Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
EpCAySF1G6.exe

Overview

General Information

Sample name:EpCAySF1G6.exe
renamed because original name is a hash value
Original sample name:6c2f397589156433b18b4c931a684a25.exe
Analysis ID:1581088
MD5:6c2f397589156433b18b4c931a684a25
SHA1:85364fdc36e163b705becb13a551a5625e930d50
SHA256:5f4c69564c3b8b8e151218444de219dc267207fa868b14622302f10c4726e5c0
Tags:exeValleyRATuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
AI detected suspicious sample
Contains functionality to detect sleep reduction / modifications
Tries to detect sandboxes / dynamic malware analysis system (QueryWinSAT)
Checks for available system drives (often done to infect USB drives)
Contains functionality for read data from the clipboard
Contains functionality to block mouse and keyboard input (often used to hinder debugging)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Contains functionality to modify clipboard data
Contains functionality to read the clipboard data
Contains functionality to simulate keystroke presses
Contains functionality to simulate mouse events
Creates a DirectInput object (often for capturing keystrokes)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Installs a global mouse hook
Internet Provider seen in connection with other malware
May check if the current machine is a sandbox (GetTickCount - Sleep)
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
Sample execution stops while process was sleeping (likely an evasion)
Stores large binary data to the registry

Classification

  • System is w10x64
  • EpCAySF1G6.exe (PID: 6792 cmdline: "C:\Users\user\Desktop\EpCAySF1G6.exe" MD5: 6C2F397589156433B18B4C931A684A25)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-12-26T23:10:03.704899+010020528751A Network Trojan was detected192.168.2.4497308.218.163.626666TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: EpCAySF1G6.exeReversingLabs: Detection: 68%
Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
Source: EpCAySF1G6.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: z:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: x:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: v:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: t:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: r:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: p:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: n:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: l:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: j:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: h:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: f:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: b:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: y:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: w:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: u:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: s:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: q:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: o:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: m:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: k:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: i:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: g:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: e:Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile opened: [:Jump to behavior

Networking

barindex
Source: Network trafficSuricata IDS: 2052875 - Severity 1 - ET MALWARE Anonymous RAT CnC Checkin : 192.168.2.4:49730 -> 8.218.163.62:6666
Source: global trafficTCP traffic: 192.168.2.4:49730 -> 8.218.163.62:6666
Source: Joe Sandbox ViewASN Name: CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: unknownTCP traffic detected without corresponding DNS query: 8.218.163.62
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_00000001800036B0 select,recv,_errno,_errno,_errno,0_3_00000001800036B0
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_0000000180006D99 OpenClipboard,GetClipboardData,CloseClipboard,GlobalSize,GlobalLock,GlobalUnlock,CloseClipboard,0_3_0000000180006D99
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_0000000180006DB0 OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,GlobalUnlock,SetClipboardData,GlobalFree,CloseClipboard,0_3_0000000180006DB0
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_00000001800076C3 OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,GlobalUnlock,SetClipboardData,GlobalFree,CloseClipboard,0_3_00000001800076C3
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_0000000180006D99 OpenClipboard,GetClipboardData,CloseClipboard,GlobalSize,GlobalLock,GlobalUnlock,CloseClipboard,0_3_0000000180006D99
Source: EpCAySF1G6.exe, 00000000.00000003.2238000309.0000000003D98000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: DirectInput8Creatememstr_10fcfc40-f
Source: C:\Users\user\Desktop\EpCAySF1G6.exeWindows user hook set: 0 mouse low level C:\Windows\SYSTEM32\DINPUT8.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_00000001800033B00_3_00000001800033B0
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_000000018000DC000_3_000000018000DC00
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_00000001800078700_3_0000000180007870
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_00000001800028800_3_0000000180002880
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_000000018000A88C0_3_000000018000A88C
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_000000018003BC940_3_000000018003BC94
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_0000000180030DA00_3_0000000180030DA0
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_000000018000B3600_3_000000018000B360
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_00000001800073700_3_0000000180007370
Source: classification engineClassification label: mal68.evad.winEXE@1/0@0/1
Source: C:\Users\user\Desktop\EpCAySF1G6.exeMutant created: \Sessions\1\BaseNamedObjects\2024.12.22
Source: EpCAySF1G6.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\EpCAySF1G6.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: EpCAySF1G6.exeReversingLabs: Detection: 68%
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: winmm.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: napinsp.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: pnrpnsp.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: wshbth.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: nlaapi.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: winrnr.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: dinput8.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: devenum.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: devobj.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: msdmo.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62BE5D10-60EB-11d0-BD3B-00A0C911CE86}\InprocServer32Jump to behavior
Source: EpCAySF1G6.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: EpCAySF1G6.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_000000018000D6C8 LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,0_3_000000018000D6C8
Source: EpCAySF1G6.exeStatic PE information: real checksum: 0x2bb4f should be: 0x20c8f
Source: C:\Users\user\Desktop\EpCAySF1G6.exeKey value created or modified: HKEY_CURRENT_USER\Console\1 d33f351a4aeea5e608853d1a56661059Jump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_00000001800086000_3_0000000180008600
Source: C:\Users\user\Desktop\EpCAySF1G6.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{05DF8D13-C355-47F4-A11E-851B338CEFB8}Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeWindow / User API: threadDelayed 365Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeWindow / User API: threadDelayed 4756Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeWindow / User API: threadDelayed 470Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_00000001800086000_3_0000000180008600
Source: C:\Users\user\Desktop\EpCAySF1G6.exe TID: 6972Thread sleep count: 365 > 30Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exe TID: 7096Thread sleep count: 75 > 30Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exe TID: 7096Thread sleep time: -75000s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exe TID: 7084Thread sleep count: 4756 > 30Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exe TID: 7084Thread sleep time: -47560s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exe TID: 6160Thread sleep count: 470 > 30Jump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeLast function: Thread delayed
Source: C:\Users\user\Desktop\EpCAySF1G6.exeLast function: Thread delayed
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_0000000180007220 WaitForSingleObject,SleepEx,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,SystemParametersInfoW,PostMessageW,SystemParametersInfoW,PostMessageW,BlockInput,SleepEx,BlockInput,0_3_0000000180007220
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_00000001800090E0 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_3_00000001800090E0
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_000000018000D6C8 LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,0_3_000000018000D6C8
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_00000001800090E0 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_3_00000001800090E0
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_000000018000AB74 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_3_000000018000AB74
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_0000000180007370 BlockInput,GetDeviceCaps,GetDeviceCaps,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,mouse_event,0_3_0000000180007370
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_0000000180007591 mouse_event,0_3_0000000180007591
Source: EpCAySF1G6.exe, 00000000.00000003.2068644632.0000000003DDC000.00000004.00000020.00020000.00000000.sdmp, EpCAySF1G6.exe, 00000000.00000003.2238000309.0000000003DDC000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: 0 minProgram Manager
Source: EpCAySF1G6.exe, 00000000.00000003.2759712941.0000000003DDC000.00000004.00000020.00020000.00000000.sdmp, EpCAySF1G6.exe, 00000000.00000003.2434810732.0000000003DDC000.00000004.00000020.00020000.00000000.sdmp, EpCAySF1G6.exe, 00000000.00000003.2921591496.0000000003DDC000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Program Manager;;W
Source: EpCAySF1G6.exe, 00000000.00000003.1776763826.0000000003D52000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Windows 10 Pro10.0.190454HDD:1WW 223 Gb Free 168 Gb Mem: 8 Gb Free3 Gb Microsoft Basic Render Driver 0 5140 Microsoft Basic Render Driver 0 5140 Program Manager
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_000000018000D154 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter,0_3_000000018000D154
Source: C:\Users\user\Desktop\EpCAySF1G6.exeCode function: 0_3_000000018000A438 HeapCreate,GetVersion,HeapSetInformation,0_3_000000018000A438
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
1
Native API
1
DLL Side-Loading
1
Process Injection
1
Modify Registry
2
Input Capture
1
System Time Discovery
Remote Services2
Input Capture
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory22
Security Software Discovery
Remote Desktop Protocol1
Archive Collected Data
1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Disable or Modify Tools
Security Account Manager1
Virtualization/Sandbox Evasion
SMB/Windows Admin Shares3
Clipboard Data
1
Ingress Tool Transfer
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS2
Process Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets1
Application Window Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials11
Peripheral Device Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync4
System Information Discovery
Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
EpCAySF1G6.exe68%ReversingLabsWin64.Backdoor.Farfli
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
8.218.163.62
unknownSingapore
45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCtrue
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581088
Start date and time:2024-12-26 23:09:10 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 6m 11s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run name:Run with higher sleep bypass
Number of analysed new started processes analysed:5
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:EpCAySF1G6.exe
renamed because original name is a hash value
Original Sample Name:6c2f397589156433b18b4c931a684a25.exe
Detection:MAL
Classification:mal68.evad.winEXE@1/0@0/1
EGA Information:Failed
HCA Information:
  • Successful, ratio: 97%
  • Number of executed functions: 15
  • Number of non-executed functions: 82
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Sleeps bigger than 100000000ms are automatically reduced to 1000ms
  • Sleep loops longer than 100000000ms are bypassed. Single calls with delay of 100000000ms and higher are ignored
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
  • Excluded IPs from analysis (whitelisted): 20.109.210.53, 13.107.246.63
  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Execution Graph export aborted for target EpCAySF1G6.exe, PID 6792 because there are no executed function
  • Not all processes where analyzed, report is missing behavior information
  • Report size getting too big, too many NtEnumerateKey calls found.
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • VT rate limit hit for: EpCAySF1G6.exe
No simulations
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCxd.ppc.elfGet hashmaliciousMiraiBrowse
  • 47.245.158.74
loligang.mpsl.elfGet hashmaliciousMiraiBrowse
  • 47.57.184.195
T1#U5b89#U88c5#U52a9#U624b1.0.2.exeGet hashmaliciousNitolBrowse
  • 8.212.102.187
splarm7.elfGet hashmaliciousUnknownBrowse
  • 47.253.191.95
nabsh4.elfGet hashmaliciousUnknownBrowse
  • 47.240.78.242
splppc.elfGet hashmaliciousUnknownBrowse
  • 47.52.40.232
arm.elfGet hashmaliciousUnknownBrowse
  • 8.208.49.9
splx86.elfGet hashmaliciousUnknownBrowse
  • 47.241.90.97
armv4l.elfGet hashmaliciousUnknownBrowse
  • 8.222.176.99
No context
No context
No created / dropped files found
File type:PE32+ executable (GUI) x86-64, for MS Windows
Entropy (8bit):6.106036027086711
TrID:
  • Win64 Executable GUI (202006/5) 92.65%
  • Win64 Executable (generic) (12005/4) 5.51%
  • Generic Win/DOS Executable (2004/3) 0.92%
  • DOS Executable Generic (2002/1) 0.92%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:EpCAySF1G6.exe
File size:133'632 bytes
MD5:6c2f397589156433b18b4c931a684a25
SHA1:85364fdc36e163b705becb13a551a5625e930d50
SHA256:5f4c69564c3b8b8e151218444de219dc267207fa868b14622302f10c4726e5c0
SHA512:206fee1c1b0fdd4aa263a70d21fe0f81df6025085e03234881032ad77317c2ad90ada34bc47d3c6ac917541b7edd5ce618a93c3c3a4ce0dfdc92ba864d9be4ce
SSDEEP:3072:lO55k/y5dAj+BMTYlgEQnB+Y+pek7+3OrFZeUqe6oW:lO5n5d56TYZQnB+Dpekyyqm
TLSH:96D37D4733A450F9D4A78279C9A24A06E7B374660735A7CF17A086BA2F137D1BD3A331
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........VF.g.F.g.F.g.)...+.g.)...M.g.)...k.g.O...M.g.F.f...g.)...K.g.)...G.g.RichF.g.........................PE..d.....ld.........."
Icon Hash:90cececece8e8eb0
Entrypoint:0x140009a74
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x140000000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Time Stamp:0x646C86AC [Tue May 23 09:26:04 2023 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:5
OS Version Minor:2
File Version Major:5
File Version Minor:2
Subsystem Version Major:5
Subsystem Version Minor:2
Import Hash:fb51ede541a9ad63bf23d302e319d2a0
Instruction
dec eax
sub esp, 28h
call 00007F03ECB4C7E8h
dec eax
add esp, 28h
jmp 00007F03ECB489CBh
int3
int3
dec eax
mov dword ptr [esp+10h], ebx
dec eax
mov dword ptr [esp+18h], edi
push ebp
dec eax
mov ebp, esp
dec eax
sub esp, 60h
dec eax
mov edi, edx
dec eax
mov ebx, ecx
dec eax
lea ecx, dword ptr [ebp-40h]
dec eax
lea edx, dword ptr [0000EAE5h]
inc ecx
mov eax, 00000040h
call 00007F03ECB47B9Fh
dec eax
lea edx, dword ptr [ebp+10h]
dec eax
mov ecx, edi
dec eax
mov dword ptr [ebp-18h], ebx
dec eax
mov dword ptr [ebp-10h], edi
call 00007F03ECB50855h
dec esp
mov ebx, eax
dec eax
mov dword ptr [ebp+10h], eax
dec eax
mov dword ptr [ebp-08h], eax
dec eax
test edi, edi
je 00007F03ECB48B6Dh
test byte ptr [edi], 00000008h
mov ecx, 01994000h
je 00007F03ECB48B57h
mov dword ptr [ebp-20h], ecx
jmp 00007F03ECB48B5Eh
mov eax, dword ptr [ebp-20h]
dec ebp
test ebx, ebx
cmove eax, ecx
mov dword ptr [ebp-20h], eax
inc esp
mov eax, dword ptr [ebp-28h]
mov edx, dword ptr [ebp-3Ch]
mov ecx, dword ptr [ebp-40h]
dec esp
lea ecx, dword ptr [ebp-20h]
call dword ptr [0000E7AFh]
dec esp
lea ebx, dword ptr [esp+60h]
dec ecx
mov ebx, dword ptr [ebx+18h]
dec ecx
mov edi, dword ptr [ebx+20h]
dec ecx
mov esp, ebx
pop ebp
ret
int3
dec eax
mov dword ptr [esp+08h], ecx
dec eax
sub esp, 00000088h
dec eax
lea ecx, dword ptr [00016781h]
call dword ptr [0000E7B3h]
dec eax
mov eax, dword ptr [0001686Ch]
Programming Language:
  • [ C ] VS2010 build 30319
  • [ASM] VS2010 build 30319
  • [C++] VS2010 build 30319
  • [IMP] VS2008 SP1 build 30729
  • [LNK] VS2010 build 30319
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0x1d0280x78.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0x270000x1b4.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x250000x1578.pdata
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x280000x2f8.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x180000x438.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x166060x168009cde0d8ddbf108908aa730f375bc1766False0.5621636284722222zlib compressed data6.429037086317127IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rdata0x180000x5d3a0x5e00b44503f0aa67867070e1b6433af825a5False0.3683926196808511data4.8111582224132965IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0x1e0000x67700x22004dddad5b9c888efde6aff4d8b6f42a73False0.22047334558823528data2.6960600551063005IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.pdata0x250000x15780x16006b2fcd8de66b48f900df2c9c6b6db832False0.4728338068181818data5.019696142888745IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.rsrc0x270000x1b40x2005f882a758b6b0045acd02c3e0551be90False0.486328125data5.112623549532036IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0x280000x5be0x6003b9d434e2274fd734402fea8d43c6f67False0.3587239583333333data3.4572271853315204IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
RT_MANIFEST0x270580x15aASCII text, with CRLF line terminatorsEnglishUnited States0.5491329479768786
DLLImport
KERNEL32.dllHeapCreate, EnterCriticalSection, DeleteCriticalSection, WaitForSingleObject, SetEvent, Sleep, CreateEventA, GetLastError, CloseHandle, GetCurrentThreadId, SwitchToThread, SetLastError, WideCharToMultiByte, lstrlenW, ResetEvent, CreateEventW, CancelIo, TryEnterCriticalSection, SetWaitableTimer, CreateWaitableTimerW, GetThreadContext, SetThreadContext, LeaveCriticalSection, GetExitCodeProcess, CreateProcessA, GetSystemDirectoryA, VirtualAllocEx, WriteProcessMemory, ResumeThread, FreeLibrary, SetUnhandledExceptionFilter, GetCurrentProcess, LoadLibraryW, GetConsoleWindow, CreateFileW, GetProcAddress, GetLocalTime, IsDebuggerPresent, GetCurrentProcessId, CreateThread, LCMapStringW, WriteConsoleW, SetStdHandle, GetStringTypeW, MultiByteToWideChar, HeapDestroy, InitializeCriticalSectionAndSpinCount, HeapFree, HeapAlloc, VirtualAlloc, OpenProcess, VirtualFree, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, GetConsoleMode, FlushFileBuffers, GetConsoleCP, SetFilePointer, GetSystemTimeAsFileTime, GetTickCount, QueryPerformanceCounter, GetStartupInfoW, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, RtlUnwindEx, FlsAlloc, FlsFree, FlsSetValue, FlsGetValue, HeapReAlloc, HeapSize, GetProcessHeap, ExitThread, DecodePointer, EncodePointer, GetCommandLineW, RaiseException, RtlPcToFileHeader, TerminateProcess, UnhandledExceptionFilter, RtlVirtualUnwind, RtlLookupFunctionEntry, RtlCaptureContext, HeapSetInformation, GetVersion, GetModuleHandleW, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameW
USER32.dllDispatchMessageW, PostThreadMessageA, PeekMessageW, TranslateMessage, MsgWaitForMultipleObjects, ShowWindow, GetInputState, wsprintfW
ADVAPI32.dllRegCloseKey, RegOpenKeyExW, RegDeleteValueW, RegQueryValueExW, RegCreateKeyW, RegSetValueExW
WS2_32.dllWSAWaitForMultipleEvents, WSAIoctl, connect, WSAStartup, select, WSAResetEvent, setsockopt, recv, socket, closesocket, gethostbyname, send, WSASetLastError, WSACreateEvent, shutdown, WSAEventSelect, WSAEnumNetworkEvents, WSAGetLastError, WSACloseEvent, htons, WSACleanup
WINMM.dlltimeGetTime
Language of compilation systemCountry where language is spokenMap
EnglishUnited States
TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
2024-12-26T23:10:03.704899+01002052875ET MALWARE Anonymous RAT CnC Checkin1192.168.2.4497308.218.163.626666TCP
TimestampSource PortDest PortSource IPDest IP
Dec 26, 2024 23:10:03.554869890 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:03.674709082 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:03.674814939 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:03.704899073 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:03.824542999 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:05.220470905 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:05.221002102 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:05.340900898 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:05.340943098 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:05.340977907 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:05.767657995 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:05.767709017 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:05.767746925 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:05.767780066 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:05.767817020 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:05.767878056 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:05.817718983 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:05.999377966 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:05.999413013 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:05.999449015 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:05.999485970 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:05.999492884 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:05.999540091 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.007657051 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.007786036 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.007843971 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.016119957 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.016191959 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.016239882 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.024085045 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.024183989 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.024241924 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.191252947 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.231594086 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.231632948 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.231692076 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.235681057 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.235748053 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.235856056 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.244119883 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.244158030 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.244180918 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.252456903 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.252579927 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.252615929 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.260972977 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.261022091 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.261068106 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.269254923 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.269313097 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.269387960 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.277715921 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.277776957 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.277888060 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.286047935 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.286159992 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.286174059 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.294390917 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.294459105 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.464299917 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.464344025 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.464423895 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.468583107 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.468620062 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.468678951 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.476787090 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.476984024 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.477051020 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.485727072 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.485871077 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.485925913 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.493571043 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.493733883 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.493787050 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.501631975 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.501773119 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.501830101 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.510061026 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.510248899 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.510303020 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.518455029 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.518601894 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.518672943 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.526803017 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.526987076 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.527050018 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.535142899 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.535264969 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.535331011 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.655772924 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.696099997 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.696187019 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.696234941 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.699371099 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.699429989 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.699503899 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.706235886 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.706326008 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.706352949 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.712821960 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.712884903 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.712970972 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.719513893 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.719620943 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.719726086 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.726244926 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.726303101 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.726320982 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.732814074 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.732877970 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.732963085 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.739511013 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.739578009 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.739641905 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.746215105 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.746284962 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.746340990 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.752907991 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.752985001 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.753056049 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.759586096 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.759665966 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.759777069 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.766324043 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.766383886 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.766450882 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.773025990 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.773134947 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.930913925 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.930931091 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.930988073 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.932193995 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.932207108 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.932251930 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.937982082 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.938102961 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.938150883 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.944780111 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.944917917 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.944978952 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.951534986 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.951667070 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.951714993 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.957154036 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.957247972 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.957298040 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.965872049 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.965886116 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.965938091 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.970011950 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.970077038 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.970123053 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.976327896 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.976424932 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.976469994 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.982667923 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.982805967 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.982851028 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.989061117 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.989192963 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.989238024 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:06.995542049 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.995567083 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:06.995605946 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.001816988 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.001920938 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.001967907 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.008241892 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.008281946 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.008332014 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.014580011 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.014738083 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.014780045 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.020992041 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.021070004 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.021116018 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.027331114 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.027471066 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.027518034 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.033761024 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.033876896 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.033924103 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.161902905 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.162131071 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.162188053 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.164035082 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.164134026 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.164206028 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.168451071 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.168517113 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.168566942 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.172796011 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.172934055 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.172985077 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.177161932 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.177299976 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.177345037 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.181514978 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.181687117 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.181730986 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.185909033 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.186007023 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.186048985 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.190336943 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.190402985 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.190445900 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.195724010 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.195854902 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.195902109 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.199162960 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.199295044 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.199333906 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.203568935 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.203643084 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.203686953 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.207912922 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.208014965 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.208055973 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.212327003 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.212428093 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.212471962 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.216636896 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.216801882 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.216847897 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.221046925 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.221220016 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.221265078 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.225502014 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.225616932 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.225661993 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.229814053 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.229952097 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.230000019 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.234222889 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.234369040 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.234410048 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.238559961 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.238651037 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.238693953 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.242981911 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.243118048 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.243163109 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.247186899 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.247329950 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.247370958 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.251586914 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.251641035 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.251698017 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.392462015 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.392508984 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.392561913 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.394042015 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.394193888 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.394238949 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.397352934 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.397483110 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.397532940 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.400698900 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.400818110 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.400861979 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.404191017 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.404361963 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.404412031 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.407351017 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.407452106 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.407499075 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.410696030 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.410793066 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.410856962 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.414022923 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.414134979 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.414323092 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.417336941 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.417447090 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.417500019 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.420680046 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.420825958 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.420881033 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.424001932 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.424143076 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.424195051 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.427337885 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.427603960 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.427651882 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.430643082 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.430797100 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.430856943 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.434006929 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.434108973 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.434154987 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.437311888 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.437434912 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.437484026 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.440670013 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.440778017 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.440824986 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.444011927 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.444142103 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.444194078 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.447334051 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.447457075 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.447508097 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.450742960 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.450784922 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.450829029 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.453999996 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.454129934 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.454185963 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.457324028 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.457461119 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.457516909 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.460633993 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.460798979 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.460850954 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.463962078 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.464133978 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.464190960 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.467302084 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.467421055 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.467466116 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.470683098 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.470769882 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.470817089 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.473958015 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.474179983 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.474234104 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.477287054 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.477425098 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.477489948 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.480683088 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.480751991 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.480849028 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.483959913 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.484070063 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.484122038 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.487303019 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.536479950 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.624430895 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.624510050 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.624567986 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.625737906 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.625750065 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.625794888 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.628216982 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.628305912 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.628360987 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.630779028 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.630897999 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.630944967 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.633337975 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.633459091 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.633507013 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.635885954 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.636010885 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.636059046 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.638473988 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.638623953 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.638670921 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.641020060 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.641138077 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.641194105 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.643662930 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.643738985 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.643780947 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.646141052 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.646275997 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.646323919 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.648736000 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.648830891 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.648878098 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:07.651276112 CET6666497308.218.163.62192.168.2.4
Dec 26, 2024 23:10:07.692706108 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:08.678446054 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:08.798449993 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:08.798525095 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:10.661720037 CET497306666192.168.2.48.218.163.62
Dec 26, 2024 23:10:13.695470095 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:13.815454960 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:13.815476894 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:13.815493107 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:13.815517902 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:14.484566927 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:14.484852076 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:14.604490995 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:25.911722898 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:26.031147003 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:26.464457035 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:26.505229950 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:26.803904057 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:26.923652887 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:35.263329029 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:35.263353109 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:35.263361931 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:35.263452053 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:35.263797998 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:35.383337975 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:35.383353949 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:35.383367062 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.051640034 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.051676035 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.051687956 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.051719904 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.051817894 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.051830053 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.051840067 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.051865101 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.051877975 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.059947968 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.114667892 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.283433914 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.283534050 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.283588886 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.287611961 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.287631035 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.287679911 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.295994043 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.296135902 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.296175957 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.304356098 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.304461956 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.304510117 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.312681913 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.312802076 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.312840939 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.321078062 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.364669085 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.515311003 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.515424967 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.515470028 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.519509077 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.519604921 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.519645929 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.527889967 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.527966022 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.528007984 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.536312103 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.536406994 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.536444902 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.544635057 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.544749022 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.544785976 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.552983046 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.553090096 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.553138018 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.561451912 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.561574936 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.561618090 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.569936037 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.569961071 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.570005894 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.578134060 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.630263090 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.747061968 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.747107029 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.747154951 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.750520945 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.751972914 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.752016068 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.752075911 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.759708881 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.759728909 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.759771109 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.767246008 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.767292976 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.767353058 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.774872065 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.774923086 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.774986029 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.782582998 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.782607079 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.782630920 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.790127039 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.790175915 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.790205956 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.797739983 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.797796011 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.797854900 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.805488110 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.805536985 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.805541039 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.813036919 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.813081980 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.813088894 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.864615917 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.978455067 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.978529930 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.978590012 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.982219934 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.982369900 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.982414961 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:36.989814997 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.992556095 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.992574930 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:36.992607117 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.000358105 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.000432968 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.000451088 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.007803917 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.007857084 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.007962942 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.015431881 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.015486956 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.015489101 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.023175001 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.023185015 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.023237944 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.030704975 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.030756950 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.030827045 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.038367033 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.038417101 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.038431883 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.045929909 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.045994997 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.046058893 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.053563118 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.053615093 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.053621054 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.061152935 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.061207056 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.061269999 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.068784952 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.068845034 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.068916082 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.076416016 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.076463938 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.210294962 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.210438967 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.210483074 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.213500023 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.213641882 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.213680029 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.220277071 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.220288038 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.220333099 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.226728916 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.226773977 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.226814985 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.233377934 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.233388901 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.233426094 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.239886999 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.240015030 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.240051031 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.246511936 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.246618986 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.246659040 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.253249884 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.253338099 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.253379107 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.259843111 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.259884119 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.259918928 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.266390085 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.266467094 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.266501904 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.272927046 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.273005962 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.273046017 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.279495001 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.279601097 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.279640913 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.286148071 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.286261082 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.286304951 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.292642117 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.292793989 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.292841911 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.299320936 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.299447060 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.299498081 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.305898905 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.306031942 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.306073904 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.312552929 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.312563896 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.312606096 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.318975925 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.319159985 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.319201946 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.325452089 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.325579882 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.325628042 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.332916021 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.333007097 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.333048105 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.338849068 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.338860989 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.338900089 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.345248938 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.395931959 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.441791058 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.441855907 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.441895008 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.443170071 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.443181038 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.443223953 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.447546005 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.447696924 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.447746992 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.452040911 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.452155113 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.452193022 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.456414938 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.456522942 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.456585884 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.460745096 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.460916996 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.460968018 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.465107918 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.465428114 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.465475082 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.469302893 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.469409943 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.469460964 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.473437071 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.473566055 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.473609924 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.477607012 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.477694035 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.477736950 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.481704950 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.481806040 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.481846094 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.485852957 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.486006975 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.486059904 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.490032911 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.490222931 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.490268946 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.494152069 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.494277954 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.494323015 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.498256922 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.498363972 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.498414040 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.502434015 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.502542973 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.502598047 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.506545067 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.506669044 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.506719112 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.510662079 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.510781050 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.510834932 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.514878035 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.514962912 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.515005112 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.519021034 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.519165993 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.519203901 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.523123026 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.523297071 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.523334980 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.527415991 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.527555943 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.527600050 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.530524969 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.530628920 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.530667067 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.533766985 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.533915997 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.533946991 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.537111998 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.537157059 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.537199974 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.540297031 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.540409088 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.540451050 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.543592930 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.543699980 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.543740034 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.546884060 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.547178030 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.547224998 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.550124884 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.550143003 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.550185919 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.673515081 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.673636913 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.673711061 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.674675941 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.675162077 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.675211906 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.675283909 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.679999113 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.680011988 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.680059910 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.682087898 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.682140112 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.682245970 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.684453964 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.684497118 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.684627056 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.687131882 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.687182903 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.687274933 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.687982082 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.687994003 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.688030958 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.690053940 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.690120935 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.690179110 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.692519903 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.692572117 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.692600012 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.694977999 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.695029020 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.695102930 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.697406054 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.697449923 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.697513103 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.699863911 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.699911118 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.699973106 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.702361107 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.702402115 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.702426910 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.704809904 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.704850912 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.704922915 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.707340956 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.707398891 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.707401037 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.709764957 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.709822893 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.709860086 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.712256908 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.712301016 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.712342024 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.714716911 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.714765072 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.714797974 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.717183113 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.717232943 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.717339039 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.719703913 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.719744921 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.719786882 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.722167969 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.722229004 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.722313881 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.724636078 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.724683046 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.724684954 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.727101088 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.727144957 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.727303028 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.729742050 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.729794025 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.729816914 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.732036114 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.732089043 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.732148886 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.734498024 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.734550953 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.734606981 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.736967087 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.737023115 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.737101078 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.739475012 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.739516973 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.739597082 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.741946936 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.741985083 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.741991997 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.744380951 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.744436026 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.744499922 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.746884108 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.746923923 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.747193098 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.749372959 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.749414921 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.749495029 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.751840115 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.751876116 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.751940966 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.754285097 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.754329920 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.754388094 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.756752968 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.756795883 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.756880999 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.759217024 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.759277105 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.759306908 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.761674881 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.761758089 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.761792898 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.764182091 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.764224052 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.764358044 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.766637087 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.766686916 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.766730070 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.769107103 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.769217014 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.905525923 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.905651093 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.905704021 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.906382084 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.906498909 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.906538963 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.908278942 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.908390999 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.908431053 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.910196066 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.910312891 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.910350084 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.912105083 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.912204981 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.912241936 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.914020061 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.914138079 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.914175034 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.915900946 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.916013002 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.916050911 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.917783022 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.917922974 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.917979956 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.919703960 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.919773102 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.919812918 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.921636105 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.921760082 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.921802044 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.923518896 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.923626900 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.923665047 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.925451040 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.925542116 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.925576925 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.927406073 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.927535057 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.927580118 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.929260015 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.929372072 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.929414988 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.931150913 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.931247950 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.931286097 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.933070898 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.933182955 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.933221102 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.934974909 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.935086966 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.935138941 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.936885118 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.936985016 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.937026024 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.938791037 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.938941956 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.938980103 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.940706015 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.940817118 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.940865993 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.942604065 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.942722082 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.942760944 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.944518089 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.944613934 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.944658041 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.946427107 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.946558952 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.946607113 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.948355913 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.948482990 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.948518991 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.950299978 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.950375080 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.950412035 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.952172995 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.952266932 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.952307940 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.954068899 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.954164028 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.954206944 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.956032991 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.956185102 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.956228971 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.957956076 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.958030939 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.958067894 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.959770918 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.959894896 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.959933996 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.961714983 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.961813927 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.961857080 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.963617086 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.963725090 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.963761091 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.965548992 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.965663910 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.965698957 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.967415094 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.967546940 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.967582941 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.969333887 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.969458103 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.969501972 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.971227884 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.971335888 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.971378088 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.973157883 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.973270893 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.973308086 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.975182056 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.975269079 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.975311041 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.977022886 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.977127075 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.977178097 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.978907108 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.978988886 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.979070902 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.981153965 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.981292963 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.981338978 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.982690096 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.982820034 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.982865095 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.984599113 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.984733105 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.984772921 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.986517906 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.986644030 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.986689091 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.988445044 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.988558054 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.988607883 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.990351915 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.990469933 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.990514994 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.992224932 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.992343903 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.992386103 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.994137049 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.994239092 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.994294882 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.996046066 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.996141911 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.996196985 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.997982025 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.998127937 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.998182058 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:37.999878883 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:37.999983072 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:38.000020981 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:38.001805067 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:38.001936913 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:38.001976013 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:38.003748894 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:38.003792048 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:38.003834963 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:38.005573988 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:38.005695105 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:38.005733967 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:38.007447958 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:38.052170992 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:38.106714010 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:38.106829882 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:38.106895924 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:38.107573986 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:38.107688904 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:38.107728958 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:38.109303951 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:38.115828037 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:38.116885900 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:38.235343933 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:38.236352921 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:38.236464977 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:38.259577990 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:38.379163027 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:39.789164066 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:39.833448887 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.099371910 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.183223963 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.218987942 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.303046942 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.303056955 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.303127050 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.303141117 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.303149939 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.303159952 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.303191900 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.303206921 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.303240061 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.303297043 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.303349018 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.307025909 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.307041883 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.307071924 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.307091951 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.307094097 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.307141066 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.422750950 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.422769070 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.422842026 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.422883987 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.422893047 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.422939062 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.422969103 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.423017979 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.423047066 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.423104048 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.423105955 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.423156023 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.423203945 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.423228979 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.423259974 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.423276901 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.426563978 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.426615953 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.426640987 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.426692009 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.426850080 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.426906109 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.470911026 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.471015930 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.542793989 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.542845964 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.543006897 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.543056965 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.543150902 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.543224096 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.543263912 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.543286085 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.543350935 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.543402910 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.543540955 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.543550968 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.543608904 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.543612003 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.543652058 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.543701887 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.543735981 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.543749094 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:40.543905973 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.543915033 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.543924093 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.543967962 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.546533108 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.546541929 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.546725988 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.546735048 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.546817064 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.546825886 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.546854973 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.546897888 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.546984911 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.546999931 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.547044039 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.547075987 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.590595961 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.590610981 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.662631989 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.662687063 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.662734032 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.662772894 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.662898064 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.662906885 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663009882 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663105965 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663115978 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663151026 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663275957 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663284063 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663420916 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663429022 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663521051 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663530111 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663537979 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663559914 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663685083 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663697004 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663711071 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663718939 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663800001 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663809061 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663872957 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663924932 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.663933039 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.664052963 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.664062023 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:40.664068937 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:41.202531099 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:41.322316885 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:42.196178913 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:42.271089077 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:42.315964937 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:42.390723944 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:42.823939085 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:42.864645958 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:42.916112900 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:43.035877943 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:43.196425915 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:43.316246986 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:44.212703943 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:44.332444906 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:44.332496881 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:44.332500935 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:44.332504988 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:44.332622051 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:44.332631111 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:45.205075979 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:45.325124025 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:45.325139999 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:45.972270966 CET6666497388.218.163.62192.168.2.4
Dec 26, 2024 23:10:45.972398043 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:45.972568035 CET497386666192.168.2.48.218.163.62
Dec 26, 2024 23:10:47.570955038 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:47.690732002 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:59.224153042 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:59.343803883 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:59.778162956 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:10:59.825803995 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:10:59.945444107 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:11:14.768781900 CET6666497318.218.163.62192.168.2.4
Dec 26, 2024 23:11:14.768851042 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:11:14.768944025 CET497316666192.168.2.48.218.163.62
Dec 26, 2024 23:11:16.724497080 CET497706666192.168.2.48.218.163.62
Dec 26, 2024 23:11:16.844276905 CET6666497708.218.163.62192.168.2.4
Dec 26, 2024 23:11:16.849633932 CET497706666192.168.2.48.218.163.62
Dec 26, 2024 23:11:19.499937057 CET6666497708.218.163.62192.168.2.4
Dec 26, 2024 23:11:19.500051022 CET497706666192.168.2.48.218.163.62
Dec 26, 2024 23:11:19.500180006 CET497706666192.168.2.48.218.163.62
Dec 26, 2024 23:11:32.992883921 CET498076666192.168.2.48.218.163.62
Dec 26, 2024 23:11:33.112572908 CET6666498078.218.163.62192.168.2.4
Dec 26, 2024 23:11:33.112651110 CET498076666192.168.2.48.218.163.62
Dec 26, 2024 23:11:35.735347986 CET6666498078.218.163.62192.168.2.4
Dec 26, 2024 23:11:35.735470057 CET498076666192.168.2.48.218.163.62
Dec 26, 2024 23:11:35.735579014 CET498076666192.168.2.48.218.163.62
Dec 26, 2024 23:11:49.240142107 CET498416666192.168.2.48.218.163.62
Dec 26, 2024 23:11:49.359649897 CET6666498418.218.163.62192.168.2.4
Dec 26, 2024 23:11:49.359731913 CET498416666192.168.2.48.218.163.62
Dec 26, 2024 23:11:51.990386009 CET6666498418.218.163.62192.168.2.4
Dec 26, 2024 23:11:51.990443945 CET498416666192.168.2.48.218.163.62
Dec 26, 2024 23:11:51.990520000 CET498416666192.168.2.48.218.163.62
Dec 26, 2024 23:12:05.427975893 CET498776666192.168.2.48.218.163.62
Dec 26, 2024 23:12:05.547660112 CET6666498778.218.163.62192.168.2.4
Dec 26, 2024 23:12:05.547882080 CET498776666192.168.2.48.218.163.62
Dec 26, 2024 23:12:08.178220987 CET6666498778.218.163.62192.168.2.4
Dec 26, 2024 23:12:08.178301096 CET498776666192.168.2.48.218.163.62
Dec 26, 2024 23:12:08.178390980 CET498776666192.168.2.48.218.163.62
Dec 26, 2024 23:12:21.709021091 CET499126666192.168.2.48.218.163.62
Dec 26, 2024 23:12:21.828618050 CET6666499128.218.163.62192.168.2.4
Dec 26, 2024 23:12:21.828824997 CET499126666192.168.2.48.218.163.62
Dec 26, 2024 23:12:24.486093998 CET6666499128.218.163.62192.168.2.4
Dec 26, 2024 23:12:24.486185074 CET499126666192.168.2.48.218.163.62
Dec 26, 2024 23:12:24.486258984 CET499126666192.168.2.48.218.163.62
Dec 26, 2024 23:12:38.162132025 CET499476666192.168.2.48.218.163.62
Dec 26, 2024 23:12:38.513231039 CET6666499478.218.163.62192.168.2.4
Dec 26, 2024 23:12:38.513338089 CET499476666192.168.2.48.218.163.62
Dec 26, 2024 23:12:41.168345928 CET6666499478.218.163.62192.168.2.4
Dec 26, 2024 23:12:41.172054052 CET499476666192.168.2.48.218.163.62
Dec 26, 2024 23:12:41.172204971 CET499476666192.168.2.48.218.163.62
Dec 26, 2024 23:12:54.834016085 CET499826666192.168.2.48.218.163.62
Dec 26, 2024 23:12:54.954426050 CET6666499828.218.163.62192.168.2.4
Dec 26, 2024 23:12:54.957822084 CET499826666192.168.2.48.218.163.62
Dec 26, 2024 23:12:57.607212067 CET6666499828.218.163.62192.168.2.4
Dec 26, 2024 23:12:57.607276917 CET499826666192.168.2.48.218.163.62
Dec 26, 2024 23:12:57.607433081 CET499826666192.168.2.48.218.163.62

Click to jump to process

Click to jump to process

Click to dive into process behavior distribution

Target ID:0
Start time:17:10:00
Start date:26/12/2024
Path:C:\Users\user\Desktop\EpCAySF1G6.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\EpCAySF1G6.exe"
Imagebase:0x7ff6b2fd0000
File size:133'632 bytes
MD5 hash:6C2F397589156433B18B4C931A684A25
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

Reset < >
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ByteCharMultiWidelstrlen$EventResetTimeconnectgethostbynamehtonssockettime
    • String ID: 0u
    • API String ID: 950253168-3203441087
    • Opcode ID: c39f5e32f51c546854f64cedb869f783fd802a92260de7296560489a3630704c
    • Instruction ID: ec4882751799e2c0c383b7b6b55624c8c334291d3863e3b1b8806a0e6b2c8991
    • Opcode Fuzzy Hash: c39f5e32f51c546854f64cedb869f783fd802a92260de7296560489a3630704c
    • Instruction Fuzzy Hash: 44814C72204B8887D765CF62F44039BB7A5F789B98F108119EB8A47B64CF3DD259CB04
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: System$Metrics$BlockInfoInputMessageParametersPostSleep$ObjectSingleWait
    • String ID:
    • API String ID: 4043121949-0
    • Opcode ID: 70942c266b939754ba25cbebb68d61ca88b0c9bf790e3a8ab3041b6dd57d2d26
    • Instruction ID: a6c19b3109f231f34a915171b8926a16e9bc877ec8146e86ed03d2c19bb4cb8b
    • Opcode Fuzzy Hash: 70942c266b939754ba25cbebb68d61ca88b0c9bf790e3a8ab3041b6dd57d2d26
    • Instruction Fuzzy Hash: 0F317E31A0064C83F7E69F34E8557A93762E759F95F148125FA1A026E5CF3DCA9CC701
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: _errno$recvselect
    • String ID:
    • API String ID: 4102763267-0
    • Opcode ID: 6e55d37ec909d9103437418c8740c1872d861fa96eb6d5ac6926f3a0f125cbe9
    • Instruction ID: 4ab95c07da45e580c7a1e664e6b10ca096951e97624ad3441197a06d63b559b9
    • Opcode Fuzzy Hash: 6e55d37ec909d9103437418c8740c1872d861fa96eb6d5ac6926f3a0f125cbe9
    • Instruction Fuzzy Hash: 9D3150B1218A8881EBB3DB66E4457EE73A5F78DBC8F448125EA5D47B95DF38C2088701
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Heap$CreateInformationVersion
    • String ID:
    • API String ID: 3563531100-0
    • Opcode ID: 94408129a73656f56999525ecae4c55ea10565afadc0b2f7b1ea26e19330658e
    • Instruction ID: 2047585caeb0d96450b74d4388bcfadda5036b37263dce35bce5ca53fe793822
    • Opcode Fuzzy Hash: 94408129a73656f56999525ecae4c55ea10565afadc0b2f7b1ea26e19330658e
    • Instruction Fuzzy Hash: 12E06D34211B9882FBC79B10B81979A2351F79D380F808415F94A03B54DF3CC35D8B00
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Virtual$AllocCurrentFreeThread
    • String ID:
    • API String ID: 1155560630-0
    • Opcode ID: 8b6e9cac55fcb94c4589c94077f4ba159caac3e0e6979146c6a5574917763282
    • Instruction ID: df7756c0319fa8f7c34d354fcb88f8a0a6f1099b4b6e46882ba731de937d8674
    • Opcode Fuzzy Hash: 8b6e9cac55fcb94c4589c94077f4ba159caac3e0e6979146c6a5574917763282
    • Instruction Fuzzy Hash: AB716B32314A849BE79ACB26E24179AB3A4F749BC4F50C115EB9A83754DF34E5B9CB00
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CreateErrorLastThread_errno_getptd_invalid_parameter_noinfofree
    • String ID:
    • API String ID: 3283625137-0
    • Opcode ID: dd8a0689508e11d5c57570d14ec8144f228c8fb4f8394bd5431a01ddf698605e
    • Instruction ID: 840def7598a3f49dface6fdfb57da55888d9872d4ea26a0761dfc1c2d03df44e
    • Opcode Fuzzy Hash: dd8a0689508e11d5c57570d14ec8144f228c8fb4f8394bd5431a01ddf698605e
    • Instruction Fuzzy Hash: DE21953120578886EA96EBA5B5407DEB394F748BE0F44C625BF69077D6CF38C659C700
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CreateObjectSingleSleepThreadWait_errno_invalid_parameter_noinfo
    • String ID: 8.218.163.62
    • API String ID: 3250838383-1363004327
    • Opcode ID: ee251b6672f538fce85ce1461ad2ae9822523f704c58887222570a03768aac97
    • Instruction ID: b1a993e78e5df7196a1f9103c4f3313f6e5f02e6875fe0577fbfca53cd9755b4
    • Opcode Fuzzy Hash: ee251b6672f538fce85ce1461ad2ae9822523f704c58887222570a03768aac97
    • Instruction Fuzzy Hash: 8E012135A0874882E752DF65B80039677A2F78D7D0F54C526FA5943BA4DF38C659C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CancelEventclosesocketsetsockopt
    • String ID:
    • API String ID: 852421847-0
    • Opcode ID: fb0b7b03ff0f7f82b9b9a198a3f5bea35088d74b0945c8c54248ee40735093d4
    • Instruction ID: c89a85dcc85f2820bd1d44f1685216a88981129d8207b33963c3667712326490
    • Opcode Fuzzy Hash: fb0b7b03ff0f7f82b9b9a198a3f5bea35088d74b0945c8c54248ee40735093d4
    • Instruction Fuzzy Hash: 95F03C36204B8883D7568F25F55839AB331F789BA4F104326DBA907AE4CF39D16ACB01
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: send
    • String ID:
    • API String ID: 2809346765-0
    • Opcode ID: eb3704afbb32cf80d8fc2292d74d73e20feec4cdc86b00731784d67511de0108
    • Instruction ID: 6b34267509c55f841139bed956c58f3dca68e6a39299f3758afa0e204980c870
    • Opcode Fuzzy Hash: eb3704afbb32cf80d8fc2292d74d73e20feec4cdc86b00731784d67511de0108
    • Instruction Fuzzy Hash: E3210A32704A8841E3A29B17B84679A7798F78CBD8F146121FF5993B91EFB4C5868300
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: SleepTimetime
    • String ID:
    • API String ID: 346578373-0
    • Opcode ID: 0778f1d0a279133f473acebe3396a217bab1a2d504ab5fe232e1993094d960a7
    • Instruction ID: 332856b26b82134b3ef7a07e2ed24c5cf692bcfec66c8bcfdeb8bde821065700
    • Opcode Fuzzy Hash: 0778f1d0a279133f473acebe3396a217bab1a2d504ab5fe232e1993094d960a7
    • Instruction Fuzzy Hash: 8701B13260474887E7A68B26E2883AD3361F348BC4F00D255F75A03AD0CF78C6A9C745
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ObjectSingleSleepWait
    • String ID:
    • API String ID: 309074506-0
    • Opcode ID: 973f945b5f5bd05faa339c84ed4b4d64e7dd1bb77631d768f487176a52932222
    • Instruction ID: d240cae8efa247cafc641eba02f268f3daaf734ce7d259a1098478c3c6c06a96
    • Opcode Fuzzy Hash: 973f945b5f5bd05faa339c84ed4b4d64e7dd1bb77631d768f487176a52932222
    • Instruction Fuzzy Hash: 8FF0B430A0028981F7A7DB35A4053E93751A75EBE4F088720F96A062E7CE2CC69D8B40
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Virtual$AllocFree
    • String ID:
    • API String ID: 2087232378-0
    • Opcode ID: 0bc9f78ae1633a0983af31e5b68c7c71bed81a00c7b6da28ef8ad6e13dba2874
    • Instruction ID: 72b7d3aad03fba2e165de2875db50fa41f8e49807fafbd3a688aa19225b51365
    • Opcode Fuzzy Hash: 0bc9f78ae1633a0983af31e5b68c7c71bed81a00c7b6da28ef8ad6e13dba2874
    • Instruction Fuzzy Hash: 3041C632704A888BD78ECE2AE8507DAB791F788BC9F04C529BE4A87758DF34C655C740
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Virtual$AllocFree
    • String ID:
    • API String ID: 2087232378-0
    • Opcode ID: e91e90dc211d4ac3dd2b8696ed2320e9465410aba3749ec224a793f89fd65685
    • Instruction ID: 39d2c09b0ad49af19ec391e2e33cc425ff618e5df754bb9e500cc7b052027a43
    • Opcode Fuzzy Hash: e91e90dc211d4ac3dd2b8696ed2320e9465410aba3749ec224a793f89fd65685
    • Instruction Fuzzy Hash: 11217132714A448BDB86CB2AE54038AB3A1F78CBC0F548521FA5993B58DF34D9E68B40
    APIs
      • Part of subcall function 000000018000BFD4: GetLastError.KERNEL32(?,?,?,000000018000999D,?,?,?,?,000000018003BFEA,?,?,?,?,000000018003BBF1), ref: 000000018000BFDE
      • Part of subcall function 000000018000BFD4: FlsGetValue.KERNEL32(?,?,?,000000018000999D,?,?,?,?,000000018003BFEA,?,?,?,?,000000018003BBF1), ref: 000000018000BFEC
      • Part of subcall function 000000018000BFD4: FlsSetValue.KERNEL32(?,?,?,000000018000999D,?,?,?,?,000000018003BFEA,?,?,?,?,000000018003BBF1), ref: 000000018000C018
      • Part of subcall function 000000018000BFD4: GetCurrentThreadId.KERNEL32 ref: 000000018000C02C
      • Part of subcall function 000000018000BFD4: SetLastError.KERNEL32(?,?,?,000000018000999D,?,?,?,?,000000018003BFEA,?,?,?,?,000000018003BBF1), ref: 000000018000C044
    • ExitThread.KERNEL32 ref: 0000000180009A38
      • Part of subcall function 000000018000C1B0: FlsGetValue.KERNEL32(?,?,?,0000000180009A36), ref: 000000018000C1C9
      • Part of subcall function 000000018000C1B0: FlsSetValue.KERNEL32(?,?,?,0000000180009A36), ref: 000000018000C1DA
      • Part of subcall function 000000018000C1B0: _freefls.LIBCMT ref: 000000018000C1E3
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Value$ErrorLastThread$CurrentExit_freefls
    • String ID:
    • API String ID: 1216290073-0
    • Opcode ID: 9ba43617d6060a859f6f529ed5b059fca6f098e0afadc2de5d5e5b81517bc422
    • Instruction ID: 7e2d9716788195060093211f914c8c74f8015c82e9622f0a3ead5c94187099e4
    • Opcode Fuzzy Hash: 9ba43617d6060a859f6f529ed5b059fca6f098e0afadc2de5d5e5b81517bc422
    • Instruction Fuzzy Hash: BFC04C7071230D52FEABB7B129567EA22551B5D780F049839790646383ED38CA5D4B81
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: DestroyHeap
    • String ID:
    • API String ID: 2435110975-0
    • Opcode ID: c76baf734cacc463f3edf7ce4c9f6505949cbacf67135dc3e5461fc18087faf8
    • Instruction ID: f40b699132607b01ac98de3414add4ed6839e3c976b6b0eec7b6fd1eca4493b3
    • Opcode Fuzzy Hash: c76baf734cacc463f3edf7ce4c9f6505949cbacf67135dc3e5461fc18087faf8
    • Instruction Fuzzy Hash: FEC04C75911B5885EA465701FC593551231735D786FD14501A15506220DF28536D4B04
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: __doserrno_errno_invalid_parameter_noinfo
    • String ID: U
    • API String ID: 3902385426-4171548499
    • Opcode ID: 78163aeb16f3b2ad721e63b0b1cc5a7f9fec38332dbcf66c90668829aeb81261
    • Instruction ID: d7937c02fd39bc783c8ca0f4a119cf2a7a79a18cfdc3a9c8ffef8114b50bd813
    • Opcode Fuzzy Hash: 78163aeb16f3b2ad721e63b0b1cc5a7f9fec38332dbcf66c90668829aeb81261
    • Instruction Fuzzy Hash: D812E23220468D86EBA2CF25E4443EA77A1F78D7C4F508126FA4A477A5DF79C64DCB10
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Pointer$AddressDecodeEncodeProc$LibraryLoad
    • String ID: GetActiveWindow$GetLastActivePopup$GetProcessWindowStation$GetUserObjectInformationW$MessageBoxW$USER32.DLL$ceil
    • API String ID: 2643518689-1731902841
    • Opcode ID: eef35e60d56da27d5e0b8f6531723091c283c3a98b3616d90fc0a75479ed4d59
    • Instruction ID: d3535494732f59449f14b0ffd64b58ac3c11d9095fcdc68b8c456ff81783e8f1
    • Opcode Fuzzy Hash: eef35e60d56da27d5e0b8f6531723091c283c3a98b3616d90fc0a75479ed4d59
    • Instruction Fuzzy Hash: 9551D435202B4D81FED7DB51BD143EA63A5AB8EBC4F19C526AC1E427A0EF38C6598310
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: write_multi_char$_errno_invalid_parameter_noinfowrite_char$_fileno_getptdfree
    • String ID: $@
    • API String ID: 1084558760-1077428164
    • Opcode ID: f97f1089f32f823f76d012dd0c8ab0c25e338b7442b712b783bf9d2dc336e878
    • Instruction ID: 2452bdb042314e0fe3febcab99f57ae4159cb2aa2937afe0bebb37c6ce2e0c15
    • Opcode Fuzzy Hash: f97f1089f32f823f76d012dd0c8ab0c25e338b7442b712b783bf9d2dc336e878
    • Instruction Fuzzy Hash: CC52C17260868886FBE6CB1594443EE7BA1B7897C4F14C016FA46C66E9DF79CB48CF01
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Desktop$Virtualkeybd_event$Thread$CapsCloseDeviceInformationInputObjectUser$BlockCurrentOpenlstrcmpimouse_event
    • String ID:
    • API String ID: 2279423893-0
    • Opcode ID: 69497c29c268d0f439f463573f78983a09bc20c3fced7f49a25841584d429e76
    • Instruction ID: 8537ef26d2cea1f88f4013564da5ad79e0ad6c78322d96bc04cbb05961646402
    • Opcode Fuzzy Hash: 69497c29c268d0f439f463573f78983a09bc20c3fced7f49a25841584d429e76
    • Instruction Fuzzy Hash: 2C51C631B04A8882E3DAC739A8447EA77A1FB6D7C4F54C211FA4A436A5DF3DDA59C700
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CreateEvent$CountCriticalInitializeSectionSpinTimetime
    • String ID: <$<
    • API String ID: 4111701721-213342407
    • Opcode ID: 05f9d6eeaa2301f8c5e41fb04d78acce11e74ccbb37d7a5d7c4285ec94b96cf4
    • Instruction ID: e02a7c7d02dad20fce2fd409f54c99c8a92b6f6ebfb2fc417219275c2c9e63df
    • Opcode Fuzzy Hash: 05f9d6eeaa2301f8c5e41fb04d78acce11e74ccbb37d7a5d7c4285ec94b96cf4
    • Instruction Fuzzy Hash: 4C816932201B9486E785DF30E8547DD37A9F748F88F18813AEE594B799CF788255CB50
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: File_set_error_mode$CurrentHandleModuleNameProcessWrite
    • String ID: ...$<program name unknown>$Microsoft Visual C++ Runtime Library$Runtime Error!Program: $ceil
    • API String ID: 2183313154-2708072404
    • Opcode ID: e803c1d3af5ecec9753290f83e9ab5e79e588cb5316708bd98aa3b48a103dd17
    • Instruction ID: af3c5ad1f1de3f023366cba7ce7246f7b398c9545f6d521bd91af1248e81a5c2
    • Opcode Fuzzy Hash: e803c1d3af5ecec9753290f83e9ab5e79e588cb5316708bd98aa3b48a103dd17
    • Instruction Fuzzy Hash: 9F51BE3131868882FAA6DB25A911BDA3391A78F7D0F54C116FE5903BC6DF38C709C701
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
    • String ID: ceil
    • API String ID: 1239891234-3069211559
    • Opcode ID: 547dbf1b02abe9440baa9f8f4ff2ca07c8d875fe4d7c9c04976ebe548166385e
    • Instruction ID: ad9169e07515aed976b9ba48c315529bc9b2c52a188ebb741d918b587164d0d0
    • Opcode Fuzzy Hash: 547dbf1b02abe9440baa9f8f4ff2ca07c8d875fe4d7c9c04976ebe548166385e
    • Instruction Fuzzy Hash: A7319032214B8886EBA1CF25E8407DF73A4F789794F514116FA9D43B95DF38C649CB00
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CountTick$CursorReleaseSleep
    • String ID:
    • API String ID: 1603040516-0
    • Opcode ID: 6a0133b0f874e709b43431347706ad5dec5376e7ac02394a3babd20454a655ee
    • Instruction ID: 65bcf487f87c86bc5952fa777737346912f80f57b0d51337cefdee1cc81c5337
    • Opcode Fuzzy Hash: 6a0133b0f874e709b43431347706ad5dec5376e7ac02394a3babd20454a655ee
    • Instruction Fuzzy Hash: EF416D326047889BD79ACF39E24079EB7B1F748790F008115EB8983A44DF38E5B9CB01
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ExceptionFilterProcessUnhandled$CaptureContextCurrentDebuggerEntryFunctionLookupPresentTerminateUnwindVirtual
    • String ID:
    • API String ID: 3778485334-0
    • Opcode ID: 3fe5d9be6abb456b153f2fd78e6a0890fc2cf96e21cb3a436cb3c3cbb8aa6692
    • Instruction ID: 92d4229850ceaceddd7c782502ba5022ea39dcecbc37d68dfe865f03005425cd
    • Opcode Fuzzy Hash: 3fe5d9be6abb456b153f2fd78e6a0890fc2cf96e21cb3a436cb3c3cbb8aa6692
    • Instruction Fuzzy Hash: 78311335508B4C86EB92AB15F8803DA73A1F78D3D0F618026FA9E477A5DF7DC2588700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ClipboardGlobal$AllocCloseDataEmptyFreeLockOpenUnlock
    • String ID:
    • API String ID: 453615576-0
    • Opcode ID: c324e4f9ed4764e5596ff27f5279ee80f8690d45007cef04fa72d5e1ed59cc9a
    • Instruction ID: b194addbfe9b26d0ab635f73133e22ed73d0d91d4edad7232035568f5b796e29
    • Opcode Fuzzy Hash: c324e4f9ed4764e5596ff27f5279ee80f8690d45007cef04fa72d5e1ed59cc9a
    • Instruction Fuzzy Hash: E301FF75704B4D82EA8A9B52B8583EA6351EB4DFC1F099036AD4B07755DF2CC65D8340
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ClipboardGlobal$AllocCloseDataEmptyFreeLockOpenUnlock
    • String ID:
    • API String ID: 453615576-0
    • Opcode ID: 375e20a99bf2319a86a66ff350dcc740ae14344422d4cbb28c6d44e50ed1fcbe
    • Instruction ID: 683c79a761524da91316f7a972f8740088dc3dce9a1cce0b7c72746da1918862
    • Opcode Fuzzy Hash: 375e20a99bf2319a86a66ff350dcc740ae14344422d4cbb28c6d44e50ed1fcbe
    • Instruction Fuzzy Hash: 8F118435714B4982EA9A9B12B8443AA6351FB4CFC0F099036FE4F07755DF3CC6998340
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ClipboardGlobal$CloseDataLockOpenSizeUnlock
    • String ID:
    • API String ID: 1964585863-0
    • Opcode ID: 5e27bf2a7382e610c6a91c43ad33970337c36fceabc1802507e96028b810b86a
    • Instruction ID: ba8cbadef7bf09348e7265ddccb45d7e132c969cb973bab97690c3bb7856a0fd
    • Opcode Fuzzy Hash: 5e27bf2a7382e610c6a91c43ad33970337c36fceabc1802507e96028b810b86a
    • Instruction Fuzzy Hash: C4213D32718A8882E7969B52F4583AA7360F78CFC5F189026FE4A07B56DF3DC659C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CurrentTime$CountCounterFilePerformanceProcessQuerySystemThreadTick
    • String ID:
    • API String ID: 1445889803-0
    • Opcode ID: 74ebcfaa1585adeb4553c2b651c04ae91b55a7832ce35f07ceca5609dd6a977e
    • Instruction ID: 64199a0b69e1a65d1df8218f42b8becb81c33f6c64bd41741b06a6c4f539d25f
    • Opcode Fuzzy Hash: 74ebcfaa1585adeb4553c2b651c04ae91b55a7832ce35f07ceca5609dd6a977e
    • Instruction Fuzzy Hash: A0015B31265B4C92E7C28F21F8443966361F74EBD0F55A522FE6A477A0DE38CA998300
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID:
    • String ID: [RO] %ld bytes
    • API String ID: 0-772938740
    • Opcode ID: 459f5504e9e704ec9cd6536985179fca075ed0b2fdb4cbfe3347bd892f916517
    • Instruction ID: ea451133cc71beb6ead4a8e2b9dcfa473d362eb5e7058315a1ebab0c0645d117
    • Opcode Fuzzy Hash: 459f5504e9e704ec9cd6536985179fca075ed0b2fdb4cbfe3347bd892f916517
    • Instruction Fuzzy Hash: CF528E732092C48FD36ACF29E44079EBBA0F369B48F448129EBC587B45DB78D959CB50
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CapsDevice$BlockInputVirtualkeybd_eventmouse_event
    • String ID:
    • API String ID: 1381131145-0
    • Opcode ID: cfbf087a84474e10d918829ffa8c6be962006b0e009a0cda664c11313fd55a8a
    • Instruction ID: 595ed494fcdefadc8ac681faddca1516c98c0760401290edadde9f4cea5416c8
    • Opcode Fuzzy Hash: cfbf087a84474e10d918829ffa8c6be962006b0e009a0cda664c11313fd55a8a
    • Instruction Fuzzy Hash: ABE06D66718984C2E2528B19B00138BA761F7987D5F245112EF8D43B68CE39C29ACB00
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 80290d1d8bad87e0592b8ef29a3c3ec20167a743bd2eff6d23ab07c448ac93f8
    • Instruction ID: 0325a7ae0354827c0e2fddb97fec9f8c092c603d59696671edbf51ea75ce31cc
    • Opcode Fuzzy Hash: 80290d1d8bad87e0592b8ef29a3c3ec20167a743bd2eff6d23ab07c448ac93f8
    • Instruction Fuzzy Hash: 06626F766017548BD7A68F26C0807AD37B1F34CFA9F269216EF4A43789CB34C995CB90
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: free$ErrorFreeHeapLast_errno
    • String ID:
    • API String ID: 1012874770-0
    • Opcode ID: 021b41133cd1ead1be3f60199342001b1f29ae534ddb99bc225400cd6796cf43
    • Instruction ID: be9f4a51adaeba7f25736ffa2ce7e74a650e6789f8973609459047087f1058fd
    • Opcode Fuzzy Hash: 021b41133cd1ead1be3f60199342001b1f29ae534ddb99bc225400cd6796cf43
    • Instruction Fuzzy Hash: BCA1543225255885EB86FFF1C8953ED3321ABC8F84F048132BB4D5B5A7CE12CA49C390
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Desktop$Create$CapsDeviceMetricsObjectSystem$CompatibleThread$CloseInformationReleaseSectionSelectUser$CountCurrentCursorInputLoadOpenTickWindowlstrcmpi
    • String ID: $U
    • API String ID: 2893566681-770038575
    • Opcode ID: b86f48dc643f242cefc531a4be5a3682f6d023113ff47b511178bb2e5ed44561
    • Instruction ID: 5a974b94c51b32a5b076b50a0235f2bb3082aa2d84b1aa1b7f751e748a0e9dcb
    • Opcode Fuzzy Hash: b86f48dc643f242cefc531a4be5a3682f6d023113ff47b511178bb2e5ed44561
    • Instruction Fuzzy Hash: D9912F32610B888ED396DF35E8443C937A5F74CB98F118226FA4993B58DF38D599CB40
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: free$_errno$EnvironmentVariable__wtomb_environ_invalid_parameter_noinfo
    • String ID: JPEGMEM
    • API String ID: 101574016-443077373
    • Opcode ID: baab3304b54c17fea864bf69aebbbcbc65c4dc0821fdc2b3a32c301d9a29cbd1
    • Instruction ID: 57832427582ab62e04a86cddfd81d4d0de5ccd9b3dcea064d25929bca40df8ea
    • Opcode Fuzzy Hash: baab3304b54c17fea864bf69aebbbcbc65c4dc0821fdc2b3a32c301d9a29cbd1
    • Instruction Fuzzy Hash: 7EA1B13230279881FAF7AB15A9003EB6391BB49BD8F1AC515BE5D477D6EF34C6498300
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ByteCharMultiWidelstrlensetsockopt$CreateEventIoctlgethostbynamesocket
    • String ID:
    • API String ID: 2536029566-0
    • Opcode ID: be85cae740309082365b1f24e25b9b4c6b74c0fabf9c05cb2245f7859b4bb23b
    • Instruction ID: b91bf29bcf1dd2fc12c05ac5a62fecd5c3412f371c6058c3f5659cdc7577f7ed
    • Opcode Fuzzy Hash: be85cae740309082365b1f24e25b9b4c6b74c0fabf9c05cb2245f7859b4bb23b
    • Instruction Fuzzy Hash: D7515F76214B4886E751CF65F84039AB7A5F788BE4F104216FE9A47BA8CF3CC259CB04
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: free$ErrorFreeHeapLast__free_lconv_mon__free_lconv_num_errno
    • String ID:
    • API String ID: 518839503-0
    • Opcode ID: 9f04c1d14f6d1e3e207a0491a1d211b8977080727f5d106970ebcecb83eb6337
    • Instruction ID: d1dd2f2dfdf9e00dee34c292536803119a0a1827377dc0545368fc7bc2e3df82
    • Opcode Fuzzy Hash: 9f04c1d14f6d1e3e207a0491a1d211b8977080727f5d106970ebcecb83eb6337
    • Instruction Fuzzy Hash: DF41FC36602688C4FFE6DFA1C4503F933A1EB8CBD4F188032BA194A795CF69C699D350
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CriticalErrorLastSection$EnterLeave
    • String ID:
    • API String ID: 2124651672-0
    • Opcode ID: 43feb2fd4a2469da3acbd97ccbcc7864171f01f7b687db1fcdc4d3f3b824b837
    • Instruction ID: f057f36e22cf24516504c3ef6b47dbec7fc18d1ede4cc798e6b081c25042d96d
    • Opcode Fuzzy Hash: 43feb2fd4a2469da3acbd97ccbcc7864171f01f7b687db1fcdc4d3f3b824b837
    • Instruction Fuzzy Hash: AF41613260424C87E796EF24E4587DF77A9FB4C7E1F059126EA1A832A1DF38D649C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CriticalSection$EnterErrorLastLeave
    • String ID:
    • API String ID: 4082018349-0
    • Opcode ID: 41b014c9e8fd6412a41d98cabfe8a4d72fe6ebac2a16b7390c8065aabf1d94b0
    • Instruction ID: 371efd4154eb484db3ea27ba105f86e393cf1da87a3e353abf91c6e69ccef9a9
    • Opcode Fuzzy Hash: 41b014c9e8fd6412a41d98cabfe8a4d72fe6ebac2a16b7390c8065aabf1d94b0
    • Instruction Fuzzy Hash: 20316330700A4D87F796EB16A8143AA7352F78EBE5F449122BE26477E5DF38C65D8300
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ByteCharMultiStringWide$_errnofreemalloc$AllocHeap_callnewh
    • String ID:
    • API String ID: 1080698880-0
    • Opcode ID: c6d857fe6f0f78d55d900201d5d5a589df3c7a53c660cb7af49781f728ee279f
    • Instruction ID: 52c0a84bf8a2e05631db068ac20ee0467e36e31dacc09e872cb42c16212d318a
    • Opcode Fuzzy Hash: c6d857fe6f0f78d55d900201d5d5a589df3c7a53c660cb7af49781f728ee279f
    • Instruction Fuzzy Hash: 8181D232300B8986EBA69F25A8403EA7395FB4DBE4F548225FA5D47BD4DF78C609C300
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: _errno$_invalid_parameter_noinfo$ByteCharErrorLastMultiWide
    • String ID:
    • API String ID: 2295021086-0
    • Opcode ID: c52785b3262bb0dfee42e3c25cdfc1a26fc2b908a9e576ce46cdcbb2cb4f113f
    • Instruction ID: d3279eee94bd3acad321d930761277f3f857973e89029d5b282bde406992e120
    • Opcode Fuzzy Hash: c52785b3262bb0dfee42e3c25cdfc1a26fc2b908a9e576ce46cdcbb2cb4f113f
    • Instruction Fuzzy Hash: FC518D326016888AFBF7DB65C4403FD76A0A748BE8F14C135BE5946FD6DF288B4A9701
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CountCriticalFileInfoInitializeSectionSleepSpinStartupType
    • String ID: @
    • API String ID: 3473179607-2766056989
    • Opcode ID: 146308c57673dcaa00c052c5a74b247c91614403510e9e44b48620217c0db704
    • Instruction ID: 2fbf92190b07b31d717272316cc8c3129a207059a927e50151699144c49d7e07
    • Opcode Fuzzy Hash: 146308c57673dcaa00c052c5a74b247c91614403510e9e44b48620217c0db704
    • Instruction Fuzzy Hash: 7B81607230078986EB96DF24D84479977A1E749BB8F58C325EA79433E1DF38C659C302
    APIs
    • _lock.LIBCMT ref: 000000018000A6A9
      • Part of subcall function 000000018000D41C: _amsg_exit.LIBCMT ref: 000000018000D446
    • DecodePointer.KERNEL32(?,?,00000000,?,?,ceil,00000000,000000018000A85D,?,?,00000000,000000018000D44B,?,?,00000000,000000018000BF75), ref: 000000018000A6DC
    • DecodePointer.KERNEL32(?,?,00000000,?,?,ceil,00000000,000000018000A85D,?,?,00000000,000000018000D44B,?,?,00000000,000000018000BF75), ref: 000000018000A6FA
    • DecodePointer.KERNEL32(?,?,00000000,?,?,ceil,00000000,000000018000A85D,?,?,00000000,000000018000D44B,?,?,00000000,000000018000BF75), ref: 000000018000A73A
    • DecodePointer.KERNEL32(?,?,00000000,?,?,ceil,00000000,000000018000A85D,?,?,00000000,000000018000D44B,?,?,00000000,000000018000BF75), ref: 000000018000A754
    • DecodePointer.KERNEL32(?,?,00000000,?,?,ceil,00000000,000000018000A85D,?,?,00000000,000000018000D44B,?,?,00000000,000000018000BF75), ref: 000000018000A764
    • ExitProcess.KERNEL32 ref: 000000018000A7F0
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: DecodePointer$ExitProcess_amsg_exit_lock
    • String ID: ceil
    • API String ID: 3411037476-3069211559
    • Opcode ID: e05cc1b73c426745f44764d451be97a631cba6024066b2eab7424b92b4bd2763
    • Instruction ID: 7ccfd90f358deb18b6c558725189fbc00dd08bcdc79013f2d31b745a0aaf9daa
    • Opcode Fuzzy Hash: e05cc1b73c426745f44764d451be97a631cba6024066b2eab7424b92b4bd2763
    • Instruction Fuzzy Hash: 1041597121AB4C81FAD3DB11FC4439AB2A5B78DBD4F14C126BA8D437A5EF38C6598701
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CriticalSection$Leave$ErrorLastTimetime$EnterEvent
    • String ID:
    • API String ID: 3019579578-0
    • Opcode ID: 6c6187700454bc4c59a4335baf926a9c00d97f8409c49833492fe45c45125409
    • Instruction ID: b2dda1a618636ee271e064bde461f634b13a8de8d6a379aa51d70fdee50eeccf
    • Opcode Fuzzy Hash: 6c6187700454bc4c59a4335baf926a9c00d97f8409c49833492fe45c45125409
    • Instruction Fuzzy Hash: 4B4164325046488BE7B2DB11E4503AEB3A2F79C794F048116EB8A43BA4DF7CE799C740
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CriticalSection$EnterErrorLastLeave
    • String ID:
    • API String ID: 4082018349-0
    • Opcode ID: 509216e4530071335b692588b47e4367fec6eb90552f125319ab030dc0d1f72b
    • Instruction ID: 75e3335b1e87918230f6a9c373441254f2ba43e3bbdc08f9cd9113b1b29240e6
    • Opcode Fuzzy Hash: 509216e4530071335b692588b47e4367fec6eb90552f125319ab030dc0d1f72b
    • Instruction Fuzzy Hash: A9318F32A10949D7E792CF24E4543DD37A5FB48F88F558121EA16872B5DF39CA9EC700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Desktop$Thread$CloseInformationObjectUser$CurrentInputOpenlstrcmpi
    • String ID:
    • API String ID: 3718465862-0
    • Opcode ID: fd2f48d1e6d1968eaee02ee160a19b2c28ca0775cb4ff9dc85cc901e1692a986
    • Instruction ID: 96f2aa2bc74b01c33155bad7b66987432dd12a3f0d009d3960013aa5692eb5d5
    • Opcode Fuzzy Hash: fd2f48d1e6d1968eaee02ee160a19b2c28ca0775cb4ff9dc85cc901e1692a986
    • Instruction Fuzzy Hash: FE214F31314B8992FA61DB22F4597DA6360F78DBC4F458022EA9A47755DF3CC60AC740
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: DataRegion$CreateDeleteIndirectObjectRect
    • String ID: gfff
    • API String ID: 2186813130-1553575800
    • Opcode ID: 210b1052776d665a791326807686c54679e9d2d37cfd61b82ee3dbe07363b580
    • Instruction ID: bc2ed40e1d0f4b74609d4687d17f06db3ad57190d21ec97fb4438f9dc19cd448
    • Opcode Fuzzy Hash: 210b1052776d665a791326807686c54679e9d2d37cfd61b82ee3dbe07363b580
    • Instruction Fuzzy Hash: 0A518F767056488BE769CB26B95479A77A1FB4CBC4F004125EB8B83750EF38D64ADB00
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Object$CreateDeleteSectionSelectfree
    • String ID:
    • API String ID: 2595996717-3916222277
    • Opcode ID: f6782e0ec75eb355608d6baa56bdc04460804f101ee914dbec3cc0b645ff9191
    • Instruction ID: 5b4268221a54ee5ace4949b13ecdcb8b86921d6e4c027daeeaf1fedb3c418b76
    • Opcode Fuzzy Hash: f6782e0ec75eb355608d6baa56bdc04460804f101ee914dbec3cc0b645ff9191
    • Instruction Fuzzy Hash: 1D510876604B848BC769DF2AE48475EB7A5F788B90F15811AEBCE83714DF38E545CB00
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CriticalSection$EnterLeave$FreeHeap$ErrorLastsend
    • String ID:
    • API String ID: 1701177279-0
    • Opcode ID: 5e93c71d42a5c305066e613e53868e62f4b53e08804066344f535b4be8cad9c5
    • Instruction ID: a620b2b09fab4021b60d4499ff936709b967cc0508b128f9f8bfd0d5c675bc9b
    • Opcode Fuzzy Hash: 5e93c71d42a5c305066e613e53868e62f4b53e08804066344f535b4be8cad9c5
    • Instruction Fuzzy Hash: 24515072201A889AE7E6CF26E4547DD37A0F748BD4F408125EB0A4BF94DF38D6A9C744
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Event$CloseCurrentSleepThreadTimeclosesocketsendshutdowntime
    • String ID:
    • API String ID: 929257074-0
    • Opcode ID: 9d61f2e2c9447a3d8bcb9984658d70241f89799c3ed2799b6cf06c82dabcd3d5
    • Instruction ID: dda0e94db9e172848c5fc71e5c628d20ec21edfcea274629e6847fb904bf0f32
    • Opcode Fuzzy Hash: 9d61f2e2c9447a3d8bcb9984658d70241f89799c3ed2799b6cf06c82dabcd3d5
    • Instruction Fuzzy Hash: 34317532510A5887E792DF25E85039E3362F78CFEAF158226FA96476D8CF34C989C740
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Event$HeapReset$CreateCriticalDestroyEnterFreeSection
    • String ID:
    • API String ID: 1658878062-0
    • Opcode ID: 5fe672df45f1e2bbed79aef643380a6c9a2424feeacc98cb5f0f77531cfcc87f
    • Instruction ID: 9703f8dc8471dfc0476053e93f52503ebf4fed76f355431aaf0e94b4b4928632
    • Opcode Fuzzy Hash: 5fe672df45f1e2bbed79aef643380a6c9a2424feeacc98cb5f0f77531cfcc87f
    • Instruction Fuzzy Hash: 2931D476211B89E3E68EDB21E6843EDB364F788BC1F418126EB6943651CF34D6B9C740
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Message$Peek$CloseDispatchErrorEventHandleLastMultipleObjectsTranslateWait
    • String ID:
    • API String ID: 1713936993-0
    • Opcode ID: 6dee3109de8a5924e932cc8fd2037b2e751a14fc2ff686e065d7e26951ee4ef5
    • Instruction ID: 332fe93a0e92dbbaa167667d86b0f1f0310324c209a84aaee6c2a70f1db9f668
    • Opcode Fuzzy Hash: 6dee3109de8a5924e932cc8fd2037b2e751a14fc2ff686e065d7e26951ee4ef5
    • Instruction Fuzzy Hash: 5921713221064C82F7A2CF34E4587AF33A1FB88B85F549115FA99865A4DF38CA4DCB41
    APIs
    • _FF_MSGBANNER.LIBCMT ref: 000000018000D35B
      • Part of subcall function 000000018000AAEC: _set_error_mode.LIBCMT ref: 000000018000AAF5
      • Part of subcall function 000000018000AAEC: _set_error_mode.LIBCMT ref: 000000018000AB04
      • Part of subcall function 000000018000A88C: _set_error_mode.LIBCMT ref: 000000018000A8D1
      • Part of subcall function 000000018000A88C: _set_error_mode.LIBCMT ref: 000000018000A8E2
      • Part of subcall function 000000018000A88C: GetModuleFileNameW.KERNEL32 ref: 000000018000A944
      • Part of subcall function 000000018000A4EC: ExitProcess.KERNEL32 ref: 000000018000A4FB
      • Part of subcall function 000000018000C658: malloc.LIBCMT ref: 000000018000C683
      • Part of subcall function 000000018000C658: Sleep.KERNEL32(?,?,ceil,000000018000D395,?,?,?,000000018000D43F,?,?,00000000,000000018000BF75,?,?,00000000,000000018000C02C), ref: 000000018000C696
    • _errno.LIBCMT ref: 000000018000D39D
    • _lock.LIBCMT ref: 000000018000D3B1
    • InitializeCriticalSectionAndSpinCount.KERNEL32(?,?,?,000000018000D43F,?,?,00000000,000000018000BF75,?,?,00000000,000000018000C02C,?,?,?,000000018000999D), ref: 000000018000D3C7
    • free.LIBCMT ref: 000000018000D3D4
    • _errno.LIBCMT ref: 000000018000D3D9
    • LeaveCriticalSection.KERNEL32(?,?,?,000000018000D43F,?,?,00000000,000000018000BF75,?,?,00000000,000000018000C02C,?,?,?,000000018000999D), ref: 000000018000D3FC
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: _set_error_mode$CriticalSection_errno$CountExitFileInitializeLeaveModuleNameProcessSleepSpin_lockfreemalloc
    • String ID:
    • API String ID: 113790786-0
    • Opcode ID: 5340cad30271600366c56f56e91e848f64c22deddf261063ff2b6cbe4c9027cc
    • Instruction ID: 6f0eb30842c2824cc797e0ece3ec5bb34fb6c6b379f0403c7b3753d2049b81df
    • Opcode Fuzzy Hash: 5340cad30271600366c56f56e91e848f64c22deddf261063ff2b6cbe4c9027cc
    • Instruction Fuzzy Hash: D021473160568C82F6E7EB51A8447EE7365E7897C0F14D02ABA4A476C2CF38CB488362
    APIs
    • free.LIBCMT ref: 00000001800025A6
    • malloc.LIBCMT ref: 000000018000268D
      • Part of subcall function 0000000180009680: _FF_MSGBANNER.LIBCMT ref: 00000001800096B0
      • Part of subcall function 0000000180009680: HeapAlloc.KERNEL32(?,?,DEDE000000000000,000000018000C688,?,?,ceil,000000018000D395,?,?,?,000000018000D43F,?,?,00000000,000000018000BF75), ref: 00000001800096D5
      • Part of subcall function 0000000180009680: _callnewh.LIBCMT ref: 00000001800096EE
      • Part of subcall function 0000000180009680: _errno.LIBCMT ref: 00000001800096F9
      • Part of subcall function 0000000180009680: _errno.LIBCMT ref: 0000000180009704
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: _errno$AllocHeap_callnewhfreemalloc
    • String ID: [RI] %d bytes$input ack: sn=%lu rtt=%ld rto=%ld$input probe$input psh: sn=%lu ts=%lu$input wins: %lu
    • API String ID: 3198430600-868042568
    • Opcode ID: 12c99ae6bd755bc9ede84d896a78c2a432a3bf2c2e8d12f57f17d4c0ca2fb6bd
    • Instruction ID: 2c4445fc99983dac253dd3de491b6a48f7bcfb93e97130a427c286ea37865d3c
    • Opcode Fuzzy Hash: 12c99ae6bd755bc9ede84d896a78c2a432a3bf2c2e8d12f57f17d4c0ca2fb6bd
    • Instruction Fuzzy Hash: 5BE1C5726046948BE7B6CF29E85079E7BA1F3887C5F14C011EB9A43B85DF39DA49CB00
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ErrorLast$CurrentThread$EventsMultipleTimerWaitWaitable
    • String ID:
    • API String ID: 3058130114-0
    • Opcode ID: 79bd9b8558d3ad670daa0f2e62ec406135a76d13d5f71c22e12494678d746fea
    • Instruction ID: 25f4813ffb8264326a26a1ec3c0e5394230e4d6e90a2f7fda1d4210e42b14ad8
    • Opcode Fuzzy Hash: 79bd9b8558d3ad670daa0f2e62ec406135a76d13d5f71c22e12494678d746fea
    • Instruction Fuzzy Hash: 41617072200B8886EBE6DF2598543D933A4F749BD8F148225FE1A8B7D5EF35C6488305
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ErrorLast$setsockopt$CreateCurrentEventResetThreadTimerWaitablefreemalloc
    • String ID:
    • API String ID: 3356772049-0
    • Opcode ID: 385d7910e8cc1218ff50aec6a7d4baed77c702b4280e88e07e440001cc7534b2
    • Instruction ID: 695c8c4979a995818427334fd6355189642c83d14db7d618803583136ccf0baf
    • Opcode Fuzzy Hash: 385d7910e8cc1218ff50aec6a7d4baed77c702b4280e88e07e440001cc7534b2
    • Instruction Fuzzy Hash: A7419172600B4887E792CF16E50439E73A0F748788F108025FB8947B91CF7ED269CB04
    APIs
      • Part of subcall function 000000018000A438: HeapCreate.KERNEL32 ref: 000000018000A44E
      • Part of subcall function 000000018000A438: GetVersion.KERNEL32 ref: 000000018000A460
      • Part of subcall function 000000018000A438: HeapSetInformation.KERNEL32 ref: 000000018000A47E
    • _RTC_Initialize.LIBCMT ref: 0000000180009D82
    • GetCommandLineA.KERNEL32 ref: 0000000180009D87
      • Part of subcall function 000000018000CFF0: GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,0000000180009D99), ref: 000000018000D009
      • Part of subcall function 000000018000CFF0: WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,0000000180009D99), ref: 000000018000D060
      • Part of subcall function 000000018000CFF0: WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,0000000180009D99), ref: 000000018000D09B
      • Part of subcall function 000000018000CFF0: free.LIBCMT ref: 000000018000D0A8
      • Part of subcall function 000000018000CFF0: FreeEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,0000000180009D99), ref: 000000018000D0B3
      • Part of subcall function 000000018000C8B0: GetStartupInfoW.KERNEL32 ref: 000000018000C8D1
    • __setargv.LIBCMT ref: 0000000180009DB0
    • _cinit.LIBCMT ref: 0000000180009DC4
      • Part of subcall function 000000018000BEF4: FlsFree.KERNEL32(?,?,?,?,0000000180009E2E), ref: 000000018000BF03
      • Part of subcall function 000000018000BEF4: DeleteCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,0000000180009E2E), ref: 000000018000D2C7
      • Part of subcall function 000000018000BEF4: free.LIBCMT ref: 000000018000D2D0
      • Part of subcall function 000000018000BEF4: DeleteCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,0000000180009E2E), ref: 000000018000D2F7
      • Part of subcall function 000000018000C6D8: Sleep.KERNEL32(?,?,ceil,000000018000C007,?,?,?,000000018000999D,?,?,?,?,000000018003BFEA), ref: 000000018000C71D
    • FlsSetValue.KERNEL32 ref: 0000000180009E5E
    • GetCurrentThreadId.KERNEL32 ref: 0000000180009E72
    • free.LIBCMT ref: 0000000180009E81
      • Part of subcall function 0000000180009640: RtlFreeHeap.NTDLL(?,?,00000000,000000018000C040,?,?,?,000000018000999D,?,?,?,?,000000018003BFEA), ref: 0000000180009656
      • Part of subcall function 0000000180009640: _errno.LIBCMT ref: 0000000180009660
      • Part of subcall function 0000000180009640: GetLastError.KERNEL32(?,?,00000000,000000018000C040,?,?,?,000000018000999D,?,?,?,?,000000018003BFEA), ref: 0000000180009668
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: free$FreeHeap$ByteCharCriticalDeleteEnvironmentMultiSectionStringsWide$CommandCreateCurrentErrorInfoInformationInitializeLastLineSleepStartupThreadValueVersion__setargv_cinit_errno
    • String ID:
    • API String ID: 125979975-0
    • Opcode ID: 2dc076293398fcd7fe5081731f78aa6e849789c0d8a445cc61a0c5aec1a05bee
    • Instruction ID: fe4a1015b7d026f5d258e19d2ee1d233b5ab80a77d8628e2f8495522dc74437f
    • Opcode Fuzzy Hash: 2dc076293398fcd7fe5081731f78aa6e849789c0d8a445cc61a0c5aec1a05bee
    • Instruction Fuzzy Hash: 9431703060664E81FAE7F7F199013EE3195AB9D3D4F24C12AB921851C7EF298B4D4363
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: MetricsSystem$CapsDevice$Release$CountCreateCursorDesktopEventLoadTickWindowmalloc
    • String ID:
    • API String ID: 423607222-3916222277
    • Opcode ID: 4b28c52f20ffdf5a9381539c9fc0a716757e8578ec4c97d0e64d7f9e2a4cfef5
    • Instruction ID: c6fb0172dea399f9ccb69aaaa1339b32bad750d857247de1dd8db271205325a6
    • Opcode Fuzzy Hash: 4b28c52f20ffdf5a9381539c9fc0a716757e8578ec4c97d0e64d7f9e2a4cfef5
    • Instruction Fuzzy Hash: 42319F72100B4486E796CF35E4443CA77E5FB4CB98F10822AEA4D477A9DF79C258C740
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: __doserrno_errno
    • String ID:
    • API String ID: 921712934-0
    • Opcode ID: 3ce7682d629f21e628ed1582799be254755e637483a93035ce180d5811f39bea
    • Instruction ID: c411a6d4b71dfe7a62226b1d763e97ff5680ec92d5c3d0ce38a709bc0164baa9
    • Opcode Fuzzy Hash: 3ce7682d629f21e628ed1582799be254755e637483a93035ce180d5811f39bea
    • Instruction Fuzzy Hash: 0121B03221064C85EA97EB5999413FD76516788BF1F4A820ABE34073E3DF7886498721
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: __doserrno_errno
    • String ID:
    • API String ID: 921712934-0
    • Opcode ID: 219b57bc18c8537710296174296c9a777b41f9f22e72160e046d0417abce71e1
    • Instruction ID: 208e345af04c41b1c6889ad1f81cdd3c543414e6f2b63189b4a0446d3012c127
    • Opcode Fuzzy Hash: 219b57bc18c8537710296174296c9a777b41f9f22e72160e046d0417abce71e1
    • Instruction Fuzzy Hash: FF21013221068845F797EB69A8413FD3A11A7897E1F49C118FA24073E3CFB886899720
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: _errno$BuffersErrorFileFlushLast__doserrno
    • String ID:
    • API String ID: 1845094721-0
    • Opcode ID: 65d40c243bdbd2d8c40f04e9232bb7ffd2095a59ea85331859790807e3c7c2bb
    • Instruction ID: 443c4df203018a09317fca6b1f576f251987f8ae4d4f93c0a6d464d5531fe614
    • Opcode Fuzzy Hash: 65d40c243bdbd2d8c40f04e9232bb7ffd2095a59ea85331859790807e3c7c2bb
    • Instruction Fuzzy Hash: 8121C631300A4C45F797AFA8B9813FD3751A74D7D0F298128BA560B3E2DFB89649C301
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: __doserrno_close_nolock_errno
    • String ID:
    • API String ID: 186997739-0
    • Opcode ID: 25288049dd324bc4337847358e2c5e3441b6c920b1bebd3c2c4621ae3f576b75
    • Instruction ID: 43e174b3b8f34985c6bd657e4b35ac7fd052195ae9cb6f3272742aa463ed8682
    • Opcode Fuzzy Hash: 25288049dd324bc4337847358e2c5e3441b6c920b1bebd3c2c4621ae3f576b75
    • Instruction Fuzzy Hash: 60110A32A0468C49F39BAF6498413EC3651578C7E1F55C528B529073D3CFF88689C310
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: _errno$write_char
    • String ID:
    • API String ID: 1772936973-0
    • Opcode ID: 59595e8c2d60516688eb06fa007e0346238e38a8beb115a9248a300fee8233ca
    • Instruction ID: a675aab5ad95e2bbcca2c7ec28b259220c6970b63d32f20c08e1c2afe2d83584
    • Opcode Fuzzy Hash: 59595e8c2d60516688eb06fa007e0346238e38a8beb115a9248a300fee8233ca
    • Instruction Fuzzy Hash: D1113D3250079886E7A39B5A94013ED77A0F79DBD0F68D024FB544B796CF38DA858B41
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Delete$Object$CursorDestroyRelease
    • String ID:
    • API String ID: 1665608007-0
    • Opcode ID: b0ca0f8ae1253b7dc544d5714d81f1b2868fd1a7ecfc3c098af9debe0b337dff
    • Instruction ID: 359be030e64ea643b08230aa0655e70d7668aea15539991674f6677d56f8235d
    • Opcode Fuzzy Hash: b0ca0f8ae1253b7dc544d5714d81f1b2868fd1a7ecfc3c098af9debe0b337dff
    • Instruction Fuzzy Hash: 1311E936605A4895EB86EF65F8903E93361FB88FC5F558032EE8E46265CE28CA5DC350
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Virtual$AllocCurrentFreeThread
    • String ID:
    • API String ID: 1155560630-0
    • Opcode ID: 742b0adb832181635398d9b2203ec9d917de59162bfa4663d63228d996a146c5
    • Instruction ID: 9b0cc06c8a2fc3553dae8b8c4d95b0b666bb54d2c98ffac3feb2bae3b8b6bb9e
    • Opcode Fuzzy Hash: 742b0adb832181635398d9b2203ec9d917de59162bfa4663d63228d996a146c5
    • Instruction Fuzzy Hash: 97716A32314B8497E79ECB25E24479EB3A4F748BC1F508115FB9987654DF34E6A9CB00
    APIs
    • _getptd.LIBCMT ref: 000000018000ED8F
      • Part of subcall function 000000018000C058: _amsg_exit.LIBCMT ref: 000000018000C06E
      • Part of subcall function 000000018000E9AC: _getptd.LIBCMT ref: 000000018000E9B6
      • Part of subcall function 000000018000E9AC: _amsg_exit.LIBCMT ref: 000000018000EA53
      • Part of subcall function 000000018000EA68: GetOEMCP.KERNEL32(?,?,?,?,?,?,?,000000018000EDAA,?,?,?,?,?,000000018000EF67), ref: 000000018000EA92
      • Part of subcall function 000000018000C658: malloc.LIBCMT ref: 000000018000C683
      • Part of subcall function 000000018000C658: Sleep.KERNEL32(?,?,ceil,000000018000D395,?,?,?,000000018000D43F,?,?,00000000,000000018000BF75,?,?,00000000,000000018000C02C), ref: 000000018000C696
    • free.LIBCMT ref: 000000018000EE1A
      • Part of subcall function 0000000180009640: RtlFreeHeap.NTDLL(?,?,00000000,000000018000C040,?,?,?,000000018000999D,?,?,?,?,000000018003BFEA), ref: 0000000180009656
      • Part of subcall function 0000000180009640: _errno.LIBCMT ref: 0000000180009660
      • Part of subcall function 0000000180009640: GetLastError.KERNEL32(?,?,00000000,000000018000C040,?,?,?,000000018000999D,?,?,?,?,000000018003BFEA), ref: 0000000180009668
    • _lock.LIBCMT ref: 000000018000EE4A
    • free.LIBCMT ref: 000000018000EEED
    • free.LIBCMT ref: 000000018000EF19
    • _errno.LIBCMT ref: 000000018000EF1E
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: free$_amsg_exit_errno_getptd$ErrorFreeHeapLastSleep_lockmalloc
    • String ID:
    • API String ID: 3894533514-0
    • Opcode ID: d0407b1aac2213962a0f91f087d9c3433d8333d46dfff0cda28676efbf43b31c
    • Instruction ID: 8855c7a5f5d7c36327045c9948b09f230b9737fbd2f617063f3c55710e8465d9
    • Opcode Fuzzy Hash: d0407b1aac2213962a0f91f087d9c3433d8333d46dfff0cda28676efbf43b31c
    • Instruction Fuzzy Hash: 9651C1322006C886E7D6DB21D8403E977A1F78EBD4F14C126FA5A57396CF38C649C701
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: _errno_invalid_parameter_noinfo$_fileno_ftbuf
    • String ID:
    • API String ID: 2434734397-0
    • Opcode ID: 6db1d4df1e3ebed4864d0548da5bce2e2edce094884e200ce3494b53dfa676cf
    • Instruction ID: f5b71796390f9364027b54fca3220aebf077891c2c4cf0c7b84bc7359f2ee352
    • Opcode Fuzzy Hash: 6db1d4df1e3ebed4864d0548da5bce2e2edce094884e200ce3494b53dfa676cf
    • Instruction Fuzzy Hash: 9631E87170174D45FAD7D7695C923FE23916B59BE0FA1D229FD29862D1CF28C64D8300
    APIs
    • malloc.LIBCMT ref: 00000001800017F5
    • malloc.LIBCMT ref: 0000000180001861
      • Part of subcall function 0000000180009680: _FF_MSGBANNER.LIBCMT ref: 00000001800096B0
      • Part of subcall function 0000000180009680: HeapAlloc.KERNEL32(?,?,DEDE000000000000,000000018000C688,?,?,ceil,000000018000D395,?,?,?,000000018000D43F,?,?,00000000,000000018000BF75), ref: 00000001800096D5
      • Part of subcall function 0000000180009680: _callnewh.LIBCMT ref: 00000001800096EE
      • Part of subcall function 0000000180009680: _errno.LIBCMT ref: 00000001800096F9
      • Part of subcall function 0000000180009680: _errno.LIBCMT ref: 0000000180009704
    • free.LIBCMT ref: 000000018000188A
      • Part of subcall function 0000000180009640: RtlFreeHeap.NTDLL(?,?,00000000,000000018000C040,?,?,?,000000018000999D,?,?,?,?,000000018003BFEA), ref: 0000000180009656
      • Part of subcall function 0000000180009640: _errno.LIBCMT ref: 0000000180009660
      • Part of subcall function 0000000180009640: GetLastError.KERNEL32(?,?,00000000,000000018000C040,?,?,?,000000018000999D,?,?,?,?,000000018003BFEA), ref: 0000000180009668
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: _errno$Heapmalloc$AllocErrorFreeLast_callnewhfree
    • String ID: d$d$d
    • API String ID: 161857241-1898527202
    • Opcode ID: de9c947b52f5cced65e5fb739daeeab5d91237964ee81a3d91c2b650cd86eca5
    • Instruction ID: 26baca00d8837cea124759d0b50b5e6c371a394a4fe92fdb92bc423769365a07
    • Opcode Fuzzy Hash: de9c947b52f5cced65e5fb739daeeab5d91237964ee81a3d91c2b650cd86eca5
    • Instruction Fuzzy Hash: 5041E472112B94C9E781CF25E4403993BA9F748F88F59C13AEB8847798EF75C558CB60
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: EnvironmentStrings$ByteCharFreeMultiWide$free
    • String ID:
    • API String ID: 517548149-0
    • Opcode ID: 135297dcab80fc6b00751f3c01c8083bc8f0bde01277529d9eb1e37cdddd8d3d
    • Instruction ID: 10efca17ea9078b3eb5f2cd84dac7c3252626ee7f6f8a3ef5586864f9dde1f99
    • Opcode Fuzzy Hash: 135297dcab80fc6b00751f3c01c8083bc8f0bde01277529d9eb1e37cdddd8d3d
    • Instruction Fuzzy Hash: 8B21813260578886EBA6CF22B45079A77E5F78CBC0F488016EE8E07B58DF39C655C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: EventReset$CurrentObjectSingleThreadTimeWait_errno_invalid_parameter_noinfotime
    • String ID:
    • API String ID: 2543248268-0
    • Opcode ID: 1e8666e7e51f2ff4dd7147b107d66f999c8e4a748aa071a7d8a9cb6ed039a13f
    • Instruction ID: 843b933302644989679a588d04cb5c6b417eadd3ac19e309017223f44c84dac6
    • Opcode Fuzzy Hash: 1e8666e7e51f2ff4dd7147b107d66f999c8e4a748aa071a7d8a9cb6ed039a13f
    • Instruction Fuzzy Hash: 55214C36204B5486D782CF21F84039A73A4F788F99F198122EE8D87768DF34C68A8700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: EventThread$CloseCurrentErrorLastSwitchclosesocketsendshutdown
    • String ID:
    • API String ID: 779811758-0
    • Opcode ID: 1e86ea1f8ff452546b779ee4e855d81d8d01c69a684822cfa20fc278bfcbf352
    • Instruction ID: b5ea4ee48596f9abde93df30d7473071f8ae0aa078d83123165f73c6978b95ef
    • Opcode Fuzzy Hash: 1e86ea1f8ff452546b779ee4e855d81d8d01c69a684822cfa20fc278bfcbf352
    • Instruction Fuzzy Hash: 0121337260064986EB96DF29F4403993361F78CFE4F558222AA2A4B6D5DF34C989C744
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CloseHandleObjectSingleWait$CursorDestroyRelease
    • String ID:
    • API String ID: 1831285251-0
    • Opcode ID: 95848810752ff7ad233cd3893918d47de91eb8e101ab5f5df24dde70a11c90f1
    • Instruction ID: acc23cfdb0e0807efd00d533c1861ebf9783fd11ccc118f83a28eb62b8736fb9
    • Opcode Fuzzy Hash: 95848810752ff7ad233cd3893918d47de91eb8e101ab5f5df24dde70a11c90f1
    • Instruction Fuzzy Hash: E6212A32600F4896DB56DF29E8843897370F788BA0F548226EB6E437B4DF39D569C700
    APIs
    • GetLastError.KERNEL32(?,?,?,000000018000999D,?,?,?,?,000000018003BFEA,?,?,?,?,000000018003BBF1), ref: 000000018000BFDE
    • FlsGetValue.KERNEL32(?,?,?,000000018000999D,?,?,?,?,000000018003BFEA,?,?,?,?,000000018003BBF1), ref: 000000018000BFEC
    • SetLastError.KERNEL32(?,?,?,000000018000999D,?,?,?,?,000000018003BFEA,?,?,?,?,000000018003BBF1), ref: 000000018000C044
      • Part of subcall function 000000018000C6D8: Sleep.KERNEL32(?,?,ceil,000000018000C007,?,?,?,000000018000999D,?,?,?,?,000000018003BFEA), ref: 000000018000C71D
    • FlsSetValue.KERNEL32(?,?,?,000000018000999D,?,?,?,?,000000018003BFEA,?,?,?,?,000000018003BBF1), ref: 000000018000C018
    • free.LIBCMT ref: 000000018000C03B
    • GetCurrentThreadId.KERNEL32 ref: 000000018000C02C
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ErrorLastValue_lock$CurrentSleepThreadfree
    • String ID:
    • API String ID: 3106088686-0
    • Opcode ID: b529eeb46b1eede4f9805dd231701478292caae48f7d7ff7bc1546388e4f010e
    • Instruction ID: 9c7733a4ee0f26d526643a21944fc58a4594e8f998939a9de4bbebd5f52ac11c
    • Opcode Fuzzy Hash: b529eeb46b1eede4f9805dd231701478292caae48f7d7ff7bc1546388e4f010e
    • Instruction Fuzzy Hash: BA01713020174D82EB8B9B65A8447AA3291AB4DBE0F18C228F926463D1DE3CC64DC701
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: free
    • String ID:
    • API String ID: 1294909896-0
    • Opcode ID: 9381d8dfaf48aa47efd066fad4f4c1346dad4c0f21544f4db727ecede13f6623
    • Instruction ID: 0380db5dcc4011a8ee892774553080b5cf429d8a0f9f119caa4bb88c45e776b7
    • Opcode Fuzzy Hash: 9381d8dfaf48aa47efd066fad4f4c1346dad4c0f21544f4db727ecede13f6623
    • Instruction Fuzzy Hash: 3C713477202B88CAEB92DFA9E4903DD77A1E759B80F18C016EB8A07351CF39D569C311
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: _wgetenvswscanf
    • String ID: %ld%c$JPEGMEM$x
    • API String ID: 2353447129-3402169052
    • Opcode ID: 443b9d3dc04f006af0511064b51fe890d6b90718b02c4772b7ea7d8a57b95636
    • Instruction ID: a6e5e490e4cdb91a01faa44b3030d45d07f3799ec0b821e77b8d5236952550b4
    • Opcode Fuzzy Hash: 443b9d3dc04f006af0511064b51fe890d6b90718b02c4772b7ea7d8a57b95636
    • Instruction Fuzzy Hash: 2D41F636215F48A6E786CB25E5813C977A8F748784F908126FB8D47B64EF38D279C780
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: _errno$_fileno_getbuf_invalid_parameter_noinfo_isatty
    • String ID:
    • API String ID: 2574049805-0
    • Opcode ID: ea75e5cf20b7f7844c4b8bc67faf072f29965c7ad569393f5253f051f69abf3d
    • Instruction ID: 6a7a9942f3966caa066fa294b396ed4a18fc749f67481194838face732c5f580
    • Opcode Fuzzy Hash: ea75e5cf20b7f7844c4b8bc67faf072f29965c7ad569393f5253f051f69abf3d
    • Instruction Fuzzy Hash: 5741C472610B4C86EBAADF28D4513EE37A0E748FD4F148215EA75873D6EE34CA59CB40
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ByteCharMultiWide$StringTypefreemalloc
    • String ID:
    • API String ID: 307345228-0
    • Opcode ID: 2a3790eea4a4617312d8e4a9442f6424bede9cf37a8252f36d331abd6b65284e
    • Instruction ID: abc54c1b28ca8ca362bcab6cb60de8bd725865527ee158dc4e020e444684f391
    • Opcode Fuzzy Hash: 2a3790eea4a4617312d8e4a9442f6424bede9cf37a8252f36d331abd6b65284e
    • Instruction Fuzzy Hash: 57415032201B8886EB929F65D8147DA7395FB4CBE8F288216FE69477D5DF78C649C300
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ErrorLast$recv
    • String ID:
    • API String ID: 316788870-0
    • Opcode ID: 14e5b7a9948d1e94ba054851c6eb7a6bed2ab8c873f0c59e5f30a48817030090
    • Instruction ID: 6199e5bf986f86425fbbc0522af38a7fcd77c4a4bcf61ee2ee22b2f26d195f40
    • Opcode Fuzzy Hash: 14e5b7a9948d1e94ba054851c6eb7a6bed2ab8c873f0c59e5f30a48817030090
    • Instruction Fuzzy Hash: 104191B2700A4885E792DF39E4443DE33A1E74DBC8F548126EE198B699DF39CA88C715
    APIs
    • DecodePointer.KERNEL32(?,?,?,0000000180009D41,?,?,?,?,00000001800097B3), ref: 0000000180009C55
    • DecodePointer.KERNEL32(?,?,?,0000000180009D41,?,?,?,?,00000001800097B3), ref: 0000000180009C65
      • Part of subcall function 000000018000C874: _errno.LIBCMT ref: 000000018000C87D
      • Part of subcall function 000000018000C874: _invalid_parameter_noinfo.LIBCMT ref: 000000018000C888
    • EncodePointer.KERNEL32(?,?,?,0000000180009D41,?,?,?,?,00000001800097B3), ref: 0000000180009CE3
      • Part of subcall function 000000018000C75C: realloc.LIBCMT ref: 000000018000C787
      • Part of subcall function 000000018000C75C: Sleep.KERNEL32(?,?,00000000,0000000180009CD3,?,?,?,0000000180009D41,?,?,?,?,00000001800097B3), ref: 000000018000C7A3
    • EncodePointer.KERNEL32(?,?,?,0000000180009D41,?,?,?,?,00000001800097B3), ref: 0000000180009CF3
    • EncodePointer.KERNEL32(?,?,?,0000000180009D41,?,?,?,?,00000001800097B3), ref: 0000000180009D00
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Pointer$Encode$Decode$Sleep_errno_invalid_parameter_noinforealloc
    • String ID:
    • API String ID: 1909145217-0
    • Opcode ID: 24608c62e4ce1b5fb8eecf5b2368e6216a0b19e46f6bda97ba43d3487df48692
    • Instruction ID: a3e2518ee86cc6793519812862cdabeece31c64530b0cc53dad98b323b8d5f8e
    • Opcode Fuzzy Hash: 24608c62e4ce1b5fb8eecf5b2368e6216a0b19e46f6bda97ba43d3487df48692
    • Instruction Fuzzy Hash: 6C216931302B4891EA83DB91E9483DAB3A1B74CBD0F54C826FA4E07765EE78C68CC340
    APIs
    • EnterCriticalSection.KERNEL32(?,?,00000000,0000000180004E9E,?,?,00000000,0000000180004E64), ref: 0000000180005E55
    • EnterCriticalSection.KERNEL32(?,?,00000000,0000000180004E9E,?,?,00000000,0000000180004E64), ref: 0000000180005E5F
    • LeaveCriticalSection.KERNEL32(?,?,00000000,0000000180004E9E,?,?,00000000,0000000180004E64), ref: 0000000180005E6F
    • LeaveCriticalSection.KERNEL32(?,?,00000000,0000000180004E9E,?,?,00000000,0000000180004E64), ref: 0000000180005E79
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CriticalSection$EnterLeave
    • String ID:
    • API String ID: 3168844106-0
    • Opcode ID: 7a81fae3a11a7c8614ce4b52f652239c74409d90b28903bf66d9faeaf82510ad
    • Instruction ID: b4ff77fc8091b79fa2e2e34a0cce3b936a653a81ca79f27a33948fa61e49d118
    • Opcode Fuzzy Hash: 7a81fae3a11a7c8614ce4b52f652239c74409d90b28903bf66d9faeaf82510ad
    • Instruction Fuzzy Hash: AC113D3262494983EBA6DB21F4943DA7360F748795F459021EBCB42A60DF7CDACAC700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: __doserrno_errno
    • String ID:
    • API String ID: 921712934-0
    • Opcode ID: 2adebc5d330ba20866aa6a7c2556a59eaf06e391f068851f50b98d17d41064fc
    • Instruction ID: 58a16bfa7e209c761215f3211aa515af73cb1c68bffe57348d4b1a8d3bf2a951
    • Opcode Fuzzy Hash: 2adebc5d330ba20866aa6a7c2556a59eaf06e391f068851f50b98d17d41064fc
    • Instruction Fuzzy Hash: A7016DB230164C44EAA79B5888813F836515B69BE5F65C329F62D067E3CFAC46499312
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CloseHandleObjectSingleWait$CurrentSleepThread
    • String ID:
    • API String ID: 570250148-0
    • Opcode ID: ece6bab6b59026452e66b88529e7cc8ce58c27b9fbf2850620a6747602fb9a63
    • Instruction ID: 736addbb9bfff09ec8da44a823191799851d9216327199c24c2f421c8face72c
    • Opcode Fuzzy Hash: ece6bab6b59026452e66b88529e7cc8ce58c27b9fbf2850620a6747602fb9a63
    • Instruction Fuzzy Hash: 79F0FF7621094CC2F7879F31F8553993360F78DFA5F198221EE6A4B2A4CF348A9A8710
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: EnumErrorEventEventsLastNetworkReset
    • String ID:
    • API String ID: 1050048411-3916222277
    • Opcode ID: a7472dcd841f44729ce3af89710bd7fc3c3b6896eeff7bc9e4c0264139a2461d
    • Instruction ID: fea11a4b11cfa689fd8695676352b74c4ff2bd00134010754c4c390e4f437825
    • Opcode Fuzzy Hash: a7472dcd841f44729ce3af89710bd7fc3c3b6896eeff7bc9e4c0264139a2461d
    • Instruction Fuzzy Hash: 66516FB350868886F3A2CF29D40439E77E1F789BC8F158115EE4D4B689DF79CA498B44
    APIs
    • _callnewh.LIBCMT ref: 0000000180009746
    • malloc.LIBCMT ref: 0000000180009752
      • Part of subcall function 0000000180009680: _FF_MSGBANNER.LIBCMT ref: 00000001800096B0
      • Part of subcall function 0000000180009680: HeapAlloc.KERNEL32(?,?,DEDE000000000000,000000018000C688,?,?,ceil,000000018000D395,?,?,?,000000018000D43F,?,?,00000000,000000018000BF75), ref: 00000001800096D5
      • Part of subcall function 0000000180009680: _callnewh.LIBCMT ref: 00000001800096EE
      • Part of subcall function 0000000180009680: _errno.LIBCMT ref: 00000001800096F9
      • Part of subcall function 0000000180009680: _errno.LIBCMT ref: 0000000180009704
    • std::exception::exception.LIBCMT ref: 00000001800097BF
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: _callnewh_errno$AllocHeapmallocstd::exception::exception
    • String ID: bad allocation
    • API String ID: 2837191506-2104205924
    • Opcode ID: 0be486e1f44dbbdcdc97537e0d2caa062964e2e83d7e8e6b65d3b9047e8da2ea
    • Instruction ID: 1e2019668250625a1b2b9d31203ed3bbb8279a505be9eb8be6bcc4309ce7e2fd
    • Opcode Fuzzy Hash: 0be486e1f44dbbdcdc97537e0d2caa062964e2e83d7e8e6b65d3b9047e8da2ea
    • Instruction Fuzzy Hash: A201177162AB4D91FA92EF50B8413D57361AB8D3C0F948416B96D426A2EF38C34DCB00
    APIs
    • GetModuleHandleW.KERNEL32(?,?,000000FF,000000018000A4F9,?,?,00000028,00000001800096C9,?,?,DEDE000000000000,000000018000C688,?,?,ceil,000000018000D395), ref: 000000018000A4BF
    • GetProcAddress.KERNEL32(?,?,000000FF,000000018000A4F9,?,?,00000028,00000001800096C9,?,?,DEDE000000000000,000000018000C688,?,?,ceil,000000018000D395), ref: 000000018000A4D4
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: AddressHandleModuleProc
    • String ID: CorExitProcess$mscoree.dll
    • API String ID: 1646373207-1276376045
    • Opcode ID: 672ef6b0e385174507540a630beccfc81086d2735ce3595b79ee3def95ae5807
    • Instruction ID: ffe41d6c2d7918e1b3e091e3a1c6c1f0ba9896b85bdc52aaa2673546b8ae739a
    • Opcode Fuzzy Hash: 672ef6b0e385174507540a630beccfc81086d2735ce3595b79ee3def95ae5807
    • Instruction Fuzzy Hash: F1E0127071260C41FF9BDF50B8953A623907B9D780F49902A982E46390DF7CD76CC300
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: DecodePointer_errno_invalid_parameter_noinfo_lock
    • String ID:
    • API String ID: 27599310-0
    • Opcode ID: 7be1fa04b18b82b6304af40f75c4a51f395efe5f3bf8b949c5798881251678ca
    • Instruction ID: db3631950fbbbb294078a21d31e159497d84441af4525d3d2c46f9e7a25869a3
    • Opcode Fuzzy Hash: 7be1fa04b18b82b6304af40f75c4a51f395efe5f3bf8b949c5798881251678ca
    • Instruction Fuzzy Hash: 3551967260878D46FAE7CB14E8443FA7262E78E7D0F24C525F95A46694DF38DB498301
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Releasefree
    • String ID:
    • API String ID: 3272087685-0
    • Opcode ID: 602c15725b8d813e0bbe9a4453e79e735bb61b4ef0baeaa11b2f701d3bc43177
    • Instruction ID: d36a20cf91c62a3c5da2fb10686ac00aeac2f0e1bd2c67ccd3b48aa5594e4940
    • Opcode Fuzzy Hash: 602c15725b8d813e0bbe9a4453e79e735bb61b4ef0baeaa11b2f701d3bc43177
    • Instruction Fuzzy Hash: CA31E636704B849BDB95CB2AE28039A77E1F749790F448125EB8C83B55DF38E5B5CB00
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ErrorEventLastSelect
    • String ID:
    • API String ID: 1135597009-0
    • Opcode ID: 4eddc6159fb5817f7b92b71e64624adfa859e47db7e01beaee153f9d2d3b1a78
    • Instruction ID: 60a763c8e145126c332b07c1875366a567e6bff20b8eb41a973b137eb8261982
    • Opcode Fuzzy Hash: 4eddc6159fb5817f7b92b71e64624adfa859e47db7e01beaee153f9d2d3b1a78
    • Instruction Fuzzy Hash: C321A4B351054487E792CF7AD44839D37A1E788B98F548115EA188B6D4DF79C9CACB10
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CriticalSection$Leave$EnterEvent
    • String ID:
    • API String ID: 3394196147-0
    • Opcode ID: ae513d91c155502473071655eea00dac2445091deb4c49d91ab79747f7e52d71
    • Instruction ID: 4418377062219beeb0047eb6f9c3d7a7e649a3d0339aff7300afd703f66b726b
    • Opcode Fuzzy Hash: ae513d91c155502473071655eea00dac2445091deb4c49d91ab79747f7e52d71
    • Instruction Fuzzy Hash: 99210A36314B8993D79ACF26E5803DEB3A4F748B90F548125EBAA43724DF34D9A5C740
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CriticalDeleteSection_amsg_exit_lockfclosefree
    • String ID:
    • API String ID: 594724896-0
    • Opcode ID: 0ff1c146e562c8b9ef731e40456d16958a7a062b4949e859bf57337feb6deafa
    • Instruction ID: 999679cd4892a8d823ebd278223fbb962f6f804c6108240481e7580e3c3cfcc4
    • Opcode Fuzzy Hash: 0ff1c146e562c8b9ef731e40456d16958a7a062b4949e859bf57337feb6deafa
    • Instruction Fuzzy Hash: 36119D35104B4C82F6A2CB15E8953ACB361F789BC4F24C626FA6A437B1CF76C64AC704
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: _amsg_exit$_getptd_lockfree
    • String ID:
    • API String ID: 2148533958-0
    • Opcode ID: 426a9eb5d6c89e876dd227587e832aff735dd614218dd979964c76dfd788a66a
    • Instruction ID: 33ae14cf30371a4dcb097d3cb4d18f5fada779ac3862c5845cfff631a4120995
    • Opcode Fuzzy Hash: 426a9eb5d6c89e876dd227587e832aff735dd614218dd979964c76dfd788a66a
    • Instruction Fuzzy Hash: 3A112E36305AC886EAD6DB10E8417E972A1F74E7C0F488026FA5E13395DF28DA58C712
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: CriticalDeleteSection$Freefree
    • String ID:
    • API String ID: 1250194111-0
    • Opcode ID: 276006e167cf1aff04d3b924b3b0065a621c9c7e6871e02c9381d2983fb42916
    • Instruction ID: d5b0619c1b78ea485a760d09b6761892c619e52fee80dffde751b67dcf8e653d
    • Opcode Fuzzy Hash: 276006e167cf1aff04d3b924b3b0065a621c9c7e6871e02c9381d2983fb42916
    • Instruction Fuzzy Hash: 9811A331600A4CC6FBD7CF51F8543A973A0F759BE4F588612FA6506295CF38C699CB11
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Thread$CurrentErrorExitLast_freefls
    • String ID:
    • API String ID: 217443660-0
    • Opcode ID: dc523210d31c271efce42c5f4489225d318c034fe84fa3c4ac1ff7ac3b89093b
    • Instruction ID: 5a3ec523d43a9f79c03c4ffc50292547c424952b638033dfd63fc7133ad02ff6
    • Opcode Fuzzy Hash: dc523210d31c271efce42c5f4489225d318c034fe84fa3c4ac1ff7ac3b89093b
    • Instruction Fuzzy Hash: 3701E731601B9C85EB86EBB1E40A3DE32A5AB0DBC4F14C434BA1D87397EE75C6588751
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: Heap$Destroyfree$CreateFree
    • String ID:
    • API String ID: 3907340440-0
    • Opcode ID: b72368671db39447bcebf8604b751b5a650bd80d16f31a87944435ce3b1989b4
    • Instruction ID: 09c77e5b898923fbf598fb34f1179acc1cfe9d62ff81f816d3f87d2e91f365b8
    • Opcode Fuzzy Hash: b72368671db39447bcebf8604b751b5a650bd80d16f31a87944435ce3b1989b4
    • Instruction Fuzzy Hash: 0C011D76612A8497EB8ADF62E6903A93364FB58BC0F14D415EF1A03A51DF34D9B48700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: _amsg_exit_getptd$_lock
    • String ID:
    • API String ID: 3670291111-0
    • Opcode ID: 1509d1ac26ba87f6e958dbd463ec673252434084bc47c8eababfe531d8c90e1d
    • Instruction ID: 9f3359b1737a572f573ec7ec3736ab8805c9ebd4f4246a1d20a58ac482fbf322
    • Opcode Fuzzy Hash: 1509d1ac26ba87f6e958dbd463ec673252434084bc47c8eababfe531d8c90e1d
    • Instruction Fuzzy Hash: CAF0173564154C82FAE6EB618851BF83261E75DBC0F48C239FE190B3D2DF248A4DE711
    APIs
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: ObjectSingleWait$Sleep
    • String ID:
    • API String ID: 2961732021-0
    • Opcode ID: b1e917308134ac2fafb3ffbaff7e83120a2ae0e71f17b407860b014fa0df2722
    • Instruction ID: 806618bc8838a8f2f27bfbe1f8a99ad75248c14d8b969983b08c7d98cb429908
    • Opcode Fuzzy Hash: b1e917308134ac2fafb3ffbaff7e83120a2ae0e71f17b407860b014fa0df2722
    • Instruction Fuzzy Hash: 38F08C32200A4C82E7828F76EC0439933A0F78DFA4F168322DA7D472E4CF3485AAC710
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: _errno_invalid_parameter_noinfo
    • String ID: B
    • API String ID: 2959964966-1255198513
    • Opcode ID: ca5941614373a58d278bb108b282cf9e75e41570224192e68ce77568d080692a
    • Instruction ID: bad346df8dc404074a7f862b1d6f9a0b8a376c289568912614f9bfd4eafe758c
    • Opcode Fuzzy Hash: ca5941614373a58d278bb108b282cf9e75e41570224192e68ce77568d080692a
    • Instruction Fuzzy Hash: B111847221574886EB61DF56D44039DB7A0F78DBD4F58C215BB9907B9ACF38C649CB00
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000003.2115421052.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
    • Associated: 00000000.00000003.2020944681.0000000180075000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115408172.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.000000018003D000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180052000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115445774.0000000180062000.00000002.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115489394.000000018006C000.00000004.00001000.00020000.00000000.sdmpDownload File
    • Associated: 00000000.00000003.2115502955.0000000180071000.00000002.00001000.00020000.00000000.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_3_180000000_EpCAySF1G6.jbxd
    Similarity
    • API ID: _errno_invalid_parameter_noinfo
    • String ID: I
    • API String ID: 2959964966-3707901625
    • Opcode ID: b65754f80cf49d38160d8fdb16d4f47f40f2887a7c681dede45eb3e4f638146e
    • Instruction ID: b614669ef453788ccb25b9283b1da39d6195e8738e3b23fa787283acb0fccfd3
    • Opcode Fuzzy Hash: b65754f80cf49d38160d8fdb16d4f47f40f2887a7c681dede45eb3e4f638146e
    • Instruction Fuzzy Hash: 0911827270474485EB66DB12E54039AB7A5F798FE0F148225FB990BB95CF38D649CB00