d560a09712d731568
    • Instruction ID: c56cf61024b7fb57282771368f358ea64662bbd6cd2b1a6100189066787b089c
    • Opcode Fuzzy Hash: dc981bf603441a130e1c6ba5e96f77be0c3c60e19ec03e3d560a09712d731568
    • Instruction Fuzzy Hash: A1518676A1865185E7259F2AC08822CF7A1EB45B98FE85133CE4C27798DF3BE842C750
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: dde3b7cfbcf26fc8d7513faefc9a59c4b8821272907dfbb35b6db6355186da00
    • Instruction ID: 186ef352168a0dcf277536a5c3e1e3112bf4f06153e1ee20c3a09e144bca551a
    • Opcode Fuzzy Hash: dde3b7cfbcf26fc8d7513faefc9a59c4b8821272907dfbb35b6db6355186da00
    • Instruction Fuzzy Hash: 12418562C0974B07E999DD1A864C6BC9A809F127E0DD852B7DDED373D7CD0D6987C220
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: ErrorFreeHeapLast
    • String ID:
    • API String ID: 485612231-0
    • Opcode ID: e2fd4559255f10fba12f2fe7c3826a5d8d64873a79dc25e0e9bc72c34cfb8264
    • Instruction ID: 6eb1c0f2d17f0470482ffcb25ae4d01effd6bbe0cff57ff1cb351cf6d9f2c947
    • Opcode Fuzzy Hash: e2fd4559255f10fba12f2fe7c3826a5d8d64873a79dc25e0e9bc72c34cfb8264
    • Instruction Fuzzy Hash: 2141E262714A5582EF04DF2BD99866DB3A1BB48FD4BC99037EE0DA7B58DE7DD0428300
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: a33e2c8dffc1328ccb3c79931647987677b9da288923bf574ced27deaffa7ee3
    • Instruction ID: eed00443949d0d5f41c000cc91a98b9aedf91574c13f299b29c80b055bfd8a73
    • Opcode Fuzzy Hash: a33e2c8dffc1328ccb3c79931647987677b9da288923bf574ced27deaffa7ee3
    • Instruction Fuzzy Hash: 8A31B432708B4141E664AF27E48413EA6D5AF85BD0FD4823BEA9D63BD5DF3CD0018724
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 5d3ac10822f6242d2b374fc0e1218152d8e80c351f0dfcd4fab21387456caa74
    • Instruction ID: ad059c0820bcd99f386284cdc459f69b69a1efe507a9bd0572c49b6462fd7ce4
    • Opcode Fuzzy Hash: 5d3ac10822f6242d2b374fc0e1218152d8e80c351f0dfcd4fab21387456caa74
    • Instruction Fuzzy Hash: 2BF044717182958ADB98AF69E44262977D0F7483C0FC0C03BD58D83A24DA3C90528F14
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 3c3909751b2697c6481bc0460501d6177e5cf72f77169ad8285d6e0cd944102a
    • Instruction ID: b51727c19ce920c105c702c0cc290b215380527e55dd9d5f1755e1c38095afcc
    • Opcode Fuzzy Hash: 3c3909751b2697c6481bc0460501d6177e5cf72f77169ad8285d6e0cd944102a
    • Instruction Fuzzy Hash: F5A00221D0DC4BD0E644AF02E8D003DA374FB68341BC00033E50E514B1AF3DA409E730
    APIs
    • GetProcAddress.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF5840
    • GetLastError.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF5852
    • GetProcAddress.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF5889
    • GetLastError.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF589B
    • GetProcAddress.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF58B4
    • GetLastError.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF58C6
    • GetProcAddress.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF58DF
    • GetLastError.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF58F1
    • GetProcAddress.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF590D
    • GetLastError.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF591F
    • GetProcAddress.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF593B
    • GetLastError.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF594D
    • GetProcAddress.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF5969
    • GetLastError.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF597B
    • GetProcAddress.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF5997
    • GetLastError.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF59A9
    • GetProcAddress.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF59C5
    • GetLastError.KERNEL32(?,00007FF7D4BF64CF,?,00007FF7D4BF336E), ref: 00007FF7D4BF59D7
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: AddressErrorLastProc
    • String ID: Failed to get address for %hs$GetProcAddress$PyConfig_Clear$PyConfig_InitIsolatedConfig$PyConfig_Read$PyConfig_SetBytesString$PyConfig_SetString$PyConfig_SetWideStringList$PyErr_Clear$PyErr_Fetch$PyErr_NormalizeException$PyErr_Occurred$PyErr_Print$PyErr_Restore$PyEval_EvalCode$PyImport_AddModule$PyImport_ExecCodeModule$PyImport_ImportModule$PyMarshal_ReadObjectFromString$PyMem_RawFree$PyModule_GetDict$PyObject_CallFunction$PyObject_CallFunctionObjArgs$PyObject_GetAttrString$PyObject_SetAttrString$PyObject_Str$PyPreConfig_InitIsolatedConfig$PyRun_SimpleStringFlags$PyStatus_Exception$PySys_GetObject$PySys_SetObject$PyUnicode_AsUTF8$PyUnicode_Decode$PyUnicode_DecodeFSDefault$PyUnicode_FromFormat$PyUnicode_FromString$PyUnicode_Join$PyUnicode_Replace$Py_DecRef$Py_DecodeLocale$Py_ExitStatusException$Py_Finalize$Py_InitializeFromConfig$Py_IsInitialized$Py_PreInitialize
    • API String ID: 199729137-653951865
    • Opcode ID: a72b1b0889ffc37889110ad0e4f068dcb4eb8b0bbe2e77bf2d8672c26fae6e03
    • Instruction ID: 83fa063cda382caf27c69529a1c89f5f33e147206b71c3788dd660447b513541
    • Opcode Fuzzy Hash: a72b1b0889ffc37889110ad0e4f068dcb4eb8b0bbe2e77bf2d8672c26fae6e03
    • Instruction Fuzzy Hash: C3228EA4A0EB0792FA05FF57E8D45BCA2B0AF197D1FC45437D81E02261BF7DA5488A70
    APIs
      • Part of subcall function 00007FF7D4BF9390: MultiByteToWideChar.KERNEL32(?,?,?,00007FF7D4BF45F4,00000000,00007FF7D4BF1985), ref: 00007FF7D4BF93C9
    • ExpandEnvironmentStringsW.KERNEL32(?,00007FF7D4BF86B7,?,?,00000000,00007FF7D4BF3CBB), ref: 00007FF7D4BF822C
      • Part of subcall function 00007FF7D4BF2810: MessageBoxW.USER32 ref: 00007FF7D4BF28EA
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: ByteCharEnvironmentExpandMessageMultiStringsWide
    • String ID: %.*s$CreateDirectory$LOADER: failed to convert runtime-tmpdir to a wide string.$LOADER: failed to create runtime-tmpdir path %ls!$LOADER: failed to expand environment variables in the runtime-tmpdir.$LOADER: failed to obtain the absolute path of the runtime-tmpdir.$LOADER: runtime-tmpdir points to non-existent drive %ls (type: %d)!$\
    • API String ID: 1662231829-930877121
    • Opcode ID: 34679b23be2e6a85bad270fe565fa16c5e09c528fb77942a9d4832d630ea4d55
    • Instruction ID: 2e28ad4086776c65654f868e9cbbf242a4afb1e1eba5008452b6cf59fa83d9fa
    • Opcode Fuzzy Hash: 34679b23be2e6a85bad270fe565fa16c5e09c528fb77942a9d4832d630ea4d55
    • Instruction Fuzzy Hash: A9515311A1AA8241EA54BF26D8D52BDE2A1AF647C0FC45433E64E426D5FF2DF5048770
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CurrentProcess
    • String ID: Failed to create symbolic link %s!$Failed to extract %s: failed to allocate temporary buffer!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to open target file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$Failed to extract %s: failed to write data chunk!$fopen$fread$fseek$fwrite$malloc
    • API String ID: 2050909247-1550345328
    • Opcode ID: e3708a70641f4c25eddad747f271709fc7d2310b412025799ca2ceeb596927eb
    • Instruction ID: ee3837f1dfcca2dda76a30370d16a02d97d217a44d1a4126c5bdfbb3dcec8f82
    • Opcode Fuzzy Hash: e3708a70641f4c25eddad747f271709fc7d2310b412025799ca2ceeb596927eb
    • Instruction Fuzzy Hash: 55518061A0964392EA14BF63E4801AEA3A0BF547D4FC44533ED0C17796EE3EF9458720
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: MoveWindow$ObjectSelect$DrawReleaseText
    • String ID: P%
    • API String ID: 2147705588-2959514604
    • Opcode ID: 044398bc2faddcfc72e28419b1c607044beef288ba0900b5e0371f537bcab75f
    • Instruction ID: 13c1baf5d1a888199f5c6aba053cb1cd2a1f6d2f78880d1e30f783302df881a3
    • Opcode Fuzzy Hash: 044398bc2faddcfc72e28419b1c607044beef288ba0900b5e0371f537bcab75f
    • Instruction Fuzzy Hash: ED51D7266047A186D6349F26F4581BEF7A1FB98BA1F404126EBDE43694EF3CD045DB20
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: LongWindow$BlockCreateErrorLastReasonShutdown
    • String ID: Needs to remove its temporary files.
    • API String ID: 3975851968-2863640275
    • Opcode ID: fca9629812ae98fc4dea80e51924cd1fa5b6a95a0379263e815d251d6ca0a567
    • Instruction ID: 0633e3e686f6544d95d6b2ba43c9df32eacdd78d5c5a8f9e9f317c387814cad5
    • Opcode Fuzzy Hash: fca9629812ae98fc4dea80e51924cd1fa5b6a95a0379263e815d251d6ca0a567
    • Instruction Fuzzy Hash: 53217425B09A4281E741AF7BE88417DE2A0EF9CBD0FD84233DE5D43398EE2CD5918630
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: -$:$f$p$p
    • API String ID: 3215553584-2013873522
    • Opcode ID: 75ce3dd5e90789a751ac91fed3db50e3550f512a2f4dec46f6fb30c565ad9a60
    • Instruction ID: dd0752c162f035b21ef2f9be379e031df7670d98d080f804f14266976a8f9f70
    • Opcode Fuzzy Hash: 75ce3dd5e90789a751ac91fed3db50e3550f512a2f4dec46f6fb30c565ad9a60
    • Instruction Fuzzy Hash: 83126061F0824386FB24BE16D19A67DF691FB50794FCC4137E68D66AC4DB3CE5808B24
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: f$f$p$p$f
    • API String ID: 3215553584-1325933183
    • Opcode ID: efdc55b57c7b5823aa39a5abe82f144bbffe385c3037011f7a836833ec2ff017
    • Instruction ID: 8b5953a87f2de0b8910487f5b3ffd024a69c45841b3e0fb6f543353467b70b90
    • Opcode Fuzzy Hash: efdc55b57c7b5823aa39a5abe82f144bbffe385c3037011f7a836833ec2ff017
    • Instruction Fuzzy Hash: CA127262E0C14386FB246E56E09827DF6A5FB407D4FC44137E69E56AC8DF7EE5808B20
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CurrentProcess
    • String ID: Failed to extract %s: failed to allocate data buffer (%u bytes)!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$fread$fseek$malloc
    • API String ID: 2050909247-3659356012
    • Opcode ID: 2e822f8cd24891b1059a3a79b168aacb6a69fa12a2733a925039993d87a111eb
    • Instruction ID: 8fd81f433cec8018ccd9b17e89ddb854afd3ece4eaf03a9c2bab66ea715a9386
    • Opcode Fuzzy Hash: 2e822f8cd24891b1059a3a79b168aacb6a69fa12a2733a925039993d87a111eb
    • Instruction Fuzzy Hash: 5D414B21A0965282EA10FF13E8846BEE3A1AF54BC4FC45833ED4C57796DE3DE9058760
    APIs
    • GetTempPathW.KERNEL32(?,?,00000000,00007FF7D4BF3CBB), ref: 00007FF7D4BF8704
    • GetCurrentProcessId.KERNEL32(?,00000000,00007FF7D4BF3CBB), ref: 00007FF7D4BF870A
    • CreateDirectoryW.KERNEL32(?,00000000,00007FF7D4BF3CBB), ref: 00007FF7D4BF874C
      • Part of subcall function 00007FF7D4BF8830: GetEnvironmentVariableW.KERNEL32(00007FF7D4BF388E), ref: 00007FF7D4BF8867
      • Part of subcall function 00007FF7D4BF8830: ExpandEnvironmentStringsW.KERNEL32 ref: 00007FF7D4BF8889
      • Part of subcall function 00007FF7D4C08238: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7D4C08251
      • Part of subcall function 00007FF7D4BF2810: MessageBoxW.USER32 ref: 00007FF7D4BF28EA
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Environment$CreateCurrentDirectoryExpandMessagePathProcessStringsTempVariable_invalid_parameter_noinfo
    • String ID: LOADER: failed to set the TMP environment variable.$LOADER: length of teporary directory path exceeds maximum path length!$TMP$TMP$_MEI%d
    • API String ID: 3563477958-1339014028
    • Opcode ID: e09d7b167afd2147c660aa35db8091a51c6906773476d98e2344c67e24741bda
    • Instruction ID: bc3e3603f86c2d870d6c43cf202836b89008edfd8988a43c1616fb855c4e50b1
    • Opcode Fuzzy Hash: e09d7b167afd2147c660aa35db8091a51c6906773476d98e2344c67e24741bda
    • Instruction Fuzzy Hash: 9C41AE11A1EA4244FA24BF27E8D92BE92A1AF947C0FC04133ED4D577DAEE3DE5058760
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CurrentProcess
    • String ID: Failed to extract %s: failed to allocate data buffer (%u bytes)!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$fread$fseek$malloc
    • API String ID: 2050909247-3659356012
    • Opcode ID: 6e0dbdf68ebac07b8e07dae572509d1bc59e12a4c4e352d5f88c3b4cbd2dc1c0
    • Instruction ID: 949bc1a8573f16bad3fbe07b6e67744e7846f3d55000dd86f1a5573a8ef79d15
    • Opcode Fuzzy Hash: 6e0dbdf68ebac07b8e07dae572509d1bc59e12a4c4e352d5f88c3b4cbd2dc1c0
    • Instruction Fuzzy Hash: 04415D21A0964286EA10FF23E4815BDE3A0AF547D4FC49933ED4D17B95EE3DF9068B24
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
    • String ID: csm$csm$csm
    • API String ID: 849930591-393685449
    • Opcode ID: aab7c7e636ea8a2572919ef13f94062ff4905efd63cd4babadd9079b892b9703
    • Instruction ID: 69294884ae0872cd2b9012ea3b8b84a05b8c5e9ef7182350ea766f9271b4202b
    • Opcode Fuzzy Hash: aab7c7e636ea8a2572919ef13f94062ff4905efd63cd4babadd9079b892b9703
    • Instruction Fuzzy Hash: 2CD16D32A0974186EB60AF26D4C03BDB7E0FB65788F900536EA4D57B9ADF39E091C710
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CurrentProcess
    • String ID: 1.3.1$Failed to extract %s: decompression resulted in return code %d!$Failed to extract %s: failed to allocate temporary input buffer!$Failed to extract %s: failed to allocate temporary output buffer!$Failed to extract %s: inflateInit() failed with return code %d!$malloc
    • API String ID: 2050909247-2813020118
    • Opcode ID: 7498d34eb7022638204d509c16463b156d406bb9cf128f30b27a0aca8b7a9da8
    • Instruction ID: bab3fcb3970cc4c3ef234a41564822f9c7db8a7ab7de70ed8b76c56a4385820a
    • Opcode Fuzzy Hash: 7498d34eb7022638204d509c16463b156d406bb9cf128f30b27a0aca8b7a9da8
    • Instruction Fuzzy Hash: BC51D122A0A64281EA20BF17E4803BEA2E1BF94794FC44533ED4D577C5EE3DE905CB20
    APIs
    • FreeLibrary.KERNEL32(?,?,?,00007FF7D4C0F0AA,?,?,-00000018,00007FF7D4C0AD53,?,?,?,00007FF7D4C0AC4A,?,?,?,00007FF7D4C05F3E), ref: 00007FF7D4C0EE8C
    • GetProcAddress.KERNEL32(?,?,?,00007FF7D4C0F0AA,?,?,-00000018,00007FF7D4C0AD53,?,?,?,00007FF7D4C0AC4A,?,?,?,00007FF7D4C05F3E), ref: 00007FF7D4C0EE98
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: AddressFreeLibraryProc
    • String ID: api-ms-$ext-ms-
    • API String ID: 3013587201-537541572
    • Opcode ID: 113d78e4ddfca44ef7199ea688f338981f8b4522c7c5ddaba00381c3941a83e2
    • Instruction ID: f8885b68728758850e1d12efc8db36abd1494a9cc9bd80fe3aca9d7d8f126ca0
    • Opcode Fuzzy Hash: 113d78e4ddfca44ef7199ea688f338981f8b4522c7c5ddaba00381c3941a83e2
    • Instruction Fuzzy Hash: 1341E262B19A1641EB15EF27D88857DA291FF48BD0FC8453BDD2D67794EE3CE4058220
    APIs
    • GetCurrentProcessId.KERNEL32(?,?,?,?,?,?,?,?,00007FF7D4BF3706,?,00007FF7D4BF3804), ref: 00007FF7D4BF2C9E
    • FormatMessageW.KERNEL32(?,?,?,?,?,?,?,?,00007FF7D4BF3706,?,00007FF7D4BF3804), ref: 00007FF7D4BF2D63
    • MessageBoxW.USER32 ref: 00007FF7D4BF2D99
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Message$CurrentFormatProcess
    • String ID: %ls: $<FormatMessageW failed.>$Error$[PYI-%d:ERROR]
    • API String ID: 3940978338-251083826
    • Opcode ID: c67c27f58c2af476bbbd059d0433c12e6f67668a4e3ecf6e42cf1bc8669f0b6b
    • Instruction ID: 486772491ba50209ba961a48e7ce98e5dd2dcb054b4dc721a8308fdb76316d73
    • Opcode Fuzzy Hash: c67c27f58c2af476bbbd059d0433c12e6f67668a4e3ecf6e42cf1bc8669f0b6b
    • Instruction Fuzzy Hash: D331F826708A4142E624BF26E8942BEA6A1BF987D8FC00137EF4D53759EF3DD546C720
    APIs
    • LoadLibraryExW.KERNEL32(?,?,?,00007FF7D4BFDF7A,?,?,?,00007FF7D4BFDC6C,?,?,?,00007FF7D4BFD869), ref: 00007FF7D4BFDD4D
    • GetLastError.KERNEL32(?,?,?,00007FF7D4BFDF7A,?,?,?,00007FF7D4BFDC6C,?,?,?,00007FF7D4BFD869), ref: 00007FF7D4BFDD5B
    • LoadLibraryExW.KERNEL32(?,?,?,00007FF7D4BFDF7A,?,?,?,00007FF7D4BFDC6C,?,?,?,00007FF7D4BFD869), ref: 00007FF7D4BFDD85
    • FreeLibrary.KERNEL32(?,?,?,00007FF7D4BFDF7A,?,?,?,00007FF7D4BFDC6C,?,?,?,00007FF7D4BFD869), ref: 00007FF7D4BFDDF3
    • GetProcAddress.KERNEL32(?,?,?,00007FF7D4BFDF7A,?,?,?,00007FF7D4BFDC6C,?,?,?,00007FF7D4BFD869), ref: 00007FF7D4BFDDFF
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Library$Load$AddressErrorFreeLastProc
    • String ID: api-ms-
    • API String ID: 2559590344-2084034818
    • Opcode ID: 276526191d17588ee9fa22b972cdf0953455baf5c8a53fb276b347519b5968a9
    • Instruction ID: 3a814992f5fe1a854c59251548a32b96b5cc15cacb4d55450fe4d190674c24bc
    • Opcode Fuzzy Hash: 276526191d17588ee9fa22b972cdf0953455baf5c8a53fb276b347519b5968a9
    • Instruction Fuzzy Hash: 1A31A025B1B68291EE11EF17D8801ADA3E8FF58BA4FD90537DD1E06394EF3DE4448220
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CurrentProcess
    • String ID: Failed to load Python DLL '%ls'.$LoadLibrary$Path of Python shared library (%s) and its name (%s) exceed buffer size (%d)$Path of ucrtbase.dll (%s) and its name exceed buffer size (%d)$Reported length (%d) of Python shared library name (%s) exceeds buffer size (%d)$ucrtbase.dll
    • API String ID: 2050909247-2434346643
    • Opcode ID: 2c49d70b8cf5be1e73da3264635f3f4e48fda49976f17b757535f0242ee4fe1a
    • Instruction ID: 3a9cfc93f902a4b8df8c80586f582827a83d53f42c7d7e0c91c4e9ba3e0d1c67
    • Opcode Fuzzy Hash: 2c49d70b8cf5be1e73da3264635f3f4e48fda49976f17b757535f0242ee4fe1a
    • Instruction Fuzzy Hash: E7418431A19A8691EA15FF26E4941EDA3A1FF64384FC00133EA5C436D5EF3DE516C760
    APIs
    • GetCurrentProcessId.KERNEL32(00000000,?,?,?,00000000,00007FF7D4BF351A,?,00000000,00007FF7D4BF3F1B), ref: 00007FF7D4BF2AA0
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CurrentProcess
    • String ID: 0$WARNING$Warning$Warning [ANSI Fallback]$[PYI-%d:%s]
    • API String ID: 2050909247-2900015858
    • Opcode ID: d3ff72078d09a899d0ca032b5bdbc8691629937d026b54217f09319e947088a3
    • Instruction ID: 20a5b637b9a10aa5f4b487e849bf6c08031d5ee918b70beb859d95678057fc9d
    • Opcode Fuzzy Hash: d3ff72078d09a899d0ca032b5bdbc8691629937d026b54217f09319e947088a3
    • Instruction Fuzzy Hash: F2217F32A19B8152E620AF52F8817EAA2A4FB887C4FC01137EE8C53659EF7CD5458A50
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Token$InformationProcess$CloseConvertCurrentErrorHandleLastOpenString
    • String ID:
    • API String ID: 995526605-0
    • Opcode ID: fa90e23b90d603ff8a1fc3170628a297920662056bab6e12f28c88f429b12389
    • Instruction ID: d8160b06aaf222c53edf1eb2560728f341e4b1332ab9f28d1253493b393710d4
    • Opcode Fuzzy Hash: fa90e23b90d603ff8a1fc3170628a297920662056bab6e12f28c88f429b12389
    • Instruction Fuzzy Hash: 9C212421A0DA4242EA50AF56F58422EE3B0EB957E0FD00637EAAD43BD4DF7DD4558B20
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Value$ErrorLast
    • String ID:
    • API String ID: 2506987500-0
    • Opcode ID: bd40692f84e3da01acd5c9e715af8932c2ff4b5b564443a413d720313231dc09
    • Instruction ID: ec0dc97e345aeb7aed0f3fb7f045ab1dcc6ed5511a96f658db6ba5e56fa1b663
    • Opcode Fuzzy Hash: bd40692f84e3da01acd5c9e715af8932c2ff4b5b564443a413d720313231dc09
    • Instruction Fuzzy Hash: E9212F28B0C64242F958BF63D5D913DE1565F447F0FD44637D93E66ACAED6CA4408720
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
    • String ID: CONOUT$
    • API String ID: 3230265001-3130406586
    • Opcode ID: 3755c2f75cb97972cd4ab37a7e27d28fd0bf6f95a56d27d10542fc75f089f0eb
    • Instruction ID: f91132153b749e0719175ea675b49c9ab07e56bca72dcbbef381cbc0f2ca4855
    • Opcode Fuzzy Hash: 3755c2f75cb97972cd4ab37a7e27d28fd0bf6f95a56d27d10542fc75f089f0eb
    • Instruction Fuzzy Hash: 7B117F21B18A4186E750AF53E8D432DB2A0BB98BE4FC00237EA5D87794DF7CD8148B60
    APIs
    • GetCurrentProcess.KERNEL32(?,FFFFFFFF,00000000,00007FF7D4BF3FA9), ref: 00007FF7D4BF8EFD
    • K32EnumProcessModules.KERNEL32(?,FFFFFFFF,00000000,00007FF7D4BF3FA9), ref: 00007FF7D4BF8F5A
      • Part of subcall function 00007FF7D4BF9390: MultiByteToWideChar.KERNEL32(?,?,?,00007FF7D4BF45F4,00000000,00007FF7D4BF1985), ref: 00007FF7D4BF93C9
    • K32GetModuleFileNameExW.KERNEL32(?,FFFFFFFF,00000000,00007FF7D4BF3FA9), ref: 00007FF7D4BF8FE5
    • K32GetModuleFileNameExW.KERNEL32(?,FFFFFFFF,00000000,00007FF7D4BF3FA9), ref: 00007FF7D4BF9044
    • FreeLibrary.KERNEL32(?,FFFFFFFF,00000000,00007FF7D4BF3FA9), ref: 00007FF7D4BF9055
    • FreeLibrary.KERNEL32(?,FFFFFFFF,00000000,00007FF7D4BF3FA9), ref: 00007FF7D4BF906A
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: FileFreeLibraryModuleNameProcess$ByteCharCurrentEnumModulesMultiWide
    • String ID:
    • API String ID: 3462794448-0
    • Opcode ID: 51e73ccb600dcf9d750c353d1e93921ada3daf916e275faff0d4d54491eeaa6f
    • Instruction ID: 6e8121c7dd6a669bd29f79b22df184f7605774419bbf29d1a970fb120dfb46c5
    • Opcode Fuzzy Hash: 51e73ccb600dcf9d750c353d1e93921ada3daf916e275faff0d4d54491eeaa6f
    • Instruction Fuzzy Hash: A9416362A1A68141EA20AE23E5802BEB3E4FB95BD4FC50136DF4D57789DE3DD541CB20
    APIs
      • Part of subcall function 00007FF7D4BF8570: GetCurrentProcess.KERNEL32 ref: 00007FF7D4BF8590
      • Part of subcall function 00007FF7D4BF8570: OpenProcessToken.ADVAPI32 ref: 00007FF7D4BF85A3
      • Part of subcall function 00007FF7D4BF8570: GetTokenInformation.ADVAPI32 ref: 00007FF7D4BF85C8
      • Part of subcall function 00007FF7D4BF8570: GetLastError.KERNEL32 ref: 00007FF7D4BF85D2
      • Part of subcall function 00007FF7D4BF8570: GetTokenInformation.ADVAPI32 ref: 00007FF7D4BF8612
      • Part of subcall function 00007FF7D4BF8570: ConvertSidToStringSidW.ADVAPI32 ref: 00007FF7D4BF862E
      • Part of subcall function 00007FF7D4BF8570: CloseHandle.KERNEL32 ref: 00007FF7D4BF8646
    • LocalFree.KERNEL32(?,00007FF7D4BF3C55), ref: 00007FF7D4BF916C
    • LocalFree.KERNEL32(?,00007FF7D4BF3C55), ref: 00007FF7D4BF9175
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Token$FreeInformationLocalProcess$CloseConvertCurrentErrorHandleLastOpenString
    • String ID: D:(A;;FA;;;%s)$D:(A;;FA;;;%s)(A;;FA;;;%s)$S-1-3-4$Security descriptor string length exceeds PYI_PATH_MAX!
    • API String ID: 6828938-1529539262
    • Opcode ID: 0222097b9c90264a1a2c87a2a2fde68e1a94831f5278aced0db9eca26447961c
    • Instruction ID: 12cea9c4e6514d43866c8324fabdbef17958acca9c02247fcb17a6e4a5906eb2
    • Opcode Fuzzy Hash: 0222097b9c90264a1a2c87a2a2fde68e1a94831f5278aced0db9eca26447961c
    • Instruction Fuzzy Hash: A6216D21A09A8291F610BF12E5952FEA2A0FF98780FC44033EA4D53796EF3DE9458760
    APIs
    • GetLastError.KERNEL32(?,?,?,00007FF7D4C04F11,?,?,?,?,00007FF7D4C0A48A,?,?,?,?,00007FF7D4C0718F), ref: 00007FF7D4C0B2D7
    • FlsSetValue.KERNEL32(?,?,?,00007FF7D4C04F11,?,?,?,?,00007FF7D4C0A48A,?,?,?,?,00007FF7D4C0718F), ref: 00007FF7D4C0B30D
    • FlsSetValue.KERNEL32(?,?,?,00007FF7D4C04F11,?,?,?,?,00007FF7D4C0A48A,?,?,?,?,00007FF7D4C0718F), ref: 00007FF7D4C0B33A
    • FlsSetValue.KERNEL32(?,?,?,00007FF7D4C04F11,?,?,?,?,00007FF7D4C0A48A,?,?,?,?,00007FF7D4C0718F), ref: 00007FF7D4C0B34B
    • FlsSetValue.KERNEL32(?,?,?,00007FF7D4C04F11,?,?,?,?,00007FF7D4C0A48A,?,?,?,?,00007FF7D4C0718F), ref: 00007FF7D4C0B35C
    • SetLastError.KERNEL32(?,?,?,00007FF7D4C04F11,?,?,?,?,00007FF7D4C0A48A,?,?,?,?,00007FF7D4C0718F), ref: 00007FF7D4C0B377
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Value$ErrorLast
    • String ID:
    • API String ID: 2506987500-0
    • Opcode ID: 511c86220214880ca4b01c77dd55d0a7de68e458561f726588d357ec3f22002e
    • Instruction ID: 36dfb4f6d8652856941409170e8944a07b8cd99fca1db875f6cc100b1312c6cd
    • Opcode Fuzzy Hash: 511c86220214880ca4b01c77dd55d0a7de68e458561f726588d357ec3f22002e
    • Instruction Fuzzy Hash: A4118E24B0C64282FA58BF63D6D913DE1469F48BF0FD44737D92E676D6EE6CA4414320
    APIs
    • GetCurrentProcessId.KERNEL32(?,?,?,?,00000000,00000000,?,00000000,00007FF7D4BF1B6A), ref: 00007FF7D4BF295E
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CurrentProcess
    • String ID: %s: %s$Error$Error [ANSI Fallback]$[PYI-%d:ERROR]
    • API String ID: 2050909247-2962405886
    • Opcode ID: b3354eec44a94607d33eb4f3788ab89374ba031f66333e1b118589dca889f3f3
    • Instruction ID: f4228989cd7811dc98604ae63d993f9aeb25e9650c58a2bda6c8a3b9b17e730a
    • Opcode Fuzzy Hash: b3354eec44a94607d33eb4f3788ab89374ba031f66333e1b118589dca889f3f3
    • Instruction Fuzzy Hash: 1831E922B1968152E710BB62E8816EFA2D4BF987D4FC04133EE8D53755EF3DD5468620
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: DeleteDestroyDialogHandleIconIndirectModuleObjectParam
    • String ID: Unhandled exception in script
    • API String ID: 3081866767-2699770090
    • Opcode ID: 1a8653f9ef4157c26f2335c81c204ff7a5d47729ffdf6617f9212c2ec85f79f4
    • Instruction ID: b13f25a6e0d9347482a745e228ebda35176cb4a2514f6ad515302e93d1e21a83
    • Opcode Fuzzy Hash: 1a8653f9ef4157c26f2335c81c204ff7a5d47729ffdf6617f9212c2ec85f79f4
    • Instruction Fuzzy Hash: E231607261968189EB24EF22E8952FEA3A0FF88784FC40137EA4D57B59DF3CD1058720
    APIs
    • GetCurrentProcessId.KERNEL32(?,00000000,00000000,FFFFFFFF,00000000,00007FF7D4BF918F,?,00007FF7D4BF3C55), ref: 00007FF7D4BF2BA0
    • MessageBoxW.USER32 ref: 00007FF7D4BF2C2A
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CurrentMessageProcess
    • String ID: WARNING$Warning$[PYI-%d:%ls]
    • API String ID: 1672936522-3797743490
    • Opcode ID: 4a0b6e8ebe13cae449087f655af1d2523953ec7fd560ce9a50e7097f48d063a1
    • Instruction ID: 2aeb1e7240cf30573f8d9135d8a53bb795d5683a67e8fada7df18452873bc05a
    • Opcode Fuzzy Hash: 4a0b6e8ebe13cae449087f655af1d2523953ec7fd560ce9a50e7097f48d063a1
    • Instruction Fuzzy Hash: D821BC22709B4182E710AF26F8857AEA3A4FB887C0FC00137EE8D5365AEE3CD645C750
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: AddressFreeHandleLibraryModuleProc
    • String ID: CorExitProcess$mscoree.dll
    • API String ID: 4061214504-1276376045
    • Opcode ID: b239dd027a539e56a716c05e535b4da9cb8e2339e08a4dc57142401ef2416000
    • Instruction ID: 031acd8ca4f06a9b200d2dc2e806a0b78afd3b3116213c15d60e3dedcc110c65
    • Opcode Fuzzy Hash: b239dd027a539e56a716c05e535b4da9cb8e2339e08a4dc57142401ef2416000
    • Instruction Fuzzy Hash: 3EF04F61A0960681EA10AF26E4D837EA330AF497E1FD40237DA6E462E4DF6CD145C730
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _set_statfp
    • String ID:
    • API String ID: 1156100317-0
    • Opcode ID: bce21d2362216a5e504affcf34f2858e363de54600403cac3d1eeb36cb2ab404
    • Instruction ID: f973ca3645580d085923c9f6c763d9b52df95856d2028533d2cca350261cab06
    • Opcode Fuzzy Hash: bce21d2362216a5e504affcf34f2858e363de54600403cac3d1eeb36cb2ab404
    • Instruction Fuzzy Hash: F1118222E5CA0301FA643D67E4D137D9070AF593E0FC80677EA6F162E68E6CA846C131
    APIs
    • FlsGetValue.KERNEL32(?,?,?,00007FF7D4C0A5A3,?,?,00000000,00007FF7D4C0A83E,?,?,?,?,?,00007FF7D4C0A7CA), ref: 00007FF7D4C0B3AF
    • FlsSetValue.KERNEL32(?,?,?,00007FF7D4C0A5A3,?,?,00000000,00007FF7D4C0A83E,?,?,?,?,?,00007FF7D4C0A7CA), ref: 00007FF7D4C0B3CE
    • FlsSetValue.KERNEL32(?,?,?,00007FF7D4C0A5A3,?,?,00000000,00007FF7D4C0A83E,?,?,?,?,?,00007FF7D4C0A7CA), ref: 00007FF7D4C0B3F6
    • FlsSetValue.KERNEL32(?,?,?,00007FF7D4C0A5A3,?,?,00000000,00007FF7D4C0A83E,?,?,?,?,?,00007FF7D4C0A7CA), ref: 00007FF7D4C0B407
    • FlsSetValue.KERNEL32(?,?,?,00007FF7D4C0A5A3,?,?,00000000,00007FF7D4C0A83E,?,?,?,?,?,00007FF7D4C0A7CA), ref: 00007FF7D4C0B418
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Value
    • String ID:
    • API String ID: 3702945584-0
    • Opcode ID: 6f944022d23edc1c4acf36ee41aa723466f994e0e1af3fb98e05b0010e79b0d5
    • Instruction ID: fa482daf633637e3f57b1585e942008f61879b83b0966950328d55ea660c7ea4
    • Opcode Fuzzy Hash: 6f944022d23edc1c4acf36ee41aa723466f994e0e1af3fb98e05b0010e79b0d5
    • Instruction Fuzzy Hash: AD115C20A0C60241FA58BBA7D5D913DA1419F447E0FD84637EA2D666C6EE6CA5418220
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Value
    • String ID:
    • API String ID: 3702945584-0
    • Opcode ID: cf61fb6c00b1796c5bed08ecf7b6551a73a14dc995a044f45feadad5ae41d3ad
    • Instruction ID: a0af070aa7bce752f6e9c92650c2e4d031e17ada67ae5d5b42642c586cab814c
    • Opcode Fuzzy Hash: cf61fb6c00b1796c5bed08ecf7b6551a73a14dc995a044f45feadad5ae41d3ad
    • Instruction Fuzzy Hash: 09111824E0920782F958BEA3C4DA57EA1424F457F4FC44737DA3E7A6C2ED6CB4408231
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: verbose
    • API String ID: 3215553584-579935070
    • Opcode ID: 8c3a45f75ca5c0a3459ca2e96ae2fbbf181a3d63a640e770f0a7cf37c7606cec
    • Instruction ID: 495cfa1e67124da363cbc695c7fa59e9869294893957242aba39fe52abe88d27
    • Opcode Fuzzy Hash: 8c3a45f75ca5c0a3459ca2e96ae2fbbf181a3d63a640e770f0a7cf37c7606cec
    • Instruction Fuzzy Hash: CE91D332B0864681FB60AE26D49A37DB7A5AF40BD4FC84137DA5D673D6DE3DE4058320
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: UTF-16LEUNICODE$UTF-8$ccs
    • API String ID: 3215553584-1196891531
    • Opcode ID: 7089664b0a027e884898b454f5d4d61e653d4f3baae8c024cbe23c99275e4c13
    • Instruction ID: a4f32502f7afffaccdb06ba2aa2a64eaf9a2a5ab373edd4914971697125bded6
    • Opcode Fuzzy Hash: 7089664b0a027e884898b454f5d4d61e653d4f3baae8c024cbe23c99275e4c13
    • Instruction Fuzzy Hash: 19819172E0C24285F7657F2BC1D927CB6A0AB11BC4FD54037CA0DA7295CBADE9829721
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
    • String ID: csm
    • API String ID: 2395640692-1018135373
    • Opcode ID: 4bd751ab4a757734da5bac4c310991cbc8ef63d187f18c7a3c34a87046479a0f
    • Instruction ID: 79a34c4690f907c41517df622cd0856f0807c64ae346ce9f3e54ad59f87f58f3
    • Opcode Fuzzy Hash: 4bd751ab4a757734da5bac4c310991cbc8ef63d187f18c7a3c34a87046479a0f
    • Instruction Fuzzy Hash: 5651A236B1AA828ADB14EF16D084A7CB3D9EB54B98FD04136DA4E47748DF7EE841C710
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CallEncodePointerTranslator
    • String ID: MOC$RCC
    • API String ID: 3544855599-2084237596
    • Opcode ID: 1c81a5d02d7979dd4dad50f55436adaf5051385037e661534b2c2f58034018d3
    • Instruction ID: 5cfae5ff94cc6be98f7c61fb475aed6baed7a502484adb4994519a03e0972092
    • Opcode Fuzzy Hash: 1c81a5d02d7979dd4dad50f55436adaf5051385037e661534b2c2f58034018d3
    • Instruction Fuzzy Hash: BD617132909BC585E760AF26E4803AEFBA0FB95794F844226EB9D03B55DF7DD190CB10
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
    • String ID: csm$csm
    • API String ID: 3896166516-3733052814
    • Opcode ID: b828653c103bc27f8420a51a056d9897bfd6e6497fd7c081c32eb92dd3ed2bbb
    • Instruction ID: 46bd9ef804a1f3e83a9f272f988e7a513c733640019c7b4ba1bbafdba47cee37
    • Opcode Fuzzy Hash: b828653c103bc27f8420a51a056d9897bfd6e6497fd7c081c32eb92dd3ed2bbb
    • Instruction Fuzzy Hash: 75517D32A0928286EB74AE2BD0C426CBBE0EB65B84FD44137DA4D47B85CF3EE451C711
    APIs
    • CreateDirectoryW.KERNEL32(00000000,?,00007FF7D4BF352C,?,00000000,00007FF7D4BF3F1B), ref: 00007FF7D4BF7F32
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CreateDirectory
    • String ID: %.*s$%s%c$\
    • API String ID: 4241100979-1685191245
    • Opcode ID: a1c59376f93c8b4c6db0aee125681cb96c2ab9e1787ffa8cf6eb7b68f1c1c36c
    • Instruction ID: f0a57657b9894909c3a38b17ab714d844fff59cd727e0e343778669a090ead79
    • Opcode Fuzzy Hash: a1c59376f93c8b4c6db0aee125681cb96c2ab9e1787ffa8cf6eb7b68f1c1c36c
    • Instruction Fuzzy Hash: 0631EC2161AAC145EA21AF12E4907EEA394EF94BE0FC01632EE6D477C5EF3DD5458710
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: Message
    • String ID: ERROR$Error$[PYI-%d:%ls]
    • API String ID: 2030045667-255084403
    • Opcode ID: 035b7a672ed8def45fe49a9c290554376ffedfd07499b26c39d849b73b89d90e
    • Instruction ID: 90a1ecb6b30e64e759f2b2bc3457b42b33fef3a678c4e09f7457cb4c774d7604
    • Opcode Fuzzy Hash: 035b7a672ed8def45fe49a9c290554376ffedfd07499b26c39d849b73b89d90e
    • Instruction Fuzzy Hash: 8A21BF62B09B4192E710AF26F8857AEA3A0FB887C0FC04137EA8D53659EE3CD645C750
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: FileWrite$ConsoleErrorLastOutput
    • String ID:
    • API String ID: 2718003287-0
    • Opcode ID: 04e310725d937c0b27e7ac1e6c46040fced781be2c4963351fe3137ba04acc33
    • Instruction ID: 832b9ead7a8ad2875ec2d5618f2f720c220ce5ed0c0a01933050c067ea5e44e5
    • Opcode Fuzzy Hash: 04e310725d937c0b27e7ac1e6c46040fced781be2c4963351fe3137ba04acc33
    • Instruction Fuzzy Hash: 9BD1F172B08A418AE714DF6AD4842AC77B1FB147D8BC44227DE5DA7BD9DE38D006CB10
    APIs
    • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF7D4C0CF4B), ref: 00007FF7D4C0D07C
    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF7D4C0CF4B), ref: 00007FF7D4C0D107
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: ConsoleErrorLastMode
    • String ID:
    • API String ID: 953036326-0
    • Opcode ID: a47a8d54e36ced6583969bea4ac316e5fdc1f02f5f342ddc714eca2f45cad1a1
    • Instruction ID: 7305d066d396f2dacb0782c4ffbb0667c8c025c153e6a497ea54e7706baec015
    • Opcode Fuzzy Hash: a47a8d54e36ced6583969bea4ac316e5fdc1f02f5f342ddc714eca2f45cad1a1
    • Instruction Fuzzy Hash: 8991B636E1869185F750AF66D4C827DABA0AB44BD8FD44137EE0E67694DF38D442C720
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _get_daylight$_isindst
    • String ID:
    • API String ID: 4170891091-0
    • Opcode ID: 873197461a12b50781dd6dd2a54ab0b7f590f407db75148e336b6c99fa373a01
    • Instruction ID: 9d7cbbc14247942d3deb48bbf64635fd5b099ac6d482b955d12edbb94110b580
    • Opcode Fuzzy Hash: 873197461a12b50781dd6dd2a54ab0b7f590f407db75148e336b6c99fa373a01
    • Instruction Fuzzy Hash: C5513772F042118AEB14EF65C9D96BCA761AB043D8FD01237DD1E62AE4DF38A542CB10
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: File$ErrorHandleInformationLastNamedPeekPipeType
    • String ID:
    • API String ID: 2780335769-0
    • Opcode ID: 601044899bb77d1db34704472f686b9691880a3163deed0eb7e9945e8072c835
    • Instruction ID: 412731dd1a2170b733001fd064df7abc476d863e38ead39547c95d0a98a1b425
    • Opcode Fuzzy Hash: 601044899bb77d1db34704472f686b9691880a3163deed0eb7e9945e8072c835
    • Instruction Fuzzy Hash: 40517D62E086418AFB20EF72D4943BDB7A5AB48B98FD44537DE0D67689DF38D441C720
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CloseCreateFileHandle_invalid_parameter_noinfo
    • String ID:
    • API String ID: 1279662727-0
    • Opcode ID: b1746a8a916bbf96797ffba89da9809a683c49b2a7b1d8f7dd6efe5c63c8eb6a
    • Instruction ID: 81f46c07dad49079ff3ca9d3e0a2a8fa575d5b3cdb03b445afd4b6b96edc68f6
    • Opcode Fuzzy Hash: b1746a8a916bbf96797ffba89da9809a683c49b2a7b1d8f7dd6efe5c63c8eb6a
    • Instruction Fuzzy Hash: C841A322D2878183E710EF22D59836DA260FB947E4F909337EA5C13AD5DF7CA5E08720
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: LongWindow$DialogInvalidateRect
    • String ID:
    • API String ID: 1956198572-0
    • Opcode ID: 3f66ec3ad31a24d6b03c6ecd933265a99c2c3f38e7b83c206d3886b5f9d1bb92
    • Instruction ID: c2300b04c215560969d27953d6c78ed5601bc2fbc9608505c44df617557f4c9d
    • Opcode Fuzzy Hash: 3f66ec3ad31a24d6b03c6ecd933265a99c2c3f38e7b83c206d3886b5f9d1bb92
    • Instruction Fuzzy Hash: D8118A21A1C14242F658AF6BE5C427D92A1EB987C0FC48032DB4D07B99DD3FD5A58624
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: _get_daylight$_invalid_parameter_noinfo
    • String ID: ?
    • API String ID: 1286766494-1684325040
    • Opcode ID: 34aa9ba053483d92f686c00bb3d23c2ed0895a5cb55bf09a4ef316522e0c30cf
    • Instruction ID: 30065cdb0fe2620c5e18fb7d57c6d315f331896488219b8072ba214ddad8e690
    • Opcode Fuzzy Hash: 34aa9ba053483d92f686c00bb3d23c2ed0895a5cb55bf09a4ef316522e0c30cf
    • Instruction Fuzzy Hash: AE41E512A0828286FB64AF27D49577EE6B0EB84BE4FD44237EE5D06AD5DF3CD4418720
    APIs
    • _invalid_parameter_noinfo.LIBCMT ref: 00007FF7D4C09046
      • Part of subcall function 00007FF7D4C0A948: HeapFree.KERNEL32(?,?,?,00007FF7D4C12D22,?,?,?,00007FF7D4C12D5F,?,?,00000000,00007FF7D4C13225,?,?,?,00007FF7D4C13157), ref: 00007FF7D4C0A95E
      • Part of subcall function 00007FF7D4C0A948: GetLastError.KERNEL32(?,?,?,00007FF7D4C12D22,?,?,?,00007FF7D4C12D5F,?,?,00000000,00007FF7D4C13225,?,?,?,00007FF7D4C13157), ref: 00007FF7D4C0A968
    • GetModuleFileNameW.KERNEL32(?,?,?,?,?,00007FF7D4BFCBA5), ref: 00007FF7D4C09064
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: ErrorFileFreeHeapLastModuleName_invalid_parameter_noinfo
    • String ID: C:\Users\user\Desktop\j1gw88aHdL.exe
    • API String ID: 3580290477-3630012993
    • Opcode ID: 652ac8178d02f9bf502bb0dac840cc2c27021cfa98e1c84195502d2d1921a3a9
    • Instruction ID: 3dff8463e8264c3f01ff7a9f284275cc49ce5368565a19213fb3ad926cfbaa2d
    • Opcode Fuzzy Hash: 652ac8178d02f9bf502bb0dac840cc2c27021cfa98e1c84195502d2d1921a3a9
    • Instruction Fuzzy Hash: 4E417236A08B0286EB15FF26D4C81BDA7A4EF45BD4BD54037E94D53B85DE3DE4818320
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: ErrorFileLastWrite
    • String ID: U
    • API String ID: 442123175-4171548499
    • Opcode ID: 4f5d94246872f2193e537bc66f33c90add5f7e97f4787e66017fcfb3b1ebd6d4
    • Instruction ID: fc9b919dccb88e36fbac99816fd51955c1971a7bc3fdf557472f3bc73f3bc5ec
    • Opcode Fuzzy Hash: 4f5d94246872f2193e537bc66f33c90add5f7e97f4787e66017fcfb3b1ebd6d4
    • Instruction Fuzzy Hash: 6641A222618A4181DB209F26E4883BEA7A0FB987C4FC04133EA4D97794EF3CD441CB50
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: CurrentDirectory
    • String ID: :
    • API String ID: 1611563598-336475711
    • Opcode ID: e8d367c4ea258391d160676196091cc4497c978f166048fd005a5cb1bdaac227
    • Instruction ID: 2aa43886a07d6dd1d2d2ff897fc8662964f7ef5dd83be91e44f3feda04e534d8
    • Opcode Fuzzy Hash: e8d367c4ea258391d160676196091cc4497c978f166048fd005a5cb1bdaac227
    • Instruction Fuzzy Hash: FE21B672A0864181EB20EF16D08827DB3B1FB98BC4FD54137D64D53694DFBCE9858B61
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: ExceptionFileHeaderRaise
    • String ID: csm
    • API String ID: 2573137834-1018135373
    • Opcode ID: b596af9f6a60738c50b353da5cbad86497326ffe12a5eabfdc94c01c9dae4a3e
    • Instruction ID: 6f79bff387d7b1d042fe1bf3c2afe428e880b64ec11f16273393bbc58b1f1f65
    • Opcode Fuzzy Hash: b596af9f6a60738c50b353da5cbad86497326ffe12a5eabfdc94c01c9dae4a3e
    • Instruction Fuzzy Hash: A0115136609B4182DB119F16E48026DB7E4FB88B84F984236DB8D07754DF3DC551CB10
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1386205347.00007FF7D4BF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BF0000, based on PE: true
    • Associated: 00000000.00000002.1386183045.00007FF7D4BF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386232769.00007FF7D4C1B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C2E000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386254291.00007FF7D4C32000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1386301703.00007FF7D4C34000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7d4bf0000_j1gw88aHdL.jbxd
    Similarity
    • API ID: DriveType_invalid_parameter_noinfo
    • String ID: :
    • API String ID: 2595371189-336475711
    • Opcode ID: 68237dfdc7112287ec82a3b365f776b5c9f6f856de5878160eaa1a8f91e0357f
    • Instruction ID: fc129123845e95f33779db6648b4ce616fdac83e1a37a4ef154992778b061de7
    • Opcode Fuzzy Hash: 68237dfdc7112287ec82a3b365f776b5c9f6f856de5878160eaa1a8f91e0357f
    • Instruction Fuzzy Hash: C1018F2291860286F720BF63E4AA27EA3B0EF487C4FC00437D54D56A85EF2CE5048B34