Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
LZUCldA1ro.exe

Overview

General Information

Sample name:LZUCldA1ro.exe
renamed because original name is a hash value
Original sample name:801b1a0d107611d7467df2470f1cd20f.exe
Analysis ID:1584671
MD5:801b1a0d107611d7467df2470f1cd20f
SHA1:e2ea349f9ab2a9f0f492024266351350d3563e3c
SHA256:58f0cc4abe20d42c84ea7bd1287e5fd4ce6f888a20f49073d80329d5b7804858
Tags:exeuser-abuse_ch
Infos:

Detection

Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains very large array initializations
AI detected suspicious sample
Found many strings related to Crypto-Wallets (likely being stolen)
Machine Learning detection for sample
Queries memory information (via WMI often done to detect virtual machines)
Queries sensitive Plug and Play Device Information (via WMI, Win32_PnPEntity, often done to detect virtual machines)
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive physical memory information (via WMI, Win32_PhysicalMemory, often done to detect virtual machines)
Tries to harvest and steal Bitcoin Wallet information
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains long sleeps (>= 3 min)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer

Classification

  • System is w10x64
  • LZUCldA1ro.exe (PID: 3432 cmdline: "C:\Users\user\Desktop\LZUCldA1ro.exe" MD5: 801B1A0D107611D7467DF2470F1CD20F)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
    Process Memory Space: LZUCldA1ro.exe PID: 3432JoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
      No Sigma rule has matched
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2025-01-06T07:48:02.557024+010020355951Domain Observed Used for C2 Detected207.231.107.13756001192.168.2.649710TCP

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: LZUCldA1ro.exeAvira: detected
      Source: LZUCldA1ro.exeVirustotal: Detection: 70%Perma Link
      Source: LZUCldA1ro.exeReversingLabs: Detection: 63%
      Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
      Source: LZUCldA1ro.exeJoe Sandbox ML: detected
      Source: LZUCldA1ro.exeStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
      Source: LZUCldA1ro.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

      Networking

      barindex
      Source: Network trafficSuricata IDS: 2035595 - Severity 1 - ET MALWARE Generic AsyncRAT Style SSL Cert : 207.231.107.137:56001 -> 192.168.2.6:49710
      Source: global trafficTCP traffic: 192.168.2.6:49710 -> 207.231.107.137:56001
      Source: Joe Sandbox ViewASN Name: AS40676US AS40676US
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: unknownTCP traffic detected without corresponding DNS query: 207.231.107.137
      Source: LZUCldA1ro.exe, 00000000.00000002.4558822819.0000000001241000.00000004.00000020.00020000.00000000.sdmp, 77EC63BDA74BD0D0E0426DC8F80085060.0.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
      Source: LZUCldA1ro.exe, 00000000.00000002.4558822819.0000000001241000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en~?
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/DFfe9ewf/test3/raw/refs/heads/main/WebDriver.dll
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/DFfe9ewf/test3/raw/refs/heads/main/chromedriver.exe
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/DFfe9ewf/test3/raw/refs/heads/main/msedgedriver.exe
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/11564914/23354;
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/14436606/23354
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/2152978/23354rCannot

      System Summary

      barindex
      Source: LZUCldA1ro.exe, FilteredPolicy.csLarge array initialization: ImplementModularPolicy: array initializer size 306176
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess Stats: CPU usage > 49%
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_0119427B0_2_0119427B
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_011942C90_2_011942C9
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_0119473B0_2_0119473B
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_011947C00_2_011947C0
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_01191DB80_2_01191DB8
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_01191DC80_2_01191DC8
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_054B55500_2_054B5550
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_054B51F00_2_054B51F0
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_054B51E00_2_054B51E0
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_054B9F1E0_2_054B9F1E
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_054B9F200_2_054B9F20
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_05506CE80_2_05506CE8
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_055007500_2_05500750
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_0550E6100_2_0550E610
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_0550A5C00_2_0550A5C0
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_055025E80_2_055025E8
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_05504DA00_2_05504DA0
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_05500C370_2_05500C37
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_05506CDA0_2_05506CDA
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_0550F7E20_2_0550F7E2
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_055289A00_2_055289A0
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_0552F9280_2_0552F928
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_05550FB00_2_05550FB0
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_0555FA580_2_0555FA58
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_055547D00_2_055547D0
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_055547C00_2_055547C0
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_055547800_2_05554780
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_05550FA00_2_05550FA0
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_055547A00_2_055547A0
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_05559EE80_2_05559EE8
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_055581900_2_05558190
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_055581A00_2_055581A0
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_055562770_2_05556277
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_055562880_2_05556288
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_069557690_2_06955769
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_069534600_2_06953460
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_069500400_2_06950040
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_069509100_2_06950910
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_069557720_2_06955772
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_069534500_2_06953450
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_06952D920_2_06952D92
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_069552260_2_06955226
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_0695522F0_2_0695522F
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_069553150_2_06955315
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_069558410_2_06955841
      Source: LZUCldA1ro.exe, 00000000.00000000.2107236580.0000000000AEC000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameAlrzys.exe" vs LZUCldA1ro.exe
      Source: LZUCldA1ro.exe, 00000000.00000002.4561340221.0000000004018000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameZvnlwvfe.dll" vs LZUCldA1ro.exe
      Source: LZUCldA1ro.exe, 00000000.00000002.4562014858.0000000005390000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameZvnlwvfe.dll" vs LZUCldA1ro.exe
      Source: LZUCldA1ro.exe, 00000000.00000002.4558822819.00000000011CE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs LZUCldA1ro.exe
      Source: LZUCldA1ro.exeBinary or memory string: OriginalFilenameAlrzys.exe" vs LZUCldA1ro.exe
      Source: LZUCldA1ro.exeStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
      Source: LZUCldA1ro.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      Source: LZUCldA1ro.exe, DefinitionRequest.csCryptographic APIs: 'CreateDecryptor'
      Source: LZUCldA1ro.exe, DefinitionRequest.csCryptographic APIs: 'CreateDecryptor'
      Source: LZUCldA1ro.exe, FilteredPolicy.csCryptographic APIs: 'CreateDecryptor'
      Source: classification engineClassification label: mal100.spyw.evad.winEXE@1/2@0/1
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeMutant created: NULL
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeMutant created: \Sessions\1\BaseNamedObjects\b73b56eba7d5
      Source: LZUCldA1ro.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      Source: LZUCldA1ro.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
      Source: LZUCldA1ro.exeVirustotal: Detection: 70%
      Source: LZUCldA1ro.exeReversingLabs: Detection: 63%
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: mscoree.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: apphelp.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: version.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: wldp.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: profapi.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: cryptsp.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: rsaenh.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: cryptbase.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: amsi.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: userenv.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: msasn1.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: gpapi.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: mswsock.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: secur32.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: schannel.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: mskeyprotect.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: ntasn1.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: ncrypt.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: ncryptsslp.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: cryptnet.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: iphlpapi.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: winnsi.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: winhttp.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: dhcpcsvc6.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: dhcpcsvc.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: webio.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: dnsapi.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: rasadhlp.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: fwpuclnt.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: cabinet.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeSection loaded: wbemcomn.dllJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
      Source: LZUCldA1ro.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
      Source: LZUCldA1ro.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

      Data Obfuscation

      barindex
      Source: LZUCldA1ro.exe, DefinitionRequest.cs.Net Code: typeof(Marshal).GetMethod("GetDelegateForFunctionPointer", new Type[2]{typeof(IntPtr),typeof(Type)})
      Source: LZUCldA1ro.exeStatic PE information: 0xE222BDD2 [Thu Mar 23 04:47:14 2090 UTC]
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeCode function: 0_2_0555E558 pushad ; iretd 0_2_0555E559
      Source: LZUCldA1ro.exeStatic PE information: section name: .text entropy: 7.874303869633843
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

      Malware Analysis System Evasion

      barindex
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_PhysicalMemory
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_PnPEntity WHERE (PNPClass = 'Image' OR PNPClass = 'Camera')
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_DiskDrive
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_PhysicalMemory
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeMemory allocated: 1150000 memory reserve | memory write watchJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeMemory allocated: 2F50000 memory reserve | memory write watchJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeMemory allocated: 2DC0000 memory reserve | memory write watchJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 922337203685477Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeWindow / User API: threadDelayed 2260Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeWindow / User API: threadDelayed 7457Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 6816Thread sleep time: -30000s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -25825441703193356s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -39000s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 6672Thread sleep count: 2260 > 30Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -38598s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 6672Thread sleep count: 7457 > 30Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -38453s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -38339s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -38234s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -38117s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -38000s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -37890s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -37781s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -37672s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -37562s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -37453s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -37343s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -37234s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -37125s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -37015s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -36906s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -36797s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -36684s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -36578s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -36469s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -36359s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -36250s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -36140s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -36031s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -35922s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -35812s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -35703s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -35594s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -35484s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -35375s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -35255s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -35140s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -35031s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -34922s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -34812s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -34703s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -34594s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -34484s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -34375s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -34265s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -34156s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -34047s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -33937s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -33828s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -33719s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exe TID: 4180Thread sleep time: -33609s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 922337203685477Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 39000Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 38598Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 38453Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 38339Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 38234Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 38117Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 38000Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 37890Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 37781Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 37672Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 37562Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 37453Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 37343Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 37234Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 37125Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 37015Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 36906Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 36797Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 36684Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 36578Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 36469Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 36359Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 36250Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 36140Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 36031Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 35922Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 35812Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 35703Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 35594Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 35484Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 35375Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 35255Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 35140Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 35031Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 34922Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 34812Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 34703Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 34594Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 34484Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 34375Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 34265Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 34156Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 34047Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 33937Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 33828Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 33719Jump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeThread delayed: delay time: 33609Jump to behavior
      Source: LZUCldA1ro.exe, 00000000.00000002.4563067488.0000000006504000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: al Memory 0Win32_PhysicalMemoryPhysical MemoryPhysical MemoryPhysical MemoryRAM slot #0RAM slot #0VMware Virtual RAM00000001VMW-4096MB
      Source: LZUCldA1ro.exe, 00000000.00000002.4563067488.00000000064EA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
      Source: LZUCldA1ro.exe, 00000000.00000002.4558822819.000000000129D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWh
      Source: LZUCldA1ro.exe, 00000000.00000002.4563067488.0000000006504000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VMware Virtual RAM
      Source: LZUCldA1ro.exe, 00000000.00000002.4562935243.000000000578F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWL
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeProcess token adjusted: DebugJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeMemory allocated: page read and write | page guardJump to behavior
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.00000000033BA000.00000004.00000800.00020000.00000000.sdmp, LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000003161000.00000004.00000800.00020000.00000000.sdmp, LZUCldA1ro.exe, 00000000.00000002.4559421851.00000000033E2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Manager
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.00000000033BA000.00000004.00000800.00020000.00000000.sdmp, LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000003161000.00000004.00000800.00020000.00000000.sdmp, LZUCldA1ro.exe, 00000000.00000002.4559421851.00000000033E2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Manager*
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.00000000032B2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Managerh{
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.00000000033BA000.00000004.00000800.00020000.00000000.sdmp, LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000003161000.00000004.00000800.00020000.00000000.sdmp, LZUCldA1ro.exe, 00000000.00000002.4559421851.00000000033E2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program ManagerTe
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeQueries volume information: C:\Users\user\Desktop\LZUCldA1ro.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : SELECT * FROM AntiVirusProduct

      Stealing of Sensitive Information

      barindex
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: Electrum
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: tibnejdfjmmkpcnlpebklmnkoeoihofecuTronLinkvnkbihfbeogaeaoehlefnkodbefgpgknnwMetaMaskxfhbohimaelbohpjbbldcngcnapndodjpyBinance Chain Walletzffnbelfdoeiohenkjibnmadjiehjhajb{Yoroi|cjelfplplebdjjenllpjcblmjkfcffne}Jaxx Liberty~fihkakfobkmkjojpchpfgcmhfjnmnfpi
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000003234000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: q6C:\Users\user\AppData\Roaming\Exodus\exodus.wallet
      Source: LZUCldA1ro.exe, 00000000.00000002.4562750751.00000000056F0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: \??\C:\Users\user\AppData\Roaming\Ethereum\keystore
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: Exodus Web3
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: Ethereum
      Source: LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: keystore
      Source: C:\Users\user\Desktop\LZUCldA1ro.exeKey opened: HKEY_CURRENT_USER\Software\Bitcoin\Bitcoin-QtJump to behavior
      Source: Yara matchFile source: 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: LZUCldA1ro.exe PID: 3432, type: MEMORYSTR
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid Accounts321
      Windows Management Instrumentation
      1
      DLL Side-Loading
      1
      Process Injection
      1
      Disable or Modify Tools
      OS Credential Dumping1
      Query Registry
      Remote Services11
      Archive Collected Data
      1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
      DLL Side-Loading
      341
      Virtualization/Sandbox Evasion
      LSASS Memory421
      Security Software Discovery
      Remote Desktop Protocol1
      Data from Local System
      1
      Non-Standard Port
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
      Process Injection
      Security Account Manager1
      Process Discovery
      SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
      Deobfuscate/Decode Files or Information
      NTDS341
      Virtualization/Sandbox Evasion
      Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script2
      Obfuscated Files or Information
      LSA Secrets1
      Application Window Discovery
      SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts12
      Software Packing
      Cached Domain Credentials213
      System Information Discovery
      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
      DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
      Timestomp
      DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
      Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
      DLL Side-Loading
      Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      LZUCldA1ro.exe70%VirustotalBrowse
      LZUCldA1ro.exe63%ReversingLabsByteCode-MSIL.Trojan.Jalapeno
      LZUCldA1ro.exe100%AviraHEUR/AGEN.1323341
      LZUCldA1ro.exe100%Joe Sandbox ML
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      bg.microsoft.map.fastly.net
      199.232.210.172
      truefalse
        high
        NameSourceMaliciousAntivirus DetectionReputation
        https://stackoverflow.com/q/14436606/23354LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpfalse
          high
          https://github.com/DFfe9ewf/test3/raw/refs/heads/main/WebDriver.dllLZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpfalse
            high
            http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameLZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpfalse
              high
              https://stackoverflow.com/q/2152978/23354rCannotLZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpfalse
                high
                https://stackoverflow.com/q/11564914/23354;LZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpfalse
                  high
                  https://github.com/DFfe9ewf/test3/raw/refs/heads/main/chromedriver.exeLZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpfalse
                    high
                    https://github.com/DFfe9ewf/test3/raw/refs/heads/main/msedgedriver.exeLZUCldA1ro.exe, 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmpfalse
                      high
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      207.231.107.137
                      unknownUnited States
                      40676AS40676UStrue
                      Joe Sandbox version:41.0.0 Charoite
                      Analysis ID:1584671
                      Start date and time:2025-01-06 07:47:06 +01:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:0h 7m 41s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:default.jbs
                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                      Number of analysed new started processes analysed:7
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Sample name:LZUCldA1ro.exe
                      renamed because original name is a hash value
                      Original Sample Name:801b1a0d107611d7467df2470f1cd20f.exe
                      Detection:MAL
                      Classification:mal100.spyw.evad.winEXE@1/2@0/1
                      EGA Information:Failed
                      HCA Information:
                      • Successful, ratio: 96%
                      • Number of executed functions: 342
                      • Number of non-executed functions: 26
                      Cookbook Comments:
                      • Found application associated with file extension: .exe
                      • Override analysis time to 240000 for current running targets taking high CPU consumption
                      • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe
                      • Excluded IPs from analysis (whitelisted): 199.232.210.172, 13.107.246.45, 20.12.23.50
                      • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, wu-b-net.trafficmanager.net, fe3cr.delivery.mp.microsoft.com
                      • Execution Graph export aborted for target LZUCldA1ro.exe, PID 3432 because it is empty
                      • Report size getting too big, too many NtOpenFile calls found.
                      • Report size getting too big, too many NtOpenKeyEx calls found.
                      • Report size getting too big, too many NtQueryValueKey calls found.
                      • Report size getting too big, too many NtReadVirtualMemory calls found.
                      TimeTypeDescription
                      01:48:02API Interceptor11839824x Sleep call for process: LZUCldA1ro.exe modified
                      No context
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      bg.microsoft.map.fastly.netDUD6CqQ1Uj.docGet hashmaliciousUnknownBrowse
                      • 199.232.210.172
                      ny9LDJr6pA.exeGet hashmaliciousQuasarBrowse
                      • 199.232.214.172
                      JP1KbvjWcM.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
                      • 199.232.210.172
                      cZO.exeGet hashmaliciousUnknownBrowse
                      • 199.232.214.172
                      jaTDEkWCbs.exeGet hashmaliciousQuasarBrowse
                      • 199.232.210.172
                      3LcZO15oTC.exeGet hashmaliciousUnknownBrowse
                      • 199.232.210.172
                      N5kEzgUBn6.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
                      • 199.232.214.172
                      Tax_Refund_Claim_2024_Australian_Taxation_Office.jsGet hashmaliciousRemcosBrowse
                      • 199.232.214.172
                      N5kEzgUBn6.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
                      • 199.232.210.172
                      setup64v9.3.4.msiGet hashmaliciousUnknownBrowse
                      • 199.232.210.172
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      AS40676USdownload.ps1Get hashmaliciousUnknownBrowse
                      • 45.61.136.138
                      download.ps1Get hashmaliciousUnknownBrowse
                      • 45.61.136.138
                      download.ps1Get hashmaliciousUnknownBrowse
                      • 45.61.136.138
                      download.ps1Get hashmaliciousUnknownBrowse
                      • 45.61.136.138
                      Fantazy.spc.elfGet hashmaliciousUnknownBrowse
                      • 41.216.189.243
                      armv6l.elfGet hashmaliciousMiraiBrowse
                      • 23.179.122.63
                      download.ps1Get hashmaliciousUnknownBrowse
                      • 45.61.136.138
                      download.ps1Get hashmaliciousUnknownBrowse
                      • 45.61.136.138
                      download.ps1Get hashmaliciousUnknownBrowse
                      • 45.61.136.138
                      download.ps1Get hashmaliciousUnknownBrowse
                      • 45.61.136.138
                      No context
                      No context
                      Process:C:\Users\user\Desktop\LZUCldA1ro.exe
                      File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 71954 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
                      Category:dropped
                      Size (bytes):71954
                      Entropy (8bit):7.996617769952133
                      Encrypted:true
                      SSDEEP:1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ
                      MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
                      SHA1:1723BE06719828DDA65AD804298D0431F6AFF976
                      SHA-256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
                      SHA-512:BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B
                      Malicious:false
                      Reputation:high, very likely benign file
                      Preview:MSCF............,...................I..................XaK .authroot.stl.[.i..6..CK..<Tk......4.cl!Kg..E..*Y.f_..".$mR"$.J.E.KB."..rKv.."{.g....3.W.....c..9.s...=....y6#..x..........D......\(.#.s.!.A.......cd.c........+^.ov...n.....3BL..0.......BPUR&.X..02.q...R...J.....w.....b.vy>....-.&..(..oe."."...J9...0U.6J..|U..S.....M.F8g...=.......p...........l.?3.J.x.G.Ep..$g..tj......)v]9(:.)W.8.Op.1Q..:.nPd........7.7..M].V F..g.....12..!7(...B.......h.RZ.......l.<.....6..Z^.`p?... .p.Gp.#.'.X..........|!.8.....".m.49r?.I...g...8.v.....a``.g.R4.i...J8q....NFW,E.6Y....!.o5%.Y.....R..<..S9....r....WO...(.....F..Q=*....-..7d..O(....-..+k.........K..........{Q....Z..j._.E...QZ.~.\.^......N.9.k..O.}dD.b1r...[}/....T..E..G..c.|.c.&>?..^t. ..;..X.d.E.0G....[Q.*,*......#.Dp..L.o|#syc.J............}G-.ou6.=52..XWi=...m.....^u......c..fc?&pR7S5....I...j.G........j.j..Tc.El.....B.pQ.,Bp....j...9g.. >..s..m#.Nb.o_u.M.V...........\#...v..Mo\sF..s....Y...
                      Process:C:\Users\user\Desktop\LZUCldA1ro.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):328
                      Entropy (8bit):3.242990426783058
                      Encrypted:false
                      SSDEEP:6:kK9eT99UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:gQDImsLNkPlE99SNxAhUe/3
                      MD5:64BF69DC4E91265E6561488E7D4CEE4B
                      SHA1:FA8731DF3905CB088BA76DE9F54602D62225CF5E
                      SHA-256:5A66EA51685E642E935CD0E00F6460AC5D3A7D04AED11ADEA9B456C50FE19154
                      SHA-512:D68214F54EB7D5F5281CF021C7F8E7D9EABC8A7AC14001B21F618C9EA452329AABEF545120E80EB45AF7A2F6CEE8F35EF14440EE34CD5E00163B642CDB6814F6
                      Malicious:false
                      Reputation:low
                      Preview:p...... ..........u..`..(....................................................... ........G..@.......&......X........h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...".a.7.2.8.2.e.b.4.0.b.1.d.a.1.:.0."...
                      File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                      Entropy (8bit):7.858889367025201
                      TrID:
                      • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                      • Win32 Executable (generic) a (10002005/4) 49.78%
                      • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                      • Generic Win/DOS Executable (2004/3) 0.01%
                      • DOS Executable Generic (2002/1) 0.01%
                      File name:LZUCldA1ro.exe
                      File size:367'104 bytes
                      MD5:801b1a0d107611d7467df2470f1cd20f
                      SHA1:e2ea349f9ab2a9f0f492024266351350d3563e3c
                      SHA256:58f0cc4abe20d42c84ea7bd1287e5fd4ce6f888a20f49073d80329d5b7804858
                      SHA512:7bd4abc2849dc9d97104e88858b15860263eec86da23b157e4a6f1978df9ea7c1ecef5c62c4187773278a73111b55b4813d6eae12c0c28bf0bdd00be967b59d3
                      SSDEEP:6144:A2nXZ8Q9bZl3Y2Nzq6XGTazlqwv6gwDdxKxjFYAY2we2LR3l:A2J8Q9bZW2Nzq6qazl1ildQxjFYVeoR1
                      TLSH:D674015036C99B61C00846B5CDE7D91502F2EB572A37CB2ABD8D46C00FA3792EE877C9
                      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....."...............0.................. ........@.. ....................................@................................
                      Icon Hash:00928e8e8686b000
                      Entrypoint:0x45ae0e
                      Entrypoint Section:.text
                      Digitally signed:false
                      Imagebase:0x400000
                      Subsystem:windows gui
                      Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                      DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                      Time Stamp:0xE222BDD2 [Thu Mar 23 04:47:14 2090 UTC]
                      TLS Callbacks:
                      CLR (.Net) Version:
                      OS Version Major:4
                      OS Version Minor:0
                      File Version Major:4
                      File Version Minor:0
                      Subsystem Version Major:4
                      Subsystem Version Minor:0
                      Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                      Instruction
                      jmp dword ptr [00402000h]
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      NameVirtual AddressVirtual Size Is in Section
                      IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_IMPORT0x5adc00x4b.text
                      IMAGE_DIRECTORY_ENTRY_RESOURCE0x5c0000x560.rsrc
                      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                      IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                      IMAGE_DIRECTORY_ENTRY_BASERELOC0x5e0000xc.reloc
                      IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                      IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                      .text0x20000x58e140x59000bdef609fb0fb350f03e81cab37f1aeeeFalse0.9208463175912921data7.874303869633843IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      .rsrc0x5c0000x5600x600ee5f09bcbbe001bb3a41934f1cd24d9fFalse0.4010416666666667data3.9235272008999935IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                      .reloc0x5e0000xc0x20039b3e6a587a021cee42a99289ab8dad4False0.044921875data0.10191042566270775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                      NameRVASizeTypeLanguageCountryZLIB Complexity
                      RT_VERSION0x5c0a00x2d4data0.43370165745856354
                      RT_MANIFEST0x5c3740x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5489795918367347
                      DLLImport
                      mscoree.dll_CorExeMain
                      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                      2025-01-06T07:48:02.557024+01002035595ET MALWARE Generic AsyncRAT Style SSL Cert1207.231.107.13756001192.168.2.649710TCP
                      TimestampSource PortDest PortSource IPDest IP
                      Jan 6, 2025 07:48:01.988033056 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:01.992940903 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:01.993057966 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:01.994518995 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:01.999288082 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:02.007875919 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:02.012643099 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:02.546051025 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:02.546073914 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:02.546242952 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:02.552208900 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:02.557024002 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:02.688472033 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:02.738234043 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:04.478029966 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:04.482939959 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:04.482990980 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:04.487752914 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:28.543420076 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:28.597704887 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:28.635782003 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:28.675833941 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:42.583200932 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:42.588007927 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:42.588073969 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:42.592880011 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:42.803833961 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:42.847704887 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:42.894320965 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:42.899205923 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:42.904078960 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:42.904150009 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:42.908962965 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:54.560641050 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:54.613501072 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:48:54.694051981 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:48:54.738523960 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:20.575720072 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:20.629101038 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:20.668060064 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:20.722805023 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:21.598274946 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:21.603400946 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:21.603588104 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:21.609561920 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:21.817606926 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:21.863387108 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:21.907973051 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:21.909776926 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:21.914599895 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:21.914654016 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:21.919447899 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:43.145651102 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:43.150970936 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:43.151027918 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:43.156621933 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:43.303215027 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:43.310022116 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:43.310069084 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:43.316795111 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:43.367503881 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:43.410315037 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:43.496081114 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:43.498095989 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:43.502923012 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:43.502994061 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:43.507879972 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:43.593441010 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:43.595499992 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:43.600388050 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:43.600480080 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:43.605299950 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:46.576319933 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:46.632003069 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:46.710064888 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:46.754158974 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:55.051460981 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:55.058084011 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:55.058217049 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:55.064690113 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:55.271374941 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:55.316586018 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:55.361713886 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:55.372275114 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:55.377109051 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:49:55.377150059 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:49:55.381906033 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:06.629713058 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:06.634650946 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:06.636065960 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:06.641865969 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:06.849968910 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:06.895973921 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:06.981976986 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:06.985620022 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:06.990447044 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:06.990520954 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:06.995322943 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:08.223985910 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:08.228897095 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:08.235990047 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:08.240822077 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:08.443527937 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:08.488837957 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:08.574012041 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:08.581378937 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:08.586169004 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:08.586282969 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:08.591080904 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:12.594736099 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:12.644761086 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:12.730052948 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:12.787997007 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:15.535782099 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:15.540739059 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:15.540816069 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:15.545646906 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:15.755640030 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:15.816632986 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:15.846102953 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:15.848217964 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:15.853099108 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:15.853159904 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:15.858012915 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:17.051307917 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:17.056512117 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:17.058119059 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:17.063062906 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:17.272124052 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:17.316615105 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:17.406724930 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:17.409279108 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:17.414520025 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:17.414572954 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:17.419845104 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:18.884012938 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:18.888972044 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:18.890146971 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:18.895100117 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:19.100106955 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:19.144763947 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:19.234111071 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:19.236618042 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:19.241553068 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:19.241600037 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:19.246474028 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:19.457740068 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:19.462807894 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:19.462868929 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:19.467742920 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:19.678097963 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:19.722907066 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:19.810103893 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:19.812856913 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:19.817795038 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:19.817852974 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:19.822695017 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:29.879553080 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:29.884737015 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:29.884803057 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:29.889619112 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:30.100394011 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:30.144783020 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:30.238118887 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:30.240493059 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:30.245346069 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:30.245440960 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:30.250236034 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:32.488845110 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:32.493963957 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:32.494127035 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:32.499033928 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:32.709558010 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:32.754168034 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:32.788059950 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:32.792911053 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:32.796118975 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:32.800862074 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:32.842113018 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:32.845397949 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:32.850224018 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:32.850334883 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:32.855114937 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:33.006612062 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:33.051120996 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:33.142132044 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:33.151335001 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:33.156199932 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:33.156326056 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:33.161247969 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:36.914144039 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:36.919164896 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:36.919311047 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:36.924135923 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:37.131779909 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:37.176070929 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:37.266079903 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:37.276051998 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:37.280931950 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:37.280993938 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:37.285913944 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:38.609045029 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:38.660468102 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:38.742089987 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:38.788060904 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:54.866094112 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:54.873888016 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:54.874227047 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:54.880742073 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:55.085454941 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:55.129201889 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:55.185652018 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:55.191610098 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:55.196577072 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:50:55.198220015 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:50:55.203140020 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:01.520214081 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:01.525136948 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:01.525208950 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:01.530038118 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:01.741478920 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:01.785460949 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:01.874094963 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:01.876648903 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:01.881458044 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:01.881526947 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:01.886308908 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:17.785978079 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:17.790810108 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:17.790858030 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:17.795607090 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:18.007371902 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:18.051163912 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:18.138022900 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:18.140269995 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:18.145035028 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:18.145255089 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:18.150077105 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:18.680125952 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:18.685061932 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:18.685143948 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:18.689948082 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:18.897778034 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:18.941828966 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:19.032497883 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:19.038296938 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:19.044750929 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:19.048207998 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:19.054627895 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:38.113919020 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:38.118803978 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:38.118973017 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:38.123718023 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:38.336055040 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:38.384234905 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:38.473972082 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:38.485726118 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:38.490489006 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:38.492207050 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:38.496933937 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:47.740597963 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:47.745443106 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:47.745521069 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:47.750313997 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:47.962209940 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:48.004347086 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:48.215306997 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:48.217119932 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:48.221967936 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:51:48.222016096 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:51:48.226815939 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:52:02.013487101 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:52:02.018428087 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:52:02.018523932 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:52:02.023401976 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:52:02.228295088 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:52:02.269937038 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:52:02.317326069 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:52:02.318032980 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:52:02.322810888 CET5600149710207.231.107.137192.168.2.6
                      Jan 6, 2025 07:52:02.322894096 CET4971056001192.168.2.6207.231.107.137
                      Jan 6, 2025 07:52:02.327729940 CET5600149710207.231.107.137192.168.2.6
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Jan 6, 2025 07:48:02.867772102 CET1.1.1.1192.168.2.60xfc32No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                      Jan 6, 2025 07:48:02.867772102 CET1.1.1.1192.168.2.60xfc32No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                      Jan 6, 2025 07:49:14.844588041 CET1.1.1.1192.168.2.60x343aNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                      Jan 6, 2025 07:49:14.844588041 CET1.1.1.1192.168.2.60x343aNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false

                      Click to jump to process

                      Click to jump to process

                      Click to dive into process behavior distribution

                      Target ID:0
                      Start time:01:47:55
                      Start date:06/01/2025
                      Path:C:\Users\user\Desktop\LZUCldA1ro.exe
                      Wow64 process (32bit):true
                      Commandline:"C:\Users\user\Desktop\LZUCldA1ro.exe"
                      Imagebase:0xa90000
                      File size:367'104 bytes
                      MD5 hash:801B1A0D107611D7467DF2470F1CD20F
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Yara matches:
                      • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000000.00000002.4559421851.0000000002F73000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      Reputation:low
                      Has exited:false

                      Reset < >
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: {r
                        • API String ID: 0-2532385969
                        • Opcode ID: 3cfe02ba03b521576006f000ad28a7df5b1d5a52a51e98021e95ff6b366ebdaa
                        • Instruction ID: 6f04044a6e61c26d0f7e0bbd5f4780ac94b418ebe7ae3b91152ad3e5c1439850
                        • Opcode Fuzzy Hash: 3cfe02ba03b521576006f000ad28a7df5b1d5a52a51e98021e95ff6b366ebdaa
                        • Instruction Fuzzy Hash: 28E22AB070160A8FD744EB24E5F5EAE33F2FB88340F1546A9940A9B759DE30AE51CF91
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: {r
                        • API String ID: 0-2532385969
                        • Opcode ID: deb1bcae638c5d1f2385463dcc2d7b1b9b283e57f285ea9896b83b426f4c4d1a
                        • Instruction ID: ddaf8e62cabf6df85862b8bae8054f1bf725fd4d70136bc503094167ee8922f3
                        • Opcode Fuzzy Hash: deb1bcae638c5d1f2385463dcc2d7b1b9b283e57f285ea9896b83b426f4c4d1a
                        • Instruction Fuzzy Hash: 6EE239B070160A8FD744EB24E5F5EAE33F2FB88340F1546A9940A9B759DE30AE51CF91
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: 4
                        • API String ID: 0-4088798008
                        • Opcode ID: 89dd225aa0d6c5ef431285a2452f198bebe35b0892cd1e66b200bf422c734fd1
                        • Instruction ID: 697966e9dffd8a3cda98f2822f3c610ea7dd675b5cff612570e56b83852b5d53
                        • Opcode Fuzzy Hash: 89dd225aa0d6c5ef431285a2452f198bebe35b0892cd1e66b200bf422c734fd1
                        • Instruction Fuzzy Hash: 54E24E74A006188FDB55DF65D894BEEBBB6FB88700F1481A9E50AAB394DF309D42CF50
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: 4
                        • API String ID: 0-4088798008
                        • Opcode ID: 0b6c157d249d051c20f2aa95668484ff77be265361228e16200991c2f262a0f4
                        • Instruction ID: 4da109d5c99401626eed3585bc1e9da7c970044bea384b94d68cf73289968972
                        • Opcode Fuzzy Hash: 0b6c157d249d051c20f2aa95668484ff77be265361228e16200991c2f262a0f4
                        • Instruction Fuzzy Hash: 90625D74A006198FDB55EF65D894BEEBBB6FB88300F5480A9E50A9B394CF30AD41CF51
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: \V[n
                        • API String ID: 0-1005319620
                        • Opcode ID: 0b73202663d030a4a9851b83ddbbb65a38614be0cdf6075c4291c35d88118159
                        • Instruction ID: f2e3483928d34bc86f272948c593ab75a535272a5dfdbee9930ebeff7a112fa6
                        • Opcode Fuzzy Hash: 0b73202663d030a4a9851b83ddbbb65a38614be0cdf6075c4291c35d88118159
                        • Instruction Fuzzy Hash: BBB17E70E00209CFDB50CFA9C985BDEBBF6BF88304F258529D819A7654EB749845CF81
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: \V[n
                        • API String ID: 0-1005319620
                        • Opcode ID: c6a24356699a25740ea82c5a50abe396c4bd4173be812d4682b6ce216bd1a3ae
                        • Instruction ID: 553222fccce08185cc1297c7a26f10fc094f06377ae9e1f4f22d7301da0fd659
                        • Opcode Fuzzy Hash: c6a24356699a25740ea82c5a50abe396c4bd4173be812d4682b6ce216bd1a3ae
                        • Instruction Fuzzy Hash: 289192B0E04209DFDF10CFA9D9A57DEBBF2BF88324F14812AD805A7254EB749945CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d2a3ac1bea5ab42a1e0180d7193a4ad6648baa70335a1d6a7f6b4e8e4b70d03e
                        • Instruction ID: 8b25ce6c0f4e67fa4b6af0e892aaaa46d016cdf58a5926c32c81df9c02eba8b6
                        • Opcode Fuzzy Hash: d2a3ac1bea5ab42a1e0180d7193a4ad6648baa70335a1d6a7f6b4e8e4b70d03e
                        • Instruction Fuzzy Hash: 55527274B501498BD744EFA5D465AAFBBB6FBC8740F548169E9069B388DF30AC02CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: e5f5b66281a557e2c6d2dca44177ebba072f5061505b7c18c861bfd565d4dd6f
                        • Instruction ID: 4a4b7c1bb486ab155aae3b478776a40d2af69cd8d2ec4f89343dfce152ec7694
                        • Opcode Fuzzy Hash: e5f5b66281a557e2c6d2dca44177ebba072f5061505b7c18c861bfd565d4dd6f
                        • Instruction Fuzzy Hash: 82523575A00118DFDB15DFA8C984EA9BBB2FF48300F1581A9E10A9B362DB71EC52DF50
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 2071c63ad986fc770f3cd841195be1569769f6f08f796c110afe65435da7643f
                        • Instruction ID: b7a958f42342cd9afd007bdccb326b701ef300d371960a9f7a8c1ba733d6206f
                        • Opcode Fuzzy Hash: 2071c63ad986fc770f3cd841195be1569769f6f08f796c110afe65435da7643f
                        • Instruction Fuzzy Hash: 1F328F74B00609CFDB14EFA5D855AAEBBB2FF88300F608569D5469B394DF30AC46CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9cc69e96555ec2819317b408408c352cdd105123a24867b55b4275639e668aa9
                        • Instruction ID: 8d9b690832756d74071927903deee5fa6ae4aa9c7f7071c79b8e4d68c46a09f6
                        • Opcode Fuzzy Hash: 9cc69e96555ec2819317b408408c352cdd105123a24867b55b4275639e668aa9
                        • Instruction Fuzzy Hash: 7F1291747501498BD744EFA5D4A5AAFBBA6FBD8740F54C129E9069B388DF30EC02CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b5e6789e463554aa195034bc4b56938a70b8454642a7d2b9e8247469b1d4ddc6
                        • Instruction ID: 7e6e98893ecdf420c8de872467101f7d84a9bda09e316b2e4c44fb9477a5db1a
                        • Opcode Fuzzy Hash: b5e6789e463554aa195034bc4b56938a70b8454642a7d2b9e8247469b1d4ddc6
                        • Instruction Fuzzy Hash: 25123574B1061A9FCB04FFA4E9A49AEB7B6FF89344F508528D506A7398DF30AC45CB40
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: e86a44f3eb6d4d64d0cc4c08f2d70c726527a865457c8759ea9fdca1c54cb0c2
                        • Instruction ID: 9a0e97881ed60a3e843ae4a6d3c4e16311ff06e420f75dde23e60a8b45ab9767
                        • Opcode Fuzzy Hash: e86a44f3eb6d4d64d0cc4c08f2d70c726527a865457c8759ea9fdca1c54cb0c2
                        • Instruction Fuzzy Hash: 00D19274B00A1A9FCB05FBA4E5649BE7BB3FFC9254B504119E4059B398DF306D46CB81
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: ad20a56ac4d63f13a5c74d2ca1cf590faf9f52d3380362268e760cd73a6b0bf8
                        • Instruction ID: f05cfe4ef41d69bf8f5a421f28d582371e5d7323ffd6d8f103ba919c8ae10e2e
                        • Opcode Fuzzy Hash: ad20a56ac4d63f13a5c74d2ca1cf590faf9f52d3380362268e760cd73a6b0bf8
                        • Instruction Fuzzy Hash: B7D1A274B0091A9FCB05FBA4E5649BE7BB3FBC9244B504119E805AB398DF346D46CB81
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: e04dcd22f543ef43199308b24c22e8fd2b03373f2ae0047bb842f0733918e730
                        • Instruction ID: 9161ec54194acb72c0e41094054c1d51f8618d143c00e4f591067febefa114ae
                        • Opcode Fuzzy Hash: e04dcd22f543ef43199308b24c22e8fd2b03373f2ae0047bb842f0733918e730
                        • Instruction Fuzzy Hash: 7ED15074B4060A8FD744EF24D4A4AAE77F2FB88740F1585B9D80A9B359DF30AD42CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3d52a756a62c8747215cd78be87a168c0a23c3e6dee89ce1e66592037e7d15b2
                        • Instruction ID: 483e00d754bfbc96c2a8545eb1f17b34de14a49ab5feccc4d9555dc898a80bfa
                        • Opcode Fuzzy Hash: 3d52a756a62c8747215cd78be87a168c0a23c3e6dee89ce1e66592037e7d15b2
                        • Instruction Fuzzy Hash: 5DC15174B4020A8FD744EF24D4A4AAE77F2FB88740F1585B9D80A9B359DF30AD42CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6ee243398b349a3bae331e45c3810fc82f6ce43ece897fe16f39b74a5e845af7
                        • Instruction ID: 2428655433885aacf4679490f547e33e9b731c966455999db611185edcb50a72
                        • Opcode Fuzzy Hash: 6ee243398b349a3bae331e45c3810fc82f6ce43ece897fe16f39b74a5e845af7
                        • Instruction Fuzzy Hash: D2B19E70E0020ACFDF50CFA9D89579EBBF2BF88314F258529D819E7694EB749841CB81
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3f761c1837ee34f392a233e7619df1486d7944c006ea2ebad11b311ec120e1ad
                        • Instruction ID: ca98ae664792a78e2a0e1ddcafc380b3a2a1eda2d9dc4ae00a2caf3e20cec72f
                        • Opcode Fuzzy Hash: 3f761c1837ee34f392a233e7619df1486d7944c006ea2ebad11b311ec120e1ad
                        • Instruction Fuzzy Hash: 08A15F7474050A8FD744EF28D4A8AAE77F2FBC8740F1585A9D80A9B359DE30ED42CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 8f1c7b0c99e4953844f9e158837e9f20b61e3c9cc1af6aa0b56c9d9875d84e9f
                        • Instruction ID: f66565c31a12df68026665043ca7c034ce169829c3ec78338e223458c9f3cd44
                        • Opcode Fuzzy Hash: 8f1c7b0c99e4953844f9e158837e9f20b61e3c9cc1af6aa0b56c9d9875d84e9f
                        • Instruction Fuzzy Hash: 78516CB0E41A4A8FD748EF6BF85469ABBE3BFC8300F54C56AC0059B268EF7558458F50
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9c75e46d3f1adeefa10d2b80716b1daef865d66e4fe169fd75824a608df1e506
                        • Instruction ID: 3026bd04026e483dad0eddfa185aba3cd22c09522c1c9baa009598566721c1ac
                        • Opcode Fuzzy Hash: 9c75e46d3f1adeefa10d2b80716b1daef865d66e4fe169fd75824a608df1e506
                        • Instruction Fuzzy Hash: 75514DB0E41A4A8FD708EF6BF86469ABBE3BFC8300F54C569C0059B268EF7558458F50
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: ,kq$,kq$,kq$,kq
                        • API String ID: 0-772104199
                        • Opcode ID: f42af8f2a4de16a21623325822dfe439aee97173ccc3142618a9a6414af15c28
                        • Instruction ID: 2269220f980c244f25cfc8bff86a14fa0b3a4601979358f83818fe41fd37b985
                        • Opcode Fuzzy Hash: f42af8f2a4de16a21623325822dfe439aee97173ccc3142618a9a6414af15c28
                        • Instruction Fuzzy Hash: 16626E74B5064A8FD758EF68E4656EFBBA2FBD4B40F508069D4069B388DF309C42CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562505141.00000000054F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054F0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54f0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3d02c64eb99ff33372b19a1b87e47f4a612d2e492a5d49e0a7a1bbd89d18b9ed
                        • Instruction ID: bda0011849465a8a35ecf97e7b72c6f931dc71562ba9729b13d07fbc42b984c4
                        • Opcode Fuzzy Hash: 3d02c64eb99ff33372b19a1b87e47f4a612d2e492a5d49e0a7a1bbd89d18b9ed
                        • Instruction Fuzzy Hash: E5638270FC02258FCB655A6D841C6BF79E7EBC8680F5495ABDA0ADB344DE708C81CB91
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: ,kq$,kq
                        • API String ID: 0-910951715
                        • Opcode ID: 44265d465fd99179e852b2ea04228a34ab81d4e4d2883e08b035d9ca54feae80
                        • Instruction ID: c3e32a5931dc26e4686c0916a23ccc4cab563d744bf4ad977f6c5afe7666c85f
                        • Opcode Fuzzy Hash: 44265d465fd99179e852b2ea04228a34ab81d4e4d2883e08b035d9ca54feae80
                        • Instruction Fuzzy Hash: 5132707475064A8FE708AF64E4696EFBBA2FBD4B40F508059E5079B388DF709C02CB91
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: ,kq$,kq
                        • API String ID: 0-910951715
                        • Opcode ID: 012c28db3f6097bf4d7515bf8b0e4544eaa6403599a85c9e3a12b3263106b004
                        • Instruction ID: 326329063f7b7b4d684dd06015a7dc782f75cb6e99b9f97a0ed71e7344760e5c
                        • Opcode Fuzzy Hash: 012c28db3f6097bf4d7515bf8b0e4544eaa6403599a85c9e3a12b3263106b004
                        • Instruction Fuzzy Hash: AC32717475064A8FD709AF68E4696EFBBA2FBD4B40F508059E5079B388DF709C02CB91
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: ,kq$,kq
                        • API String ID: 0-910951715
                        • Opcode ID: 048fa4f8c54f74e55b55f3b361cc12a4288dae40cfffa07f680848769cca6ad7
                        • Instruction ID: 539fd5a79a45ff57a05bdb40d427d58ea721181fdcb1edf5ce9e70db6185ed50
                        • Opcode Fuzzy Hash: 048fa4f8c54f74e55b55f3b361cc12a4288dae40cfffa07f680848769cca6ad7
                        • Instruction Fuzzy Hash: B732727475064A8FD708AF64E4696EFBBA2FBD4B40F508059E5079B388DF709C02CB91
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: ,kq$,kq
                        • API String ID: 0-910951715
                        • Opcode ID: c69661b0bb4558f86089504cda1c72fb6cf685baf2b7fcdff5ff14961ef310cc
                        • Instruction ID: 4b0971dbd5a564f524bdbf6406142831b4f1a922cff83c0c5c0d8174447c3e7e
                        • Opcode Fuzzy Hash: c69661b0bb4558f86089504cda1c72fb6cf685baf2b7fcdff5ff14961ef310cc
                        • Instruction Fuzzy Hash: 6B22627475054A8FD708AF68E4697AFBBA2FBD4B40F508069E5079B388DF709C02CB91
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: \V[n$\V[n
                        • API String ID: 0-3705941238
                        • Opcode ID: 21b11347f47c3bf14a746afd7bd38452c014aad4894ec33144e5ca071bd0b551
                        • Instruction ID: 5f3635bf5e7be8a8c2e38153d9b220e1387a8a4d9ca70ca34bb1b3c6b09a0f2e
                        • Opcode Fuzzy Hash: 21b11347f47c3bf14a746afd7bd38452c014aad4894ec33144e5ca071bd0b551
                        • Instruction Fuzzy Hash: B6715A70E00209CFEB54CFA9C881BDEBBF6BF88710F258529D815A7654EB759841CF91
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: \V[n$\V[n
                        • API String ID: 0-3705941238
                        • Opcode ID: 40bea730f2ea4aa1c54cf6aa04e042eabe5c252b30117de75cae1a68a2fcbb93
                        • Instruction ID: edbd31428dd381ffe3019b5afbd006739414be96101d3564020cea97463da99c
                        • Opcode Fuzzy Hash: 40bea730f2ea4aa1c54cf6aa04e042eabe5c252b30117de75cae1a68a2fcbb93
                        • Instruction Fuzzy Hash: FC717A70E00209DFDB50CFA9C881BDEBBF6BF88710F258529E818A7654EB759841CF91
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: \V[n
                        • API String ID: 0-1005319620
                        • Opcode ID: b86d90539bb50a352a662848a845d03d79b419a2a613702148fbf949a65275b1
                        • Instruction ID: 7309ef73932407521b25c41fa59363c54a68246ca6c0ac76395a91fcb155d372
                        • Opcode Fuzzy Hash: b86d90539bb50a352a662848a845d03d79b419a2a613702148fbf949a65275b1
                        • Instruction Fuzzy Hash: 64C1AE70E00249CFDB50CFA8C885BDEBBF5BF88304F25812AD814EB690EB749845CB91
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: \V[n
                        • API String ID: 0-1005319620
                        • Opcode ID: 12b91e8048842a85654d4d479398be8b000ef401aba88b2698d61283efe00d76
                        • Instruction ID: 41dc098da553c7ee580cb40fcab39b5e39b1554d8b874d48ea0b3ae3a3f1fbb6
                        • Opcode Fuzzy Hash: 12b91e8048842a85654d4d479398be8b000ef401aba88b2698d61283efe00d76
                        • Instruction Fuzzy Hash: 509192B0E04209DFDF10CFA9D9A57DDBBF2BF88324F14812AD809A7254E7749945CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562505141.00000000054F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054F0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54f0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: ca296c98077aac338b060c1b759b7107330f95dbe02554adbf4872fb6387cfd7
                        • Instruction ID: 28f131a584dc3f2c12c841d096951f4d7e3c591edc42465f8afbb6863d49f225
                        • Opcode Fuzzy Hash: ca296c98077aac338b060c1b759b7107330f95dbe02554adbf4872fb6387cfd7
                        • Instruction Fuzzy Hash: 0EB27D30F80101CFD7549B6AC85C7ABBABABFD4345F9084AEE20697294DB718D91CF61
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: H
                        • API String ID: 0-2852464175
                        • Opcode ID: 06043011e14663346bed1f9a21c9fa4316ae6fc82ffae14243c472f0b93b9cc2
                        • Instruction ID: 7fcfc926e65f0ca78f3b74bb9a7d34a504a6c9982a797be854b67f6dbc1ed8da
                        • Opcode Fuzzy Hash: 06043011e14663346bed1f9a21c9fa4316ae6fc82ffae14243c472f0b93b9cc2
                        • Instruction Fuzzy Hash: ACF08172604208BBDB00DEA4DC40FEB7BEDDB85220F4484AAAD08C7241DA75DE15A7B1
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: y
                        • API String ID: 0-4225443349
                        • Opcode ID: 7adf441a6ec8fbdd7a87fb3ec7b6efc11ced017c72aefee12e246ed74790dd13
                        • Instruction ID: e19a84148a32711aa75d201445017779096b26acd680dbad71e739c7834393ec
                        • Opcode Fuzzy Hash: 7adf441a6ec8fbdd7a87fb3ec7b6efc11ced017c72aefee12e246ed74790dd13
                        • Instruction Fuzzy Hash: 81D0126162400447E344C614CD977C67BC5EB91249F68C4688889C6292DB25D9038795
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b3cd9bab3525b37a8d63ad6d6fc7f88261b6fb585f7e0e613539115bcabb562b
                        • Instruction ID: 09d3d505246b3516dc1838e17196cfa5aeb7182b3b5c842c8b60728ad01bc9b8
                        • Opcode Fuzzy Hash: b3cd9bab3525b37a8d63ad6d6fc7f88261b6fb585f7e0e613539115bcabb562b
                        • Instruction Fuzzy Hash: E382E974A002299FDB55DF68D894BEEBBB2FB88300F518199E509A7354DF30AE85CF50
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 34439fa6468921aee3c1159382dce1cd1759174ceb84a40aefc6fcece13adf1a
                        • Instruction ID: 19bdb4a254128ea2568dd3ce6a21661725c1baf52f2630ce267a459b681b5816
                        • Opcode Fuzzy Hash: 34439fa6468921aee3c1159382dce1cd1759174ceb84a40aefc6fcece13adf1a
                        • Instruction Fuzzy Hash: F5124C30A00606CFDB65DF79C450A9EB7B2FF84310F658A6DD8069B7A5DB75E842CB80
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 8e72675315b5a56aa679ea4c77404e8aad049d19c11b73d7a8d7f52cc7f68188
                        • Instruction ID: 76f1e0ea243f23053c34126dfd8222956a297aaafda697ba4cd6cf64bef5716b
                        • Opcode Fuzzy Hash: 8e72675315b5a56aa679ea4c77404e8aad049d19c11b73d7a8d7f52cc7f68188
                        • Instruction Fuzzy Hash: F80290703405068BD705EF69E4646BFBBE6FB8A640F949679E542DB3C4DE349C02CBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d2bca82c8744a753213cb32c5e9420cdaed94a5c43d5b60b7ce9207b99011b61
                        • Instruction ID: 016dd925c732d0cf21b878f39bdc467bf510d584a13cb92cc0c0dbe257a4ee29
                        • Opcode Fuzzy Hash: d2bca82c8744a753213cb32c5e9420cdaed94a5c43d5b60b7ce9207b99011b61
                        • Instruction Fuzzy Hash: F0E14374B1061A9FCB04FFA4E9A59AE77B6FF89344F508129D406AB398DF30AD45CB40
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a2d9a368d4f6ef7d19364963263b4598aa5dd3b2eb79727621ed4f7326389c72
                        • Instruction ID: b261156b9a2e50c85158ae6fe9d047d2982c475bf37f29e68acaa2e079754a95
                        • Opcode Fuzzy Hash: a2d9a368d4f6ef7d19364963263b4598aa5dd3b2eb79727621ed4f7326389c72
                        • Instruction Fuzzy Hash: 18E14F74A001299FDB55DF64C854BEEBBB6FB88700F118199E509AB394DF30AD85CF90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562505141.00000000054F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054F0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54f0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: fa2035d16d4a2eadeb8540a3ecc5d197f1756355039c12f23c78779003e85d36
                        • Instruction ID: f23e746cfd6dd02794aaf002e708ac205a8e2b1e976e266c71cf55ce7bee5e75
                        • Opcode Fuzzy Hash: fa2035d16d4a2eadeb8540a3ecc5d197f1756355039c12f23c78779003e85d36
                        • Instruction Fuzzy Hash: A0B1D034BC06028B8B15AB29E46C5BF77E3FFCA690B94855ED606C7788DF30D8528752
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d233ce640e1707059a19e432cc45218e77bab43535daac891a371f95aa0a0857
                        • Instruction ID: a36bdd4ea9d03fcc7b6119d740ff58b276a762b8848b84405913bb36e2550d7f
                        • Opcode Fuzzy Hash: d233ce640e1707059a19e432cc45218e77bab43535daac891a371f95aa0a0857
                        • Instruction Fuzzy Hash: 5FB1B170A006059FD714DF69D494ADEBBF2FF89310F1585AAE405AB3A5DB70EC42CBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c53141bd87bbc98a1c4259cc6fcb5bd9b2f7137460aa49842d59d6b16f442319
                        • Instruction ID: e412f84700266d391273d3aba8aa6383acae0e04d1bcf9dc99445e44e7ef6dd9
                        • Opcode Fuzzy Hash: c53141bd87bbc98a1c4259cc6fcb5bd9b2f7137460aa49842d59d6b16f442319
                        • Instruction Fuzzy Hash: 6CB18D70E0020ACFDF50CFA8D8857DEBBF1BF88314F258529D819AB654EB749845CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 90abc58f9587b7dc43f596068e1b5b4cbf775d8bf09f08b5384d1c55688e63be
                        • Instruction ID: 64c2bc42dc5e6663a049a47b6174512f75608bd1c7aa91bae54e4338efb8170e
                        • Opcode Fuzzy Hash: 90abc58f9587b7dc43f596068e1b5b4cbf775d8bf09f08b5384d1c55688e63be
                        • Instruction Fuzzy Hash: 08A19D74A002059FCB19DF69D494AAEBBF2FF88310F1581AAE515EB365DB31EC41CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 68142207bb7e84f39855fd3b42a396b66c8de1edecbb2ff9385bd4895f159e64
                        • Instruction ID: cb642658ab293ea863617b1faa90bfbfc64adf907b7d67c2acdae87a2caa5df4
                        • Opcode Fuzzy Hash: 68142207bb7e84f39855fd3b42a396b66c8de1edecbb2ff9385bd4895f159e64
                        • Instruction Fuzzy Hash: 3D31E5306003418FD365DB6CE440A9ABBE6EFD5320B59C66ED4868F3A1CB30D94A87A0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: add1fe3b9e793447fecae54be8c42a18cad0301ffe4ee7c3e5948af99d0aed77
                        • Instruction ID: b970b4451a741fb3fb2e988d6272819b5d09993ad7ea06317a5ae6fb5c595ce4
                        • Opcode Fuzzy Hash: add1fe3b9e793447fecae54be8c42a18cad0301ffe4ee7c3e5948af99d0aed77
                        • Instruction Fuzzy Hash: 3AA16D79B00619CFD715EFA5D4949AEB7A6FF88750F148129E8069B398CF30ED42CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 8086398f1d8c9bfc0239b205b0efc3b5947aec4f376fd207a51f4e44384cf1a2
                        • Instruction ID: 83800c9c76534c943bf35240aa26931db10f457b3cf62c107a059bfdcbbb5437
                        • Opcode Fuzzy Hash: 8086398f1d8c9bfc0239b205b0efc3b5947aec4f376fd207a51f4e44384cf1a2
                        • Instruction Fuzzy Hash: 68F04C36B04004AFDB097FA4A424BBE6753FFC8370F648166EA0A9B384CD395C028791
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: f0f9f30067f4469bd45ca9803fd6e907a067763fcff0bc94ba0f97c476100f99
                        • Instruction ID: b6cbf1664e903ce1060957985724ad7a1f180c00b1455159799115791047ede0
                        • Opcode Fuzzy Hash: f0f9f30067f4469bd45ca9803fd6e907a067763fcff0bc94ba0f97c476100f99
                        • Instruction Fuzzy Hash: 3C919374B1051A9BCB05BB64E5785AEB7B3BFC9344F10812AD806A73E8DF749846CB81
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: cc8058917a73f23948857c0e144f107cfde3437737eb0b11bf955deccaa78d00
                        • Instruction ID: 6f4b6636dca4ad36724238a5eb6af7e353e55517f514b0a7d71cb42f8c7cae60
                        • Opcode Fuzzy Hash: cc8058917a73f23948857c0e144f107cfde3437737eb0b11bf955deccaa78d00
                        • Instruction Fuzzy Hash: ADA14F74B4025A8FE754EB68E4657EBBBA2FB85640F508069D50ADB348DF309C41CBA1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 0594c8c523d0590a6013bd0ef8d12b4ef966dfd9a21d174687ef85c3ae5c16cf
                        • Instruction ID: 26f0674784e3cab57e4c7183741cbc4a29ebe4f1021579e8ee1ab2fb0fb0cf2b
                        • Opcode Fuzzy Hash: 0594c8c523d0590a6013bd0ef8d12b4ef966dfd9a21d174687ef85c3ae5c16cf
                        • Instruction Fuzzy Hash: 2E911B34A00105DFDB54CFA9C594AADBBB6FF88300F2585A9D805AB361CB31EE42CF50
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 0f44f567ae01858b1ed74f3930fe6bf1081dc96c0429fd14ce7deeccc25b4c6a
                        • Instruction ID: 82829ee40db2312077ebc897faf3f6904d3b355b308e442201e7192af7e5f836
                        • Opcode Fuzzy Hash: 0f44f567ae01858b1ed74f3930fe6bf1081dc96c0429fd14ce7deeccc25b4c6a
                        • Instruction Fuzzy Hash: 05913D74B4025A8FE754EF68E4557EBBAA2FB95700F5080A9D40ADB348DF709C42CF51
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 0780e298efb36b7f99ea03ccd805a9726ce8ee878a8969695fda253a9ab61577
                        • Instruction ID: decdc0a9584ad2fc4e18ca12d490d1f09ddefa6e0e871b3692ca97876498581a
                        • Opcode Fuzzy Hash: 0780e298efb36b7f99ea03ccd805a9726ce8ee878a8969695fda253a9ab61577
                        • Instruction Fuzzy Hash: 3471D3743545458FD748AFA8D8696AF7BA7FBD9A00F549029F107DB389CE309C02CBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 348aad4ce58d3770b043a0001a8a5c030a83f8a7444198eb21e9d9cf411b9e2d
                        • Instruction ID: 46d8a8e04d053a2b06feda53263c70ff6108a1b02065bf5c442026baa88fecd8
                        • Opcode Fuzzy Hash: 348aad4ce58d3770b043a0001a8a5c030a83f8a7444198eb21e9d9cf411b9e2d
                        • Instruction Fuzzy Hash: 0471B374B1091A9BCB05BB64E5785AEB7B3BFC9344F10812AD806A33D8DF349846CBD1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562505141.00000000054F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054F0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54f0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b079f738d6dd3c2bb7c57fc3567f5ca008b0d5622614a33963e3e08c1ac70b79
                        • Instruction ID: 71de51776a07e4d20d602c2e94473e8941509267500f194c3b3df81d93ada132
                        • Opcode Fuzzy Hash: b079f738d6dd3c2bb7c57fc3567f5ca008b0d5622614a33963e3e08c1ac70b79
                        • Instruction Fuzzy Hash: B6518D30B403404BC7A4DE1AC8D8B6BF7AABFD9601BC4897E9A0287755CF75A8198752
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562505141.00000000054F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054F0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54f0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3cb3e4cd298c1447544cc25fff5f611182cb88f51f90e41cae3ea66b705968c8
                        • Instruction ID: 41b67a6c0958bf9a407aa6de42fbecb2b4d34a50a81a5accf882df83f7f9c5ee
                        • Opcode Fuzzy Hash: 3cb3e4cd298c1447544cc25fff5f611182cb88f51f90e41cae3ea66b705968c8
                        • Instruction Fuzzy Hash: 4B516E30B403004BD7A4DE5AC8D8A3FF7AABFD9601BC4857D9A0787754CF75A8198752
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 7f711d5fbaa53864e61178d45886587e78cc9ba89b3b0ebf26a891f0ab3dac3f
                        • Instruction ID: db4a5bd844f3f11396e40a10dbfc3225b33776ab097183157d8fbb4d0e31f5b1
                        • Opcode Fuzzy Hash: 7f711d5fbaa53864e61178d45886587e78cc9ba89b3b0ebf26a891f0ab3dac3f
                        • Instruction Fuzzy Hash: 01614836B0010A9FCF45CFA8D8409EEBBF6FF88214B55812AE905E7660DA36D911DB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 23e3f93b078f0959211faa0994fd48e19e487562cd9a36bf21398825fb54de26
                        • Instruction ID: 72871bdf8927a240e04b2da2575518d3e9866d06da59be4ba52e60644f9da8b2
                        • Opcode Fuzzy Hash: 23e3f93b078f0959211faa0994fd48e19e487562cd9a36bf21398825fb54de26
                        • Instruction Fuzzy Hash: 8C71AE74A006059FCB14DF29D5949D9BBF2FF88310B6585A9E416DB3A1DB70EC41CFA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 86066b7b6735451d8722ea8db20df1f7b3a27b6b6d431de47cf49a623bdcc002
                        • Instruction ID: 8e7ccf825a9d6e79a34ac10fa7f4423cb9dcd5db3bf86ad0ea5ccd708fb461fa
                        • Opcode Fuzzy Hash: 86066b7b6735451d8722ea8db20df1f7b3a27b6b6d431de47cf49a623bdcc002
                        • Instruction Fuzzy Hash: C9617A74B002498FCB48DF78C4A8AADBBF2BF89714F2144A9E506DB3A5CB759C41CB51
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 79367a9b899623eb2681f6c7850923b81de4da64e50287eec24fb715571c5cfa
                        • Instruction ID: f48bdec262bc16ecac5b51b10e4205b48375bc87ebd17b731258a0a6bfb936a5
                        • Opcode Fuzzy Hash: 79367a9b899623eb2681f6c7850923b81de4da64e50287eec24fb715571c5cfa
                        • Instruction Fuzzy Hash: F2519179200204AFDB49AF98D915D6A7FB3FB8C3507098094E6468B376CB36DC12DF51
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 85301712b9a9373f4c1070b3fb1c23b71ba6ecf164a8ff38f8058e10065293f7
                        • Instruction ID: 160dba388fd1a66ea256cfd1c0024df0d4c56f81313e6a991da347a47b40fb17
                        • Opcode Fuzzy Hash: 85301712b9a9373f4c1070b3fb1c23b71ba6ecf164a8ff38f8058e10065293f7
                        • Instruction Fuzzy Hash: 4E51D530A9414A9BD704AFA8E865AEFFBB7FFD9740F508119D4469B358CE306C06C7A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 95bab1c1099d9c91f1e370c66c881554272bbedaa80850ac11a668941bd259dc
                        • Instruction ID: 90475f5eee400b46b1102c53111317e3529dcb3f1b33d320ad49901a81dab655
                        • Opcode Fuzzy Hash: 95bab1c1099d9c91f1e370c66c881554272bbedaa80850ac11a668941bd259dc
                        • Instruction Fuzzy Hash: E21133707442598FDB06EF28D8247EE3BB2AF8A700F11055AD841AB385CF755C09CBA9
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 389a872d069eb919d3a11ed08338de68515f335f26d5c59eb42edbeb013fd59c
                        • Instruction ID: 4341ee0efbbcace4e0b57dbcbb11471416396582a8e61b0c71325f2c86c4e97d
                        • Opcode Fuzzy Hash: 389a872d069eb919d3a11ed08338de68515f335f26d5c59eb42edbeb013fd59c
                        • Instruction Fuzzy Hash: 7051B874B446058FE704EF69D855BEFBBE6FB88710F148169E6069B348CF70AC058BA1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 7936ddccb85ad07bf90f90c213723562ff0f0a2c068f81976b9eb687df43c99e
                        • Instruction ID: de7e31edef10df90b2d58f1d8acf4a50dbfd0bbb2a120efe9b36ee2960ce07bb
                        • Opcode Fuzzy Hash: 7936ddccb85ad07bf90f90c213723562ff0f0a2c068f81976b9eb687df43c99e
                        • Instruction Fuzzy Hash: 04513874B001499FCB48DF69C498AADBBF2BF88714F214069E506AB3A5CB759C41CB51
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: f71350ef5804bff627d1d4b4a35c4b055e1ba71fe0c9dfcadc668b1e955859c1
                        • Instruction ID: 728e2f92170640778f86daf94ed6eecda875e74aaa348813a4456ead3c267bd2
                        • Opcode Fuzzy Hash: f71350ef5804bff627d1d4b4a35c4b055e1ba71fe0c9dfcadc668b1e955859c1
                        • Instruction Fuzzy Hash: 4C515C79200104AFDB49AF98D919D6A7FA3FB9C3507198098E6069B379CF32D812DF91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: eb3e41d3ae8468b063dbe309f3229aef983a33c6c2b1dfc3f95f43dc5e749747
                        • Instruction ID: 403889051f3dd9392c5c94ba5c753ea0b88c7c2e03ab6fd392f0e6c4fb47d6b1
                        • Opcode Fuzzy Hash: eb3e41d3ae8468b063dbe309f3229aef983a33c6c2b1dfc3f95f43dc5e749747
                        • Instruction Fuzzy Hash: 02511874A402588FDB64DF64CC55BD9BBB1FB89310F5080D6E909AB394DA30AD85CF60
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 09c326a99f90c6065c48fa655a492cb1775e9ff25f679a2929b96bc10215a370
                        • Instruction ID: bf55e1cefec8fb3129a3cc55d6fe7ec12d228a077634dcf7873528d1de4fcec3
                        • Opcode Fuzzy Hash: 09c326a99f90c6065c48fa655a492cb1775e9ff25f679a2929b96bc10215a370
                        • Instruction Fuzzy Hash: 5E519134A9010A9BD704AFA8E4659EFF7B7FFD8740F508129D446AB348DE306C06C791
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: cb2eb89392d544111bf0701ba5c87595bb965c6256b775aea8d020b4666d18f2
                        • Instruction ID: 24b3e38d84fb422c00f29c6444be8290402c8c97c146259e70efdb2b45b6c98e
                        • Opcode Fuzzy Hash: cb2eb89392d544111bf0701ba5c87595bb965c6256b775aea8d020b4666d18f2
                        • Instruction Fuzzy Hash: 4D517E7471010ADFD704EB65E4B5AAE77B2FB88654F10852AD8069B748DF30AD06CBD1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 837c7ff02e89d697f19ca903e567a88741029d70be2e784b7e1c154b274087b9
                        • Instruction ID: be3e017710ccfdb0710e7521d62d86ad55906278b76771c8373d1b3541036945
                        • Opcode Fuzzy Hash: 837c7ff02e89d697f19ca903e567a88741029d70be2e784b7e1c154b274087b9
                        • Instruction Fuzzy Hash: EF41947074061B8BE718AF74E465AEB7AA7FBD5B40F158069D4079B348DF709C02CBA1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: ec218872096d8f3fa47efa2a66a71a10e758c3151fe0a46cf04c79ac9d168069
                        • Instruction ID: 161eaf3a5c6eeadf78179d688ca633099dcd963c6f799e01c31a1510b37ec4ad
                        • Opcode Fuzzy Hash: ec218872096d8f3fa47efa2a66a71a10e758c3151fe0a46cf04c79ac9d168069
                        • Instruction Fuzzy Hash: 9B519C74B5010ADBD704EF65E4B9EAF77B2FB88690F508529D8069B748DF30AD02CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6815964d695d3efab8b97a9df4dc30f0a2bdac30a1571c33cddd2a59673197dc
                        • Instruction ID: 70344bab887ac5150131284309e304d14f517cfcc5e431350bf64d747f6683af
                        • Opcode Fuzzy Hash: 6815964d695d3efab8b97a9df4dc30f0a2bdac30a1571c33cddd2a59673197dc
                        • Instruction Fuzzy Hash: 1C4112306002099FC744EF79D494AAEBBB6FF85304B14856AE919CB355DF31EC06CBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 299453b1390668d7858da5fc8641f5a61aa7c807747a8b166eefa81550259442
                        • Instruction ID: 1a28c2ef78114621808725abf1fd09bc1ae183666e2a4c8b8ea0e2b6bddf69a5
                        • Opcode Fuzzy Hash: 299453b1390668d7858da5fc8641f5a61aa7c807747a8b166eefa81550259442
                        • Instruction Fuzzy Hash: 13514A30A10204DFDB65DFA9C584AADBBB6BF88310F258568D805AB295CB31EE42CF50
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6730652864e986a590cbfd2a2ed380f2d6b482f8ac37898fa2a027bc7f4d4f1b
                        • Instruction ID: d5dcb0d70cc2b37842eb7f8c70a760811c2ebe2a0fef0008a41c191eb0d347a9
                        • Opcode Fuzzy Hash: 6730652864e986a590cbfd2a2ed380f2d6b482f8ac37898fa2a027bc7f4d4f1b
                        • Instruction Fuzzy Hash: 3941B374B00606CFD714EFA9D4959AFFBF6FB88610B14852BD91AD7744DB34A802CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3a48e4bd87a8097856c7d358ac3ca7e918b50f9e25eb0a05602ecdf9f0f68243
                        • Instruction ID: b5d4b19eceefca3a166924d79e4083bc662c25df2a5a9ce416075482404459c3
                        • Opcode Fuzzy Hash: 3a48e4bd87a8097856c7d358ac3ca7e918b50f9e25eb0a05602ecdf9f0f68243
                        • Instruction Fuzzy Hash: D5515074B4020A8FD744EF68D4A8A9EB7F2FB88340F1585B9D40A9B355DE309D82CF90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: e2a5c7b9c83ba652357746146166431ca994ddbf77605091984a66f23176ffec
                        • Instruction ID: c8f45db4034d6f91155b8b52b8f4c35570b66bca497b0c1b0c3faf0fd9c855a6
                        • Opcode Fuzzy Hash: e2a5c7b9c83ba652357746146166431ca994ddbf77605091984a66f23176ffec
                        • Instruction Fuzzy Hash: 2A514F74B4021A8FD744EF68D4A8A9EB7F2FB88740F1485B9D40A9B355DE309D82CF90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 5be8f2c94db083a34c750f4362fe1207455f1c90d45bedc10b3085487b1b8ed0
                        • Instruction ID: 64ce3389a563085db3bdf51149ffa636d3e8a6bfed36b9c393f4566d215a7646
                        • Opcode Fuzzy Hash: 5be8f2c94db083a34c750f4362fe1207455f1c90d45bedc10b3085487b1b8ed0
                        • Instruction Fuzzy Hash: 9A41E030A002099FC744EF69D494AAEBBA6FF85300B54C569E919CB355DF71EC06CBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: f2ee7bc2e0f4bfe65bc957a37efcca90252bb4e670dbb98d3eed6c401ae794a8
                        • Instruction ID: 9d0c94f9cadf8ca520b5edf49915129dcead3d94d97349c6ec11c3b06eee7501
                        • Opcode Fuzzy Hash: f2ee7bc2e0f4bfe65bc957a37efcca90252bb4e670dbb98d3eed6c401ae794a8
                        • Instruction Fuzzy Hash: D941CE757401049FDB06AFA4D859AAFBBE7FB8C640B048059E606A7394CF319C02CBA1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 91d6bb98f38df42995f67fe7f6721ed4f2d66d2a24ec66817a8769465c52a55a
                        • Instruction ID: fb8883785ac863b8dccc88f8d8bafe33882692e4b4f1e301c3fcf0af3c10c80d
                        • Opcode Fuzzy Hash: 91d6bb98f38df42995f67fe7f6721ed4f2d66d2a24ec66817a8769465c52a55a
                        • Instruction Fuzzy Hash: 41319275700119AFCF04EF94E894AAE7BB6FF89354F158024EA069B394DB30EC11CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d477661956e1c9fb996444d9aeb92262b90a7b3abaad3791f65d9ca110033252
                        • Instruction ID: 3ab7d7c2c0e18ea425c9cf3a7332f4b4eda5a68149d42907063df80aac05f072
                        • Opcode Fuzzy Hash: d477661956e1c9fb996444d9aeb92262b90a7b3abaad3791f65d9ca110033252
                        • Instruction Fuzzy Hash: C441DF757401099FDB45EFA8D859AAFBBE7FB8D740B048059E6069B394CF319C02CBA1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 2b1e223269d4a4d3db188c67a3e0a34849f5eb1e88c34bac06071739b0e8246e
                        • Instruction ID: c3b084b7e9ba02ff3163865c23a1429eedd16a593df1a70e7dbf732ee6c15391
                        • Opcode Fuzzy Hash: 2b1e223269d4a4d3db188c67a3e0a34849f5eb1e88c34bac06071739b0e8246e
                        • Instruction Fuzzy Hash: EC315A74B0021ADFCB00EFA9D4959AFBBF6FB89350F108169DA0697385DB349D06CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a44db06b8521959a4029778daae105e87600e4922c59fcf8e61dfbe1f6fcb6ee
                        • Instruction ID: 6cb4a85c529e23438a9462ae3a29ff6b6e0cba0097d02788103492b1a2a6a6bf
                        • Opcode Fuzzy Hash: a44db06b8521959a4029778daae105e87600e4922c59fcf8e61dfbe1f6fcb6ee
                        • Instruction Fuzzy Hash: C1313C317093D04FD356D779841479A7FE5AF82364F5981AED889CB393CA6A8C07C3A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6d25c87e3edb2886df400e7d70614b597449166a87df64792947b3e9881c6475
                        • Instruction ID: 70bc5e5aaebefb9b3fdf29d9cd09ba292cd266e0a8c1bb7a7b7d2950a21fe088
                        • Opcode Fuzzy Hash: 6d25c87e3edb2886df400e7d70614b597449166a87df64792947b3e9881c6475
                        • Instruction Fuzzy Hash: 7031F4306043459FD741EF79D8619EEBBB1FF86304B00856AD555CB252DB30AC0ACBA1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 7013a0849836e1c744cddb2eb39ba480d946ce4d253ef078b5b832d3be17c9d2
                        • Instruction ID: 10df1309c244e75288f1a1b9d2a47541b2514d166ca05b5bce9bba187126660e
                        • Opcode Fuzzy Hash: 7013a0849836e1c744cddb2eb39ba480d946ce4d253ef078b5b832d3be17c9d2
                        • Instruction Fuzzy Hash: B7314B72A00059AF8F028ED59C50CFFBFBEFB4D251F044066FA55E2150DA36DA25ABB0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: e3aabd1e90d0e80149d8a76a8ad201c7044295ecd64a5a5967dbaf5ae7c8ae08
                        • Instruction ID: 8e10e8dde8902bd188c9d35eac40da9bf9760ca927f8f2f4a17690628a5475cd
                        • Opcode Fuzzy Hash: e3aabd1e90d0e80149d8a76a8ad201c7044295ecd64a5a5967dbaf5ae7c8ae08
                        • Instruction Fuzzy Hash: 9541FFB0D00349DFDB10DFA9C895ADEBBF5BF48310F14802AE919AB210DB75A945CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 251783637540ef3e22a41658e6b914f08f5f0a8b970661502614b830c900f44f
                        • Instruction ID: 6e3ee2d0a85ef842a04832fba31be650044e473467bcc0c1f6bb91938373e8e5
                        • Opcode Fuzzy Hash: 251783637540ef3e22a41658e6b914f08f5f0a8b970661502614b830c900f44f
                        • Instruction Fuzzy Hash: 0F3163B46506068FD704FB69E86569FBBE6FB88740F408129E14687744CF70AD02CBA1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: e6c1e65d0840579cd71c55a45a1fc7a99c2f17e1c03a369a9450d2461fb74051
                        • Instruction ID: f9d20df8dcb81b1bf547af3d2de0614310d2f1ffa5b92195c2b128895db8a2ea
                        • Opcode Fuzzy Hash: e6c1e65d0840579cd71c55a45a1fc7a99c2f17e1c03a369a9450d2461fb74051
                        • Instruction Fuzzy Hash: 1541EFB0D00349DFDB10DFA9C895ADEBBF5BF48310F20806AE919AB250DB75A945CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a4d1918e1053e53b9b4a0682f863879593872f9010c112c306acda20b0dabd05
                        • Instruction ID: e212b6ee17ea42b3bf7912158608021318309630339f083ff320f8b33b98400c
                        • Opcode Fuzzy Hash: a4d1918e1053e53b9b4a0682f863879593872f9010c112c306acda20b0dabd05
                        • Instruction Fuzzy Hash: 86314E34F10219DFDBA8EBA4E864AAE77F6BB88640F15452ADD01E7744DF309C05CB92
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 81b6b12c3286b0e32bc1ad80a8bb467411c7ab692882331c4c4418eec4613ff4
                        • Instruction ID: 15942e7ed41735c153a0c3979efd5dae6276eb4762624204786f7329bad7656e
                        • Opcode Fuzzy Hash: 81b6b12c3286b0e32bc1ad80a8bb467411c7ab692882331c4c4418eec4613ff4
                        • Instruction Fuzzy Hash: 2A31B275A401499FDB09AFA8C8555EFBBB7EBC8620F14C119E516A7388CF305802CBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 31cfce7f478017506fd862bab317ea78295846be6e8018fcd04ea6595e55aeb2
                        • Instruction ID: 6c44634951b6e5d9f693b8bbbad0aa2f011d1caeeb379bf9cd39ae5b842646d1
                        • Opcode Fuzzy Hash: 31cfce7f478017506fd862bab317ea78295846be6e8018fcd04ea6595e55aeb2
                        • Instruction Fuzzy Hash: 92319330E50209DFDBA4EBA4D854BAEB7B6FB88740F15452ADD01A7744DF309C05CB92
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c9ec1895f02951c7cc7e146d0b35efd1136d47d872d8424d9fcebab634b21bab
                        • Instruction ID: 22d662e6697851ef36c741ec8e6394c6e41ee2ea4a26b56f0e52ab07823e8e83
                        • Opcode Fuzzy Hash: c9ec1895f02951c7cc7e146d0b35efd1136d47d872d8424d9fcebab634b21bab
                        • Instruction Fuzzy Hash: 5921AB7530414AAFDF46AF5AD851ABA7BAAFBC9210F448015FA05C7394DF35DC11CB60
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 013c06a3919a03c8e26c5313939176d9f93d111c7b47147f15ac99c6389d7721
                        • Instruction ID: 2a9b779f1c61e781b7a6529fe1c1b24cd5d07ee31ab668be4d22d0fae22ccace
                        • Opcode Fuzzy Hash: 013c06a3919a03c8e26c5313939176d9f93d111c7b47147f15ac99c6389d7721
                        • Instruction Fuzzy Hash: 2831897430818AAFDF46AE5AD850ABA7BAAFB89200F048055FD55CB390DE31DC11DB60
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b8cfb04e6e2dda4b726b5ddcb4912ca025f9bab3116502034d347c2288846147
                        • Instruction ID: 0eb8ae3ae40ea18a4caea7f781ccaf16380e11e65006385fab24da2c09855f31
                        • Opcode Fuzzy Hash: b8cfb04e6e2dda4b726b5ddcb4912ca025f9bab3116502034d347c2288846147
                        • Instruction Fuzzy Hash: AF217F76600119AFCB059F94E894EABBBB7FB88310F054069E6069B3A5DA31E811CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: be78ebc65705c348b6331e1e61597d343ff974373c3fb2c178547b5810bd1768
                        • Instruction ID: b1c85627c9d62a4193cc33569541108a6ba4c763f3be879f127fa52b1640c5fc
                        • Opcode Fuzzy Hash: be78ebc65705c348b6331e1e61597d343ff974373c3fb2c178547b5810bd1768
                        • Instruction Fuzzy Hash: 2C21F774B402449FEB14AF69C856BEF7BE6EBC8750F148069E906D7384CE7488068BB1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: ad9be1f0f063a9480d142df18ded596b30c612991273e9cc581a393b07e9a3e8
                        • Instruction ID: 50d39dc3aa88869bf78b22d4938bae74c53f40e62f51caa0061c86270300f5f6
                        • Opcode Fuzzy Hash: ad9be1f0f063a9480d142df18ded596b30c612991273e9cc581a393b07e9a3e8
                        • Instruction Fuzzy Hash: 213182756505499FD709EF98D8295EFBBB7EBC8610F14C119E516A7388CF706C028BA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562505141.00000000054F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054F0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54f0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 37acbf4919ef004bf9d1fb825b29dd3b18723701d51428f96cdcaa6c792c5fb8
                        • Instruction ID: f446e02632fceb2ace09db1b916cdca796feabba45bb7e7c41d1d217f7968a53
                        • Opcode Fuzzy Hash: 37acbf4919ef004bf9d1fb825b29dd3b18723701d51428f96cdcaa6c792c5fb8
                        • Instruction Fuzzy Hash: 472124B1F482589BCB264B28DC197FA7B76FF45319F0505ABE605AB381C6788881CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3df1ed7e4368574b731f0c60d662f3cd40e53d129804feef5bde501e89458fd9
                        • Instruction ID: f3fe0b80471b33a286f41e0a0ef3fb0e2cc574aad1f627e9f00f7daf1dabc86a
                        • Opcode Fuzzy Hash: 3df1ed7e4368574b731f0c60d662f3cd40e53d129804feef5bde501e89458fd9
                        • Instruction Fuzzy Hash: 7E21C774B442449FE7149E69D855BEF7BE6EBC8640F148069EA06C7384DE748C06CBB1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 1a15dc030e3cb53346025a2d3e0abb956eb73bbf685ecc359745a0ba660722b1
                        • Instruction ID: 1a8aad540f33c25a849197a30de913eb082849aa813ec2588dd5744424439519
                        • Opcode Fuzzy Hash: 1a15dc030e3cb53346025a2d3e0abb956eb73bbf685ecc359745a0ba660722b1
                        • Instruction Fuzzy Hash: 4401DB379001299FCF059F94D814DD9BB76FB89310B0684A0EA057B265D772F925EB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9f8ea82b26bfee72bb3a8403ef27d36e1f0366fd3cf5662c77ef8e322eabb4b4
                        • Instruction ID: de9415f527fe3797c19d43a79316e9cb60dcf9e9da23ef8dae04df4a567c9457
                        • Opcode Fuzzy Hash: 9f8ea82b26bfee72bb3a8403ef27d36e1f0366fd3cf5662c77ef8e322eabb4b4
                        • Instruction Fuzzy Hash: BC31C678B11609DFEB04DF94E4D5AAEBBB2FF89710F144059E802AB354CB70AC41CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: df19c818b262b6b104ceb553107331a279523e0b2feccebd61cf20bbe16f5a45
                        • Instruction ID: a01746c54363bd4bdeb23a5883ff2770c8246a76a8cbd13da033ba81e3806faa
                        • Opcode Fuzzy Hash: df19c818b262b6b104ceb553107331a279523e0b2feccebd61cf20bbe16f5a45
                        • Instruction Fuzzy Hash: C01127317002029FC705DB6DD8A4F5ABBE6EF88360B11406AE516CF354EB71EC408B90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3e4f74acf0c33e10f9e56486c44c1982331ed5bcae49f4c4ab8dd5964c2bff69
                        • Instruction ID: 9490bf759c4eabafaf17daefe3afd33a60938405d24d870889db6d8eea3fcdf2
                        • Opcode Fuzzy Hash: 3e4f74acf0c33e10f9e56486c44c1982331ed5bcae49f4c4ab8dd5964c2bff69
                        • Instruction Fuzzy Hash: 8D210430600A018FD364DF59E544E62F7E5FF84324F56CA6AD89A8BAA1C770E9858B80
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4e0bf731994b5aa2e73570831b4354ad33a8a92570a5d36cd4ffd55e39a672f1
                        • Instruction ID: 509b23cd604664bf0f7b80eef498b1b04b747eda312cfc3d7a8aaf12394f2613
                        • Opcode Fuzzy Hash: 4e0bf731994b5aa2e73570831b4354ad33a8a92570a5d36cd4ffd55e39a672f1
                        • Instruction Fuzzy Hash: CA214AB6A001089FDB05DF99D8858DFBBB9FF8C310F05816AE506E7354DA30AD05CBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 1beecb5eb1787b66ad12ee58ddf5fe9a6de8d6ab468bd3da04762911b1fff949
                        • Instruction ID: e8f488f697e502738044657a90484bb0e46ec366112bc23f30f16e36895fd3e5
                        • Opcode Fuzzy Hash: 1beecb5eb1787b66ad12ee58ddf5fe9a6de8d6ab468bd3da04762911b1fff949
                        • Instruction Fuzzy Hash: 5C014437900115AFCF069F94DC04DD97B36FF89310F0644A0EA047B266C776E926EB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d191fc5c35d34945679ac0b393daa7fb69284b0e30d6725adf77d143f8b6c550
                        • Instruction ID: dc4ede7306e35f3a3ffe9c8dbaeb45950ddd144aed7632b530e1ca4d9d9740a2
                        • Opcode Fuzzy Hash: d191fc5c35d34945679ac0b393daa7fb69284b0e30d6725adf77d143f8b6c550
                        • Instruction Fuzzy Hash: 3D21E47834450A8FD705ABA4F0655EF7BA3FBC5A40B64C169D8068B348CF309C06CBD2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 139ba879ede64e670d49c06b260500ee30fd9a52bb78a95dee59d0f1c089535d
                        • Instruction ID: 6bde8dfc575c881a83ac8c7aefd41a7aefd2068540c548745eee541db3179630
                        • Opcode Fuzzy Hash: 139ba879ede64e670d49c06b260500ee30fd9a52bb78a95dee59d0f1c089535d
                        • Instruction Fuzzy Hash: 3511D270A807058FD754EF6994156AF7BA2EFC4750F508A1DD90A9B384DF30A9018FC1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 8256d81f696fc7b56f18cd9b47cad7746ca7b43a6906585aa668050f52a228cc
                        • Instruction ID: 1e9db6e2ceeb8f1210bc589a6c1b1c2efe2794cfc94ac8dceedb83c528b6f610
                        • Opcode Fuzzy Hash: 8256d81f696fc7b56f18cd9b47cad7746ca7b43a6906585aa668050f52a228cc
                        • Instruction Fuzzy Hash: 2311E932A08114AFD301DB99D840AD7FBB9EB85321B1585B7E518C7251D771EC0287F0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: deae18ea455b36418af5396f9a2cb354e56992ed4ee43865698ea4b9be687191
                        • Instruction ID: 80e410d4082db9b12817aca498dfef88522c366c4b6df0226cf6f51a49ea85ab
                        • Opcode Fuzzy Hash: deae18ea455b36418af5396f9a2cb354e56992ed4ee43865698ea4b9be687191
                        • Instruction Fuzzy Hash: 7B1186707006409FD764CF69D884E53BBE9EF89314B1585A9E44ACF662D731EC46CB50
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: eace5e8fb79e293aed350376767bd336ad7dcf63a71e7ca912ff88f7268aa45e
                        • Instruction ID: d91f3b6ebbd4acb7e55c49d8cf4458292ef246dc48a15e6a52bfbcc74eb04fce
                        • Opcode Fuzzy Hash: eace5e8fb79e293aed350376767bd336ad7dcf63a71e7ca912ff88f7268aa45e
                        • Instruction Fuzzy Hash: 8E11A5357002029FCB05EB6DD4A4E6AB7E6EBC8760B11806AE516CB354EF71EC418B90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 0fb2931d6336f92889982cc9ba93ad9d21331bbec41bf51801e2a80a38af176a
                        • Instruction ID: 2c12c26f56a239aa3d95ae7591fbe3e144a33913d52de0b47da36fb3136b63f7
                        • Opcode Fuzzy Hash: 0fb2931d6336f92889982cc9ba93ad9d21331bbec41bf51801e2a80a38af176a
                        • Instruction Fuzzy Hash: 9D11B9787405068FD705BB64F0655AF77A3FBC5A40B54D169D8028B748DF34AC06CBD2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: e878fa8a87fa0277cbe5768d5619b0db3d95511ffc5b9b85b1957fcb5b53c171
                        • Instruction ID: e08b65907e7ec5d8bc64f37734f26072d74323fee3c637ddec66059f43cde9f0
                        • Opcode Fuzzy Hash: e878fa8a87fa0277cbe5768d5619b0db3d95511ffc5b9b85b1957fcb5b53c171
                        • Instruction Fuzzy Hash: 0F113471A883848FD700ABA8E8227EF3BB0EB46710F448092E94ADB3C5CE341D05C7D2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: dcd43a09b656785a79ed5651f9338690107aaf1213e9c8edff93f8eff21b25fc
                        • Instruction ID: 0743f1979c70be6880f3e0cefa8d269b6a682d96cd0372caae2a45f2a8fefff0
                        • Opcode Fuzzy Hash: dcd43a09b656785a79ed5651f9338690107aaf1213e9c8edff93f8eff21b25fc
                        • Instruction Fuzzy Hash: EB119834B902599BDB19AB64D8297EF7AB3FBC9740F10405AD402AB388CF755C05C7E5
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 49cb0d207d0524c47f04c1db6e8088e0549ad606c1f14e04566602352750e83a
                        • Instruction ID: a2c9c7e1db5ec9b5d2420ec46c14f1de5897a4cd2312afa51eb04cf55ab6f7b1
                        • Opcode Fuzzy Hash: 49cb0d207d0524c47f04c1db6e8088e0549ad606c1f14e04566602352750e83a
                        • Instruction Fuzzy Hash: 8F118E70B407058FDB54EF6994146AFBBA2EBC4750F518629D90A9B384DF30A9418FC1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562505141.00000000054F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054F0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54f0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 377632a40f82c977e65d8ac9551eef5dc26e6d7e089a19a794b319f4b8a6a2b2
                        • Instruction ID: 3ca5019a788dfa484251d5237bef0a8094aaf45176fff034f25b7c380b3dcd66
                        • Opcode Fuzzy Hash: 377632a40f82c977e65d8ac9551eef5dc26e6d7e089a19a794b319f4b8a6a2b2
                        • Instruction Fuzzy Hash: 84012BB2F452119BEB15894DC8147FBB77AEFD5610F0440BBD609D7381D6724C068BA1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b317a70cb1b67764a2aefdc93d45453bf1caddd42d353313054224459b8ee708
                        • Instruction ID: bef9db48de2219a625523a4f6de89b836dd8da0ea52ecd74013b830eab67b438
                        • Opcode Fuzzy Hash: b317a70cb1b67764a2aefdc93d45453bf1caddd42d353313054224459b8ee708
                        • Instruction Fuzzy Hash: 4901B1A268D3C12FE3135374AC766E67F78EF83110F0945DBD4849B193DA54280AC3A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562505141.00000000054F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054F0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54f0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: ceff8b065fe53ff1d1553f60965406f2f72629ecdfc3b0f55ca2b5d67733c560
                        • Instruction ID: 182958b399da9e52fe6757a803b79dd7d6b1c417c0adf2996a9e9b5bd130b2f0
                        • Opcode Fuzzy Hash: ceff8b065fe53ff1d1553f60965406f2f72629ecdfc3b0f55ca2b5d67733c560
                        • Instruction Fuzzy Hash: 5311E771F44258CBCB268A68DC192FE7776FF85305F0509EBD612A7381C7788845CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 8d735f94e138d4b093ecdfdfa7b855d8cb95f8b9a61eed6d2bd4e8d5fc00af60
                        • Instruction ID: 3add534090c3e9a6479820b8bf27aa9b9f128ab0dc3cbf15b906d7936eb4c90e
                        • Opcode Fuzzy Hash: 8d735f94e138d4b093ecdfdfa7b855d8cb95f8b9a61eed6d2bd4e8d5fc00af60
                        • Instruction Fuzzy Hash: AB11A57120020A9BDB04EF19E891EDBBBA6FB84714F00852DB6168B354CFB4EC4687A0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 66727b4ca4c01438d749d95b03c8caaedd1de7ec0874e8cac3d2f3f3f8adafb7
                        • Instruction ID: 34df273b547080556c7c5e8ce34446c3babdbf9851fb117eeab4309412ba5ce7
                        • Opcode Fuzzy Hash: 66727b4ca4c01438d749d95b03c8caaedd1de7ec0874e8cac3d2f3f3f8adafb7
                        • Instruction Fuzzy Hash: 5B116DB1B4010A8FDB44EB94D9A57DD7BB5BB98200F64406AD445EB780DB359D028BA1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 738da10f299803919fe89b1b239ae6cd83f1e1f40c1c57839da452e46fca344d
                        • Instruction ID: f6c99f94cf9837724310c71e14e5acc9fdf9d2b1d55f9d43e276474eee0c06bc
                        • Opcode Fuzzy Hash: 738da10f299803919fe89b1b239ae6cd83f1e1f40c1c57839da452e46fca344d
                        • Instruction Fuzzy Hash: 2A110CB170450A4FD744EF65E4509EBBBA9FF89251F048179EC46C3381DA34DC12CBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4fb7eb732fe53878148c04fc76885096cd01290150df7429b94fe6350b423c4f
                        • Instruction ID: 8154b60526686036e5e96d58f9023a35d87707285bc2506c0f6f71c097a6106d
                        • Opcode Fuzzy Hash: 4fb7eb732fe53878148c04fc76885096cd01290150df7429b94fe6350b423c4f
                        • Instruction Fuzzy Hash: 5C019239B002018FC760CF6DD844A7AB7F6EFCD260B1944ADE98ADB761D631EC018B50
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 87a69403ed5c24695d62320c042a4d98a7b6b2ab610635d5914068499b1db202
                        • Instruction ID: 25dda0c9373e6c99469199d2acedf3dab1138d3cf80363352fce3d1a77c3ff09
                        • Opcode Fuzzy Hash: 87a69403ed5c24695d62320c042a4d98a7b6b2ab610635d5914068499b1db202
                        • Instruction Fuzzy Hash: 8E01D67120C381DFD301CB54E850B67BFB6FBC6320F0884AAE4458F245C6359C06C7A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c92cb023cb6599a09f1fc1dee979dd19f665c21dc657330cca5a02b87321d1ae
                        • Instruction ID: 1a11efb6a3d6ebc4d54472fb060cc4b30173cd4e5e1b2cd1e2b0c7b30c16a1e2
                        • Opcode Fuzzy Hash: c92cb023cb6599a09f1fc1dee979dd19f665c21dc657330cca5a02b87321d1ae
                        • Instruction Fuzzy Hash: 7411A934B501199BDB19AF64D4197EFBAA3FBC9B40F10442AD402AB388CF745C0187E1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 91b03f3c00e2d0991c6291127aae455ee41049cfa94e8febbead0327c21213b1
                        • Instruction ID: 5475bd05efe44449d06ae74cb151a0d7fcafb55ae428e42d94bd34ed5644763c
                        • Opcode Fuzzy Hash: 91b03f3c00e2d0991c6291127aae455ee41049cfa94e8febbead0327c21213b1
                        • Instruction Fuzzy Hash: 0101AE5274E3915FE71352249C557A76FB9FBC3660B4A01EBF844DB2A3D05C8C0683B1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 002de003286ac68b0d5be20bcce30e66ed376a9c56ce13dd9708e2c6abc99779
                        • Instruction ID: 2bd5183c1fce19ff2bfe9534dad3bb0d68ad2a861aa822fccad4d0ec946541c4
                        • Opcode Fuzzy Hash: 002de003286ac68b0d5be20bcce30e66ed376a9c56ce13dd9708e2c6abc99779
                        • Instruction Fuzzy Hash: CC01A7363402096B9B056E89EC98CEFBF5BFBD96607408039F60587354CE319C15D760
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a435d0279ee55261040b1c40e3cfb37ed379fe36a2cdfec9391ae77dc1b31019
                        • Instruction ID: 8fa3245ac1f0095b56623cf280be208e812ef0787e56d8265f2988130f04a768
                        • Opcode Fuzzy Hash: a435d0279ee55261040b1c40e3cfb37ed379fe36a2cdfec9391ae77dc1b31019
                        • Instruction Fuzzy Hash: 9401D670B502198BDB14EF65D4297EF7BB2ABC8B04F11411AD8026B384CFB55C05C7E9
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 993473a4a9bd883e785d054ecc6977bc01110f802dfb32c6f823c8483d787aca
                        • Instruction ID: 7ce14dbd8f79d3c7e2f4ce1f2c1aa1ac06048c4b6bae947ddd8519ca6b2f2021
                        • Opcode Fuzzy Hash: 993473a4a9bd883e785d054ecc6977bc01110f802dfb32c6f823c8483d787aca
                        • Instruction Fuzzy Hash: E901A2357002018FD710DF5DD844D3AB7EAEFCD261B1544A9E589DB761DA31EC018B50
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 5c071f3dfa912d58de2eb7eee3f2a68e077cc7d261862aeaec7692195b389452
                        • Instruction ID: 986defe87da39c4de5f8e43b9f737a2b9744fce0817a6774a94f681d6b74a847
                        • Opcode Fuzzy Hash: 5c071f3dfa912d58de2eb7eee3f2a68e077cc7d261862aeaec7692195b389452
                        • Instruction Fuzzy Hash: 0AF02B378141286BC702AE48EC519D27F68DF85360F08844FBC4186241D662EC96DBA1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558535903.00000000010AD000.00000040.00000800.00020000.00000000.sdmp, Offset: 010AD000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_10ad000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d2424cc5e1bdde35be3cbc3051365e1b8d1b3a0bfa155f07add0f4d0fbcc1354
                        • Instruction ID: c0bc367572cb36bc51f4e97282877724d169d3c443966359aed87788b957cb3c
                        • Opcode Fuzzy Hash: d2424cc5e1bdde35be3cbc3051365e1b8d1b3a0bfa155f07add0f4d0fbcc1354
                        • Instruction Fuzzy Hash: 1E01F2714053059AE7208AEACD80B67BFD8EF80720F18805AEE8C0E682C278D845C7B2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 7fcc39119fd182a781cb82f6fd1c7640c48b62371138c371c67ce152ed241e64
                        • Instruction ID: ca4b7d0b6cf241f2ffe1cbc257c490f6522742b89f07a6fa868f18e7649ba226
                        • Opcode Fuzzy Hash: 7fcc39119fd182a781cb82f6fd1c7640c48b62371138c371c67ce152ed241e64
                        • Instruction Fuzzy Hash: F41103B58003498FDB20DF9AD944BDEBBF4EF48324F208419D519A7250C774A944CFA5
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: db4cc0715687c05d395bbdcdb949083947b251f3d5cb8117927b87fa96a250a8
                        • Instruction ID: 39227311d659f7860aec8a3459dad6f92f0435cf5c6f552470c33f7b693c03d5
                        • Opcode Fuzzy Hash: db4cc0715687c05d395bbdcdb949083947b251f3d5cb8117927b87fa96a250a8
                        • Instruction Fuzzy Hash: A801B5B4A402059FE740EBA8E5167EF7BA1E785B10F008015E61AC73C4CF305D01CBD1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9eff79f2d556eeeff6df1de08c2cede5e8111b0205a44063c2c7a61724df4dc6
                        • Instruction ID: 35df2b15998f33301f4c615c9995fe5418f224c94dd464b383104e5f564b0aa3
                        • Opcode Fuzzy Hash: 9eff79f2d556eeeff6df1de08c2cede5e8111b0205a44063c2c7a61724df4dc6
                        • Instruction Fuzzy Hash: 54F0AFB2905208AFCB02DBA8DD527DBBBB9DB45210F1005E6D908D7251F93A9E0A63A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 1d3ab533b2c002331bfd0e0b448694638dd721c6268bccf62540abced42790fb
                        • Instruction ID: ce760e7c26c74e80dea8f907b2b71fa195c0169a7aee03a41bbcbd42efe40c3f
                        • Opcode Fuzzy Hash: 1d3ab533b2c002331bfd0e0b448694638dd721c6268bccf62540abced42790fb
                        • Instruction Fuzzy Hash: 7E012B31A28148CFC714EFA8D4455AEFBB6FBC5600F04C06AE142AB244EF30A989C7D1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3fd1d4f5be063d7f3b6f57e3ce05a5e4f55cecfdcb0aaf0b87824f4dea443f50
                        • Instruction ID: 9efe4e19a4599af447bcd9c4a89f989346a66590d0949800d6f94de67de6407d
                        • Opcode Fuzzy Hash: 3fd1d4f5be063d7f3b6f57e3ce05a5e4f55cecfdcb0aaf0b87824f4dea443f50
                        • Instruction Fuzzy Hash: 9E01D171A091849BDB01C768D8909EEFF76DF85221F1481BAE454D7392D7329C07C720
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 95edd0feb09728061bfdfe045cb91a68fccf9f056f886becf5586e0221a97495
                        • Instruction ID: 22cb03ef53317389862d4d1b6dfa20748da0278f50a0555aec5bbeec449d59f9
                        • Opcode Fuzzy Hash: 95edd0feb09728061bfdfe045cb91a68fccf9f056f886becf5586e0221a97495
                        • Instruction Fuzzy Hash: 1F01FD31210109AFDB40EF54F910AABB7AAFF88210F158959A9418B294CB329C02DBA1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 1c5f1bac504ab7cb90e73f23588d222a8cd025074a2780173f85cd2d035e94f1
                        • Instruction ID: 826d0ae674891c8698fdececa92f22ceefdf12e263225398ad904b8f480dfbe1
                        • Opcode Fuzzy Hash: 1c5f1bac504ab7cb90e73f23588d222a8cd025074a2780173f85cd2d035e94f1
                        • Instruction Fuzzy Hash: 9001FF76A102259BEB18CE18D840BEAB7B6FBD4310F24C53EE800A7380CB35D9168B90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4a91f12fca0f3e108c89db3581c1b75f56733f71e0a7264b4a68acf6cfc44713
                        • Instruction ID: 71e951131528554c216c029eaf7930e7e3f4e602921236125395d74c33007447
                        • Opcode Fuzzy Hash: 4a91f12fca0f3e108c89db3581c1b75f56733f71e0a7264b4a68acf6cfc44713
                        • Instruction Fuzzy Hash: 91F03C36500008FFCB06DF94D840E8ABBB6FB89210B0684DAE5089B671E732C925EB50
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 053c953b54ffad294aa26462acd1d61a355ec14881a27e2d3274aab30fc9130c
                        • Instruction ID: 9045e8b7de54568992253fd8d028b637df7eb04b31b386f47ad16160b24ba9ad
                        • Opcode Fuzzy Hash: 053c953b54ffad294aa26462acd1d61a355ec14881a27e2d3274aab30fc9130c
                        • Instruction Fuzzy Hash: 73F096B134400557C205AA59F496EEBB7DEF7DC650F484039F60AC7748DE64AC0283A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a7a4d8b5ae5ed8b1a8f22d02e6e9b49fe21f1ea3ea2340b9a9460b13cadbb6b0
                        • Instruction ID: 0a6562236b202e15fca191f04eb5822143d366cf18b94cc5702eb93eef2ed2c0
                        • Opcode Fuzzy Hash: a7a4d8b5ae5ed8b1a8f22d02e6e9b49fe21f1ea3ea2340b9a9460b13cadbb6b0
                        • Instruction Fuzzy Hash: 04F0843034051A8BEA1922A8AC10BAB739AFBC5220F0040369A0D9B3C0DE209C00C7D4
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4371c43b535ee5208e77cf089fcff172a2d31ea426026076e7d14506e7ecef09
                        • Instruction ID: ceff373596cca77f2f530643bad7b5543222d11ae90e8611260fa4c45790af87
                        • Opcode Fuzzy Hash: 4371c43b535ee5208e77cf089fcff172a2d31ea426026076e7d14506e7ecef09
                        • Instruction Fuzzy Hash: 36F0F6313842442B97065A99EC95CAB7F6AEFCA5643448079F6048B241CD218C16C360
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 7dff95e20abd4bee7eea131770fd7ad5c10386a61443d44fdfbd9062e14220e8
                        • Instruction ID: 2b0c1f6c6a514cb11a9ef8ddc606e611a458d52ed2873e13e063a7bf379b71d0
                        • Opcode Fuzzy Hash: 7dff95e20abd4bee7eea131770fd7ad5c10386a61443d44fdfbd9062e14220e8
                        • Instruction Fuzzy Hash: 82F0AF307807059BD754FB68A4247AE7B92EFC4760F508A1DEA0A5B384CF71AD468BC5
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 89b05e59487ce19fb379aa249f235438c6c2444c4d98c56783b185d789f643b3
                        • Instruction ID: 9a23cfcfb6a550940eeb4fbb75266cb9574a6151c02356dfd10b00ae9730a2a0
                        • Opcode Fuzzy Hash: 89b05e59487ce19fb379aa249f235438c6c2444c4d98c56783b185d789f643b3
                        • Instruction Fuzzy Hash: 90F059713805169BEA253611DD11FAB779AFBC1630F048026AE09AA3C0DE60AC0187E4
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 2114546a3ba25fc57aba729aa16f77aa0ce9845e67163c82984e60fde9ae6144
                        • Instruction ID: 32bbd699e4f156d485496b743373e672ce57ad2053854cf0068ea2012898b315
                        • Opcode Fuzzy Hash: 2114546a3ba25fc57aba729aa16f77aa0ce9845e67163c82984e60fde9ae6144
                        • Instruction Fuzzy Hash: 71F0E9723404056BC711BA59F8D49FF7BABFBC9260B148024F84AC3344CE255C07D7A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558535903.00000000010AD000.00000040.00000800.00020000.00000000.sdmp, Offset: 010AD000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_10ad000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c280f71c159a77c4a92fccf2c10279f68f43964899807cea0c94795cb91bdb89
                        • Instruction ID: bc66069573a901cf1af8f80fe7abb8cd7550904cbde6e238e759725fed9ac162
                        • Opcode Fuzzy Hash: c280f71c159a77c4a92fccf2c10279f68f43964899807cea0c94795cb91bdb89
                        • Instruction Fuzzy Hash: 7BF0A971405244AAE7108A5AD984B62FFD8EB80624F18C09AED4C0B682C2789844CBA1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: fc755d7b967e7e121e7d8f05cc647ab6891fd854d3184d3c5b3d375957f044eb
                        • Instruction ID: 98c17524360fb31209bfa982d6041c4402e2a7d7aae8db12128b4e4375007120
                        • Opcode Fuzzy Hash: fc755d7b967e7e121e7d8f05cc647ab6891fd854d3184d3c5b3d375957f044eb
                        • Instruction Fuzzy Hash: 85E01A321041587FCB01DE88DC91EE77F2DEB86364F08C15BBC4587252C676AC62ABA2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: af90e0859b77088fab1a5f9370c9a189bac0a62f85270018ac0b9f9a4d59c4eb
                        • Instruction ID: e7a48745f01d6219b6f021c4e685ef5c0eea60ab1e83a2aa8a2fcb071cfb8dd4
                        • Opcode Fuzzy Hash: af90e0859b77088fab1a5f9370c9a189bac0a62f85270018ac0b9f9a4d59c4eb
                        • Instruction Fuzzy Hash: C9F03C32104198BFDF428E94CC00EFA7FAAEF0D254F098086FE5496261C276C961EB60
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b6ba729640a2d05598599250e72d74fdddfefc179601410e667f97aa736f57da
                        • Instruction ID: 3a9af73e21d777d32e5829f5974708d45fd54fe5004ba158b01b7c12f10c8423
                        • Opcode Fuzzy Hash: b6ba729640a2d05598599250e72d74fdddfefc179601410e667f97aa736f57da
                        • Instruction Fuzzy Hash: 82F0E2713400095BC208BA99F4AA9ABBBDBF7CC650B448039F20AC7348CE70AC0283E0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 914b08dba061cf2bcf86c029f0529c4ac12a423924c2cfea00e433829a0fe274
                        • Instruction ID: 2c47726ae33f8fca62a617b82b7671717368a275a9974e18b313e235444e14e1
                        • Opcode Fuzzy Hash: 914b08dba061cf2bcf86c029f0529c4ac12a423924c2cfea00e433829a0fe274
                        • Instruction Fuzzy Hash: A6F08CB02013499FDB01EFA8E611BDEBBB1FF02240F6086AAD808C7256DB345D06DB51
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: ac50aee2177e0504d2ca937fd47f58229e2420e439f5b432e0798129dc1a763f
                        • Instruction ID: 474431037d4c1a0f6de81eeb1a781c5c64e290f541c0db179c75dc1ce0990bc3
                        • Opcode Fuzzy Hash: ac50aee2177e0504d2ca937fd47f58229e2420e439f5b432e0798129dc1a763f
                        • Instruction Fuzzy Hash: 67F05C723403947BEB14655ADC06FA7B7DEF7C5750F190099F201DB5C4CD50D80287A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: df1aef6a31c337cff735a46b08aefcf76cfa0f69eab9f01c3c45b40cb9d626a2
                        • Instruction ID: b75ba69066d34594578f4126a44acc09cf18a2b6cf652e85707fd244275eb0ba
                        • Opcode Fuzzy Hash: df1aef6a31c337cff735a46b08aefcf76cfa0f69eab9f01c3c45b40cb9d626a2
                        • Instruction Fuzzy Hash: ECF08CB20040987FCB418E94CC41EFA3FADDB4D264F088046FE98D2241C12ADD22ABB0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 32b06bf866aeef74f5ceb883e1acb932fad7a3e2fdd2a0612e2260979b01369b
                        • Instruction ID: 3c1423fdf9b5d5873b163747f390763112d8743dc6fccb7d0520de4134cc5012
                        • Opcode Fuzzy Hash: 32b06bf866aeef74f5ceb883e1acb932fad7a3e2fdd2a0612e2260979b01369b
                        • Instruction Fuzzy Hash: B8F0B435508240CFC742DFA4D9509DABBB1FF85211755C9DBD4088B652DA31CD03D791
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 416a8d303a02a88e7ccf85a92837bc5c1b9758dcd07111ac5ee3bb85806a4e8b
                        • Instruction ID: 5bc57ee9d580ccc56ea8a93dddb4d3531828bb0db1f7956839831d82cc69bee4
                        • Opcode Fuzzy Hash: 416a8d303a02a88e7ccf85a92837bc5c1b9758dcd07111ac5ee3bb85806a4e8b
                        • Instruction Fuzzy Hash: 28E09B36704000AFDB01AB84D454EA9BB92FF88370F15C126FD489F390C636EC018790
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 16e959e6e212c7c12a33518bf34579ab1ee1acb165aed6a74ba8ae60886a51ff
                        • Instruction ID: 422df2cee8387e387c48efd174634010bd4d46393d7c0af55f70b99599fcf4aa
                        • Opcode Fuzzy Hash: 16e959e6e212c7c12a33518bf34579ab1ee1acb165aed6a74ba8ae60886a51ff
                        • Instruction Fuzzy Hash: B6F055303902549BC200E668A02A5E73BEAEBCA920B0110AEF485D7241CE115C02C3E0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 91219f957cdad8a36a8544e2367f157b5868980899626dfa0df30f0ab190e86d
                        • Instruction ID: c6c4fb3a306682d4d87eab8a34630627889ede36637ddb60016f97517fccef41
                        • Opcode Fuzzy Hash: 91219f957cdad8a36a8544e2367f157b5868980899626dfa0df30f0ab190e86d
                        • Instruction Fuzzy Hash: E5F05531300244ABDA14A54EAC04FA773DEEBC9B50F244069B305CB2C4CD60DC0287A6
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6e15fcb3f289ab1c673b0936c582ab545763975d403b18763eb3c203dd4a8ea4
                        • Instruction ID: 4acd935b8278d4d1b4f7a5790d8a5450d61c7d2f16bf22768955fe2c89ba7b9b
                        • Opcode Fuzzy Hash: 6e15fcb3f289ab1c673b0936c582ab545763975d403b18763eb3c203dd4a8ea4
                        • Instruction Fuzzy Hash: B3F054355142889FCF02AF78DC508E9BF75EF4B210B05C29AFC945B212EA31D969D791
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 40993af1220e55d3b7386f2f52cd063b23b9a609b763f51f7a8a7a9607cecbf0
                        • Instruction ID: 1049ecb9b54e91ec807d7bcd9e0018e4ef399f5c86e8c69f5d1c2de5aa4d5637
                        • Opcode Fuzzy Hash: 40993af1220e55d3b7386f2f52cd063b23b9a609b763f51f7a8a7a9607cecbf0
                        • Instruction Fuzzy Hash: B4F030763405056B8715AA59F89486BBBAAFBC96607148025F54A87344CE31AC02D7A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9c33e7b8c879c0c0083519c75eee31f0c06ce2e27102669b162b5b3b1e541f4d
                        • Instruction ID: cf3074c0e25f4103f58c4f7f30ea1db1d1b422a838e7c4b37068c14b0041508d
                        • Opcode Fuzzy Hash: 9c33e7b8c879c0c0083519c75eee31f0c06ce2e27102669b162b5b3b1e541f4d
                        • Instruction Fuzzy Hash: 88F06D721141987FDB41CE89DC11EFB7FAD9B5D221F08805AFDA4C2242C66ED9229BB0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: ee1db7da392918eb677482389b3720375f5549fe0e4f7421fb9d420a6e151aad
                        • Instruction ID: 0905eb614f9e0bd1a79eeaa5aab7de92fa3721ba4fcd2eefd8621460de4466d3
                        • Opcode Fuzzy Hash: ee1db7da392918eb677482389b3720375f5549fe0e4f7421fb9d420a6e151aad
                        • Instruction Fuzzy Hash: AFF02434A08606CFDB0DAF98D0A4BD577A5FB5A301F4642BAE54B9F34ADB74C840C742
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 02e3b3ac8c1c90312333468d8c1cb079a3f721a403b096e93793f616a9ad3935
                        • Instruction ID: 3165a1441514fa8904605574d62674ea277f7d29f2a5da05e1206f7e6b890033
                        • Opcode Fuzzy Hash: 02e3b3ac8c1c90312333468d8c1cb079a3f721a403b096e93793f616a9ad3935
                        • Instruction Fuzzy Hash: B3E09B703501059BE608F769EC56BE6B7AAEB84310F44827E70058B359DF65AC038671
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 37e04bea7350471dc8935ca9be02bd849c2d38d1f35782c052191efa75def2ca
                        • Instruction ID: 679fe062a1248a7999385cc8b91520c32dcb13f17f9685c2bb5cc48e22505653
                        • Opcode Fuzzy Hash: 37e04bea7350471dc8935ca9be02bd849c2d38d1f35782c052191efa75def2ca
                        • Instruction Fuzzy Hash: 3CE0E5392491841BC702566598119EB7F66DBC6A60F09C0AEE185CA542C9624C0B87A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c705bcd5ff3b85abd795d90962f64368e4251e0e183a08248ab40813e9006bd4
                        • Instruction ID: 777c974505a96f22f1cea80d28ec7e78ac3c1e17bab77b30010afd3dc567bf69
                        • Opcode Fuzzy Hash: c705bcd5ff3b85abd795d90962f64368e4251e0e183a08248ab40813e9006bd4
                        • Instruction Fuzzy Hash: 19F039721101587FDF458F84CC01DFB7FAEEB4D228F08814ABD5492251C63ADD22ABA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 0c256abdcc74e3f3b0cc899d90851ad6532574588c596e9905f6b62b223b5a7c
                        • Instruction ID: ac77b03cff917aaa36cf5760e499c42e344fb1dd42388426998b80f277778232
                        • Opcode Fuzzy Hash: 0c256abdcc74e3f3b0cc899d90851ad6532574588c596e9905f6b62b223b5a7c
                        • Instruction Fuzzy Hash: 70F0A07210C2A86FCB02CB94CC21EA33FB8AB46215F0D809BF844C7293C166C911D7B0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 2178fb91bbfa43cfc9d59056c338fb8c374c7e516cf8c4849299f840b32f0033
                        • Instruction ID: ca829bcf2f18f47cc9370dc8e50283f5c52032b08ebe81030f708232dbccb86a
                        • Opcode Fuzzy Hash: 2178fb91bbfa43cfc9d59056c338fb8c374c7e516cf8c4849299f840b32f0033
                        • Instruction Fuzzy Hash: 27F07F36114144AFCB468F94DD44CA5BF76FF8922030A81DAFA198B272C633D926EB50
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b08b0c20d7f28e46f6957c74b631a0d80ab55b175e2fa9a11867466f1e33f34f
                        • Instruction ID: 8ec17389fe1ffc88424cd7a874960b6d6069049d753257e6ac49c08500964ccb
                        • Opcode Fuzzy Hash: b08b0c20d7f28e46f6957c74b631a0d80ab55b175e2fa9a11867466f1e33f34f
                        • Instruction Fuzzy Hash: A4F0E533340109A7CB01AE99E805BDF3F6AEBCC720F04802AF54587214CF3198129760
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: cd7cebee19c8ef7650b151674d3cb43ecc6ab0c67d2920bb49caa29559fa7bd1
                        • Instruction ID: 5713effb40be0a4359ad45dddae526de9ef2887320f78a806879a3acc1152c47
                        • Opcode Fuzzy Hash: cd7cebee19c8ef7650b151674d3cb43ecc6ab0c67d2920bb49caa29559fa7bd1
                        • Instruction Fuzzy Hash: D7E0EDB63051006FD344CA14CC95B97F7A9DBD4625F18C46DAD49CB351EA36ED03DA21
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3ffec7fcbf489ea891dc7857f9c7dab5c50e359d659741e1eefa66bcbf44de77
                        • Instruction ID: 9a6fda95b2b9101ef66e4c55973cb296d2e742202fec34a9248adb1bcea4c483
                        • Opcode Fuzzy Hash: 3ffec7fcbf489ea891dc7857f9c7dab5c50e359d659741e1eefa66bcbf44de77
                        • Instruction Fuzzy Hash: 95F03070918349EFC705EFB4D9948A97BB8FF0630471105DAE545DF251D6326E009BA1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b95d0d2523a7d2deac1c2d3f839b5bc48c776d3e821162f10d3815bc3d7109f5
                        • Instruction ID: 6b702366463c59519f85e66e78dce1d5ca59cf24b697171177697c9c5217a175
                        • Opcode Fuzzy Hash: b95d0d2523a7d2deac1c2d3f839b5bc48c776d3e821162f10d3815bc3d7109f5
                        • Instruction Fuzzy Hash: 35E0ED70A8020AEFC750EB61ED6AADEB3B9FB40240F40416A900497244EE306E018790
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 0fa2d30e4d55209cc9d1e00ad667679eef0dc5544911cf43fff874e5146c9279
                        • Instruction ID: 1d9ee4bc310d63df8cf6f35b4ed74db1983bf267b13b4faf45f7eafb0b628cef
                        • Opcode Fuzzy Hash: 0fa2d30e4d55209cc9d1e00ad667679eef0dc5544911cf43fff874e5146c9279
                        • Instruction Fuzzy Hash: 50E01A661092D82FC702CAA99C619A7BFEC8A4E121709809BF994C7283C56AD902D7B1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 271bc338437ed29b2098d0adae7595977a388a0699aacc73de9ad4175bf630f9
                        • Instruction ID: 15aac57ccad3f1b4fa2174eaf1ee3680a29d10ab830136cdb33de6998f2fb390
                        • Opcode Fuzzy Hash: 271bc338437ed29b2098d0adae7595977a388a0699aacc73de9ad4175bf630f9
                        • Instruction Fuzzy Hash: C1E0ED32140019BBDB068E84DC01DDB7F6AEB58760F04811ABD0887251C776D822EB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 393f7a88cb715c0f50d5810445defcb1317bf06d714992202bd19b09ecaa802c
                        • Instruction ID: 5bf380b76d8c015c63896cec9094d824670b1dc50b8abef60ade75e6867ee393
                        • Opcode Fuzzy Hash: 393f7a88cb715c0f50d5810445defcb1317bf06d714992202bd19b09ecaa802c
                        • Instruction Fuzzy Hash: 14E046721041187FDB408A88DC81FE67B6DDB88260F048016FD4896241C66AED22A7B0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 5e15507fc50ee948970dbd4762f3ff8614c5cf8d10decee01242b114e01db4c8
                        • Instruction ID: 5dd3c1d11ce0abbd0a6421927aafbfe96e00f8e474ef36b1fa3fb3cc611671f7
                        • Opcode Fuzzy Hash: 5e15507fc50ee948970dbd4762f3ff8614c5cf8d10decee01242b114e01db4c8
                        • Instruction Fuzzy Hash: 03E05236110114BF8B469FC4D944C91BFAAFF8D22030AC09AF6188B232C673D922EB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 5c50d493f181fff6a062ffbe909f1d60c1dd54dbf63f50dfe7649e341d3ad6ac
                        • Instruction ID: 03f37c912341d006ec84cebc75017e85c1a6f431f334e8160c5399fb1dba8d2a
                        • Opcode Fuzzy Hash: 5c50d493f181fff6a062ffbe909f1d60c1dd54dbf63f50dfe7649e341d3ad6ac
                        • Instruction Fuzzy Hash: AAE0C232790114978604F69DF4299FB77EEEBCAA61B45606AF11ADB344CE61AC0287E0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 664f35d6e9b6a0b8d0af0c68ad880da06b61d7390ef2d4ad81f92f49d285d556
                        • Instruction ID: ab42ce4db648e4beb32346b8b6c2f302b8672c3b12da0919521848ec76e6fc6f
                        • Opcode Fuzzy Hash: 664f35d6e9b6a0b8d0af0c68ad880da06b61d7390ef2d4ad81f92f49d285d556
                        • Instruction Fuzzy Hash: 83E04F721040A87F8B41CE99CC10DFB7FED9A4D111B08804BFDA4C2242C57AD922EBB0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 12c7ed831dc031ef9bb48cc7b1b0c19b31c50cc15cb10a5bf57496d2a238c9f0
                        • Instruction ID: a457f263c01bafc140448535d8f890fc4cecef94341b65b01da58ec25f6e44e5
                        • Opcode Fuzzy Hash: 12c7ed831dc031ef9bb48cc7b1b0c19b31c50cc15cb10a5bf57496d2a238c9f0
                        • Instruction Fuzzy Hash: 5AE08CB25442109BD618EA44D8C0EABB7ADFBE8320F08881FFC1182304C779FC1BD6A0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 01ce93e713cc5dbd930c845e9fa096e5556c26bd16f4097572909bb0a2776505
                        • Instruction ID: a8c3e18a0aa011405ea1438eceac1b6a689154c39bd34c979f4289fef8cf0193
                        • Opcode Fuzzy Hash: 01ce93e713cc5dbd930c845e9fa096e5556c26bd16f4097572909bb0a2776505
                        • Instruction Fuzzy Hash: C1E09A34624001ABDF08ABB4D9549FE7B73EB48210F118522BB01DB390CA32C8468702
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 0e381dc2508c68bbd41fd731b656dde20cb037a06cd9d31af6102a5751f466de
                        • Instruction ID: 767684c18cb5aa51aa22a298096e8454bc384a568bd5dde6f632aff880f73b54
                        • Opcode Fuzzy Hash: 0e381dc2508c68bbd41fd731b656dde20cb037a06cd9d31af6102a5751f466de
                        • Instruction Fuzzy Hash: 44E0EC32604119BBDB058E84DC42EE67B6AEB98760F04C05AFD0496321D772DD629BE0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 04e8dd29940e68be290c36023ac59d43656052af186a3e6c0020676a1ccca2f5
                        • Instruction ID: 7f4a1c8b677ca7381c3a32daf3e689be4c7061c4763f726c599abcbdd0f2938d
                        • Opcode Fuzzy Hash: 04e8dd29940e68be290c36023ac59d43656052af186a3e6c0020676a1ccca2f5
                        • Instruction Fuzzy Hash: E8E04F311042486FCB06CF48CC51CA6BB79EF85224709C49BF94487253C673EC22DBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: f799511eeb21dd98db77a8b378c81c1f3452f49d22aa1a66e07b5c327beff745
                        • Instruction ID: 936fe8beaa4d37c03835519af8ca39b8624bda764dfb4da3f156dbce928d01f1
                        • Opcode Fuzzy Hash: f799511eeb21dd98db77a8b378c81c1f3452f49d22aa1a66e07b5c327beff745
                        • Instruction Fuzzy Hash: C0F0E575A04118CFEB00CF94D885AEDF7B2FB84314F5081A7D209AB211E7709942CF60
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4ffd729b656d4bf7321c5cff1e67fa317d85f1d6ed2f15d996842c2f092a0cc6
                        • Instruction ID: ea767be6590138f6beeebcd7445ee537f8c8c6f43818401e86a77d512f61824b
                        • Opcode Fuzzy Hash: 4ffd729b656d4bf7321c5cff1e67fa317d85f1d6ed2f15d996842c2f092a0cc6
                        • Instruction Fuzzy Hash: E1E01274A08005DBEB059BB4DA545ED7BE3DF84240B554126A902A7350DEA5DC168B21
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 0024ecd1caf81b3b721195d554dae05f26cbbdd71e19faef40c3cdc61de78c9b
                        • Instruction ID: d01a88a0453394a8741d53b7fc2edf8e8597474975b297308ea5e3f50b01f022
                        • Opcode Fuzzy Hash: 0024ecd1caf81b3b721195d554dae05f26cbbdd71e19faef40c3cdc61de78c9b
                        • Instruction Fuzzy Hash: 21E0C23660000CDBCB8ADF54D941BCAB375DFC4300F0442DEA4088B210EF36CB0287A0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d4bdde36e1e361e21c52e213d8365e0bfbb52d65d01735425ba509896e76415c
                        • Instruction ID: 6b513fb2012614ba342731299ea181ea26249fdcea9bbd9b273aa874ce780d98
                        • Opcode Fuzzy Hash: d4bdde36e1e361e21c52e213d8365e0bfbb52d65d01735425ba509896e76415c
                        • Instruction Fuzzy Hash: FBE026721085D42FC301CA94DD609767FA88F89022B0CC0CBFCA4CB292C879CD02D760
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c11fe0d0797dc67f1c5eaa86bcf6b67774c45d5a258c85d0c65e16aa636fb5d9
                        • Instruction ID: 77101f910c6eeca29ae3d100080a88161016a69d35c6775602c5e37436e2fd67
                        • Opcode Fuzzy Hash: c11fe0d0797dc67f1c5eaa86bcf6b67774c45d5a258c85d0c65e16aa636fb5d9
                        • Instruction Fuzzy Hash: 02E072724205004BE300EA08CC01B99B3A0EB81300F00C42CE888A3351EA24AA4796A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 199ec46509acc8c9c76acd5617e3c49912a790ef133602f9d88963ae93dac037
                        • Instruction ID: cd546b4c8d598525c802443c7f4b3eb0e9c516f26933eb8ca15192f187501004
                        • Opcode Fuzzy Hash: 199ec46509acc8c9c76acd5617e3c49912a790ef133602f9d88963ae93dac037
                        • Instruction Fuzzy Hash: 75E08C325155109BC300EA18CC80BDAB3A9EF95210F04C56EE808A7305EA35E80A9BB1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c4ea81e932490bd425dd1eecb5f46db3a70b9bcc9a5aefbf77d55a27225e88ea
                        • Instruction ID: 66090d2a0f6b3fb8c2cbaf81942151f85be4e8b8149f3cce45b1d9f4a85930c9
                        • Opcode Fuzzy Hash: c4ea81e932490bd425dd1eecb5f46db3a70b9bcc9a5aefbf77d55a27225e88ea
                        • Instruction Fuzzy Hash: 0ED0C2363400186BD7056988E801EBB7B9EE7C8B60F048026F206CB244CE719C0187E0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a87956a886bccd33d39971a8f6d5864a4c6cfea287e1648d96d0c22ae7e5b522
                        • Instruction ID: d2ae85557e9e2071dc3c1a374e81acff04cf616ac4327166fe155a5de0a833d1
                        • Opcode Fuzzy Hash: a87956a886bccd33d39971a8f6d5864a4c6cfea287e1648d96d0c22ae7e5b522
                        • Instruction Fuzzy Hash: 46E012B060020EDFCB44FFB5E96099EB7B5FB44200B50566D940597344DE716E01DB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9f44631fe7c118a0a6b8d82dd1d9a4ce8c3760eff3cde8ce56f504847067c016
                        • Instruction ID: 60a102e52eac758bfe3cada343921d23108b513531de9282296ad8c26894649a
                        • Opcode Fuzzy Hash: 9f44631fe7c118a0a6b8d82dd1d9a4ce8c3760eff3cde8ce56f504847067c016
                        • Instruction Fuzzy Hash: 3EE08C7090A389FFC702EFB498016CABFF89E0620270545DBE448DB162EA314A14E7A2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 157dfc891ca88875c3f879bbb4813dbd203fd06cd9a8f6648bbc87852fd159b8
                        • Instruction ID: f39f0e3ac9307f9419e4c671c700b90f4a363e80d4ff0665dba6dc387ca3d4a1
                        • Opcode Fuzzy Hash: 157dfc891ca88875c3f879bbb4813dbd203fd06cd9a8f6648bbc87852fd159b8
                        • Instruction Fuzzy Hash: 60E08671809288AFC703DF6498506CABFBD9E4610074900E7D944DF153EA228A14D361
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 68f562490550108a1acf684514063e3d660341b3121234463374542d93d9924f
                        • Instruction ID: 09f26ffc4abba538bde01b470c08ce3c0e7e6cf1d5e2e796450c43f4c802bb39
                        • Opcode Fuzzy Hash: 68f562490550108a1acf684514063e3d660341b3121234463374542d93d9924f
                        • Instruction Fuzzy Hash: BAD01272940108BBCB01EAA4CC417FF7BFDD744110F5008A6D904E3250EA359A0566A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: fedcf6184b12080d227d26b6f6bd029dc3164dcc1f54aa205f1f5fffbc3fc3a7
                        • Instruction ID: 405edb1f0e1d55ca2337d33f6f72afd8d41419799aee26594d7a1be664abbb96
                        • Opcode Fuzzy Hash: fedcf6184b12080d227d26b6f6bd029dc3164dcc1f54aa205f1f5fffbc3fc3a7
                        • Instruction Fuzzy Hash: 05E0C231515288AFCB02DFA88D615DF7FF9DB06201B0004E7980CCB251FA31AB09A7A2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 111bd743462bc2b6fd6f666f947e8692ae2d2ea8c88899b37327c6bcd6da8751
                        • Instruction ID: d1063adb583ceb484d159f768113fd2f8364cd2d2ad2853b75525ed7e5cfcc0d
                        • Opcode Fuzzy Hash: 111bd743462bc2b6fd6f666f947e8692ae2d2ea8c88899b37327c6bcd6da8751
                        • Instruction Fuzzy Hash: 3EE04F70A4020EEFCB04FFB5F9659DEB7B9FB40240B50556ED40597248DE312E00CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 26551769e68ab135966450663f7a6eaa91f8c80239e2b7024028480f59fb50d8
                        • Instruction ID: fd0600599afb7f109cf2a33ac267192b7715ea44f696624dd28632ea633270af
                        • Opcode Fuzzy Hash: 26551769e68ab135966450663f7a6eaa91f8c80239e2b7024028480f59fb50d8
                        • Instruction Fuzzy Hash: E1D05B313002196BD604BA7AF865AEA775AFBC1611F41557FF6068B245CE616C0243D4
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 2f3d50b0f6c67bcc62dd882915eb972f2856c861e6a7f045e04bb350ba5473f5
                        • Instruction ID: 19648b38933ec848220f68607e16391b951522acd05d39a51724bb4e5854af16
                        • Opcode Fuzzy Hash: 2f3d50b0f6c67bcc62dd882915eb972f2856c861e6a7f045e04bb350ba5473f5
                        • Instruction Fuzzy Hash: BAD01272904108ABD704DBA4C8527CBBBFED708210F4005AAD504E7210FA758B4556A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 80b3b5537755b4f1db85e8f23218d2280a1bb85c9db21d2452c0a94f0924a6ad
                        • Instruction ID: 4e86174967427b1c86348fb42e2d66265d111dff6a77f2a1040e7ec478b37591
                        • Opcode Fuzzy Hash: 80b3b5537755b4f1db85e8f23218d2280a1bb85c9db21d2452c0a94f0924a6ad
                        • Instruction Fuzzy Hash: 49E04F361082987FCB01CF94DC508A67F29EF49214B08C09BFD4447252C6B29C22D791
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d7f11fbb3a883cc2330a9462e54d2f3cb50e3aa785b5b75b243fe633c7bc0759
                        • Instruction ID: d7d894e18b5c68c2ee454d389c62586fe9d31aecbaee9b97b15f60f4ae23f0f3
                        • Opcode Fuzzy Hash: d7f11fbb3a883cc2330a9462e54d2f3cb50e3aa785b5b75b243fe633c7bc0759
                        • Instruction Fuzzy Hash: 4BE04F71A092449FC741CBB49A555ED7FB29E9610471805FF800DC7662EA229B16D781
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 276cad6b323e97f70f2b7e181a8147b37704140e0287511066db3891c9d0a226
                        • Instruction ID: 7f61b135d1a9c7032262f4ed2419c7b015686f7a2e32b94a2d26eb1ce6c5f62b
                        • Opcode Fuzzy Hash: 276cad6b323e97f70f2b7e181a8147b37704140e0287511066db3891c9d0a226
                        • Instruction Fuzzy Hash: 23E086315093509FC301EF58C85089AB7F49F86610B05859FF48497212DB319D46C7A2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: ecb30322a785a9e8a15433bcec885d69e3f08c2de4cb5f10e33ff81865bb48db
                        • Instruction ID: 0ab1536e4e4088f79b5111d047a34308005aac421a20c508883fac77c05d3aa8
                        • Opcode Fuzzy Hash: ecb30322a785a9e8a15433bcec885d69e3f08c2de4cb5f10e33ff81865bb48db
                        • Instruction Fuzzy Hash: E6D012B7A45108BBCB45DBA89D456CE7BB9DA4520074005D79508D7210FA329A1597A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 2c59d956c586637386b851d267094da3af282047a9bf53023292690b53895ada
                        • Instruction ID: fcbdb916dbf610a64635b3cdb7968381a68d523d2634ff6a0e89a88e29cf9b90
                        • Opcode Fuzzy Hash: 2c59d956c586637386b851d267094da3af282047a9bf53023292690b53895ada
                        • Instruction Fuzzy Hash: 8AD01232744120274314119EBC94C9BD6DEFADD5F5355457EFA49D3304C8E59C0582B4
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 49bec1adbdd607e6d40542e0f5ee0b269763f6f04078961a161352a179076708
                        • Instruction ID: b7c15f5d6199f36f7ff641d71568f529fc96a3582e1d2df4f696ef0e7959edf5
                        • Opcode Fuzzy Hash: 49bec1adbdd607e6d40542e0f5ee0b269763f6f04078961a161352a179076708
                        • Instruction Fuzzy Hash: 05E0EC721041586F8B41CE89D811CB67BADDB89260704805ABD5486251C672DD229BB0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a2bea8119849f001bb42580bfb82b41fac61e52087c5bebf5b96779c1e721ddd
                        • Instruction ID: 95f205e53beaa1859723d6ba0a3ea102423b3ab39d0a9dbcb8bee970a575c9b0
                        • Opcode Fuzzy Hash: a2bea8119849f001bb42580bfb82b41fac61e52087c5bebf5b96779c1e721ddd
                        • Instruction Fuzzy Hash: 8DE0C2366000046FDB01CE84DD519B67B22EF84220B08C44BFC5D47261C672CD22DB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: abc99ac828a12f083493c7cbd8537dbb3c159c457685001e539f2cda916c9fdd
                        • Instruction ID: 1136eee659b3e0349a351cbc07ae73545605a4fc3656e5d553dde9322b6ed7a3
                        • Opcode Fuzzy Hash: abc99ac828a12f083493c7cbd8537dbb3c159c457685001e539f2cda916c9fdd
                        • Instruction Fuzzy Hash: 7DE08C30E0020EEFCB08FFE4EA849ACB7B9FB04204B1106D9FA459B200EB315E009BC1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a40955db19a3b2b37f047606fe8bd382a2cb0bb64926a973faa4a8bb93b2ecb9
                        • Instruction ID: e4ad736103f53b6f19d816c606a864089fe21238ead15b0e01cbda4d96e3c2ca
                        • Opcode Fuzzy Hash: a40955db19a3b2b37f047606fe8bd382a2cb0bb64926a973faa4a8bb93b2ecb9
                        • Instruction Fuzzy Hash: 80E0EC7550D3D05FD302CB54D890C16BFB5AF8A20471AC8DFE4848B253C6639C0BC7A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 33345dd430e981ad3e99febe637f3f49248713b3d28b576d30223e9878c286b3
                        • Instruction ID: 50bfdc37e323b84f2262770ef0723b59d068c14e0e752136084bfe089ed8787f
                        • Opcode Fuzzy Hash: 33345dd430e981ad3e99febe637f3f49248713b3d28b576d30223e9878c286b3
                        • Instruction Fuzzy Hash: 89E0EC721180505BD254CA48DD52EA7F7EC9B99610F18885FB480D3241C659DD0A87B2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 63173830f5eb16c023416a9024ec1309bf0d88537e2518dac091693de3736b89
                        • Instruction ID: 929b6c086a25c45d6653498d6f6b635744d66586195a5b032caf23e7f2309ddf
                        • Opcode Fuzzy Hash: 63173830f5eb16c023416a9024ec1309bf0d88537e2518dac091693de3736b89
                        • Instruction Fuzzy Hash: 24E02C72608188AFCB01CE80CC108BA3F20EF84210B08808BFC58CB242C632CC21D760
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 41375bccbe077064bf1d046120fcdc115215b589a7d4e5df5d028f8de967c932
                        • Instruction ID: d19b6eddb76321b4b426415ce011a40885fb57beec7ffb9238eae4dc87148ec1
                        • Opcode Fuzzy Hash: 41375bccbe077064bf1d046120fcdc115215b589a7d4e5df5d028f8de967c932
                        • Instruction Fuzzy Hash: B0E08C301092509FC342DF14ED119A7BBF8DF8AA00B18888FF880A7242C6219C1AC7B2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 05e20c9a0ce000f5d9f37b927e42b0c48eff7e5465cb11407a9b36e1037f67cd
                        • Instruction ID: 46d91041117bea2d9c6fd1d2761b744ef2592adafdfb8c58ed5016aa7b7d1922
                        • Opcode Fuzzy Hash: 05e20c9a0ce000f5d9f37b927e42b0c48eff7e5465cb11407a9b36e1037f67cd
                        • Instruction Fuzzy Hash: 72E01275219250AFC202CF64FE51D97BBB59FC5B00B09484AF880E7262C6229D1BC773
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 5a88183ee5192f18c6d227ca9d7cf94a85a58454e1d8d594a2ef596ea8c4abf2
                        • Instruction ID: 575dc4d38da221c2a81cc852da68d132fbbbe71bdbd46fe7423a8ab5b2012fc2
                        • Opcode Fuzzy Hash: 5a88183ee5192f18c6d227ca9d7cf94a85a58454e1d8d594a2ef596ea8c4abf2
                        • Instruction Fuzzy Hash: D0D05EB2901108BFD741EFA8CC02BCBBBFDDB85210F5006AB9508D7320FA36CA1657A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6df2d91cbd17000f0497ad07c0f074e64dfe4ff3899a40bd12f661196ae7275f
                        • Instruction ID: 95a8111cc324e3239f716f01cc2268362f180659a981dbf467f8e2c7cf30711f
                        • Opcode Fuzzy Hash: 6df2d91cbd17000f0497ad07c0f074e64dfe4ff3899a40bd12f661196ae7275f
                        • Instruction Fuzzy Hash: DED05B71940108AFD700DFD4CC027DAB7FDD749314F5006AA9508D7310FA358B0157A3
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 1905db4b4f918e504ace485577c2c9cfac156f2368bb8b1ef919f7f0c36171a1
                        • Instruction ID: 8d2c0514283f140f37e0903821f6e8844f24959b3ef09c059c6ad7bee53a67b5
                        • Opcode Fuzzy Hash: 1905db4b4f918e504ace485577c2c9cfac156f2368bb8b1ef919f7f0c36171a1
                        • Instruction Fuzzy Hash: 3DD05E762182106FE204DA04DC42EB7A7A9EBC4320F24C92FF44083300CA66DC078660
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 791aadaef5f0b3703b011bd2fa2db3cb3f9a06264b776398dd7f71148b80d0ce
                        • Instruction ID: 4264248d254100a91ffdaae0bd49bbfefea7d76f9932b3de7f29c5ff964cd87f
                        • Opcode Fuzzy Hash: 791aadaef5f0b3703b011bd2fa2db3cb3f9a06264b776398dd7f71148b80d0ce
                        • Instruction Fuzzy Hash: 9AE046312082209FC306CB54D840C56BBB2EFC9604B2AC49FE4449B253C6739C0BC762
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: f7f4622edc4f13f9cd1ff3b4465d6f9b39224560bbdbcd499366c5fb73e0e4c4
                        • Instruction ID: 73188f034a62943dac6d77abddca5c3dde1906a41ad39e21483d40f969e0b57b
                        • Opcode Fuzzy Hash: f7f4622edc4f13f9cd1ff3b4465d6f9b39224560bbdbcd499366c5fb73e0e4c4
                        • Instruction Fuzzy Hash: D8D05E721042602BD294D908CC91EA3A7ECEB99210F08884FBC90C3345CA59EC079770
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c5d08335698fa17956e4e9db425e265f7b265f7e0bef76a59fd2acb0ffa39e63
                        • Instruction ID: 8165a32c2816bff3fb3816adc23aa0eec1565abd0a86b4e705196f6ccb410aab
                        • Opcode Fuzzy Hash: c5d08335698fa17956e4e9db425e265f7b265f7e0bef76a59fd2acb0ffa39e63
                        • Instruction Fuzzy Hash: EBE08C325042018FC304DB98D851EAAF3F4EB85700F19C56EE84A9B260EB61EC4AC7A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 7ad7a6b48bb2aee8653e1c287710cf41f3574e2b1cf95bab2c92440089a50c8b
                        • Instruction ID: a2a3622ec3f231f8069d7fc3809cdcd6e939e357b70c1b316db261913d5661a5
                        • Opcode Fuzzy Hash: 7ad7a6b48bb2aee8653e1c287710cf41f3574e2b1cf95bab2c92440089a50c8b
                        • Instruction Fuzzy Hash: FCD05B721141106FD200CE44DE41E9BB7AEDBC4614F048C0EBC0053311C765DC07D671
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a8e6a07dc12e02ad3e5ed504a5308a9fd4191ff32c073443818bcad8348e5d37
                        • Instruction ID: 74bd5e682b91a2d78f462f720d40d5774850364329bd47b2e62bddd07364fa43
                        • Opcode Fuzzy Hash: a8e6a07dc12e02ad3e5ed504a5308a9fd4191ff32c073443818bcad8348e5d37
                        • Instruction Fuzzy Hash: B2D012321001187F8B01CE84DC01CA67B6DEB89260704C056FD1487211C672DD22DBE0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4057dc4db29ac1ff9470b90a362514f290257040dab1a0da7b7bce07972f2a04
                        • Instruction ID: abb7c5721c46776443eda6fdca7002c1ee87a4512f86f14b703abb5063e95163
                        • Opcode Fuzzy Hash: 4057dc4db29ac1ff9470b90a362514f290257040dab1a0da7b7bce07972f2a04
                        • Instruction Fuzzy Hash: 43D017B2509110ABD340CA04E941BA6B7E9DBD9B10F59845EB840A3241E661ED03D672
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a886e1a8de9946ae28673f0fb6429815b0ad893556dabb59b034a9cf5e2d84c2
                        • Instruction ID: 9400a9d3095ffc0a87a2d8a260ba56d1efde9c42215575bdb9c3ed2d5f3c73c6
                        • Opcode Fuzzy Hash: a886e1a8de9946ae28673f0fb6429815b0ad893556dabb59b034a9cf5e2d84c2
                        • Instruction Fuzzy Hash: F4D0C7B22181106FE300CB08DC11CA7BBF8CFA9600B09888FB880E3281D665CC028A72
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: f782b9ab46746214998ac0eddcd6c234bd91ead6baf1556439da91e9ab41bdc5
                        • Instruction ID: e45325a6292ea3dfba9888c2fedbdbce91b6d5fb89a4737ab3a2c9e7f6d0f642
                        • Opcode Fuzzy Hash: f782b9ab46746214998ac0eddcd6c234bd91ead6baf1556439da91e9ab41bdc5
                        • Instruction Fuzzy Hash: 1BD012351493926FC202DA54E814856BBA1AF86100B05888AE490D7292C756D917C7B1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c3ca13f39053886e40b116eb9ac1d5f1af32b600211b8cb349a839fd16688d3d
                        • Instruction ID: d1d1b5fb8e217ab2c37c40605ceeda35f31773a651d33298e2074062527193a7
                        • Opcode Fuzzy Hash: c3ca13f39053886e40b116eb9ac1d5f1af32b600211b8cb349a839fd16688d3d
                        • Instruction Fuzzy Hash: 84D05EB3114010AFE248DB04ED42EE7BBAADBD8B20F08890EF400A3301C666DC03C6B2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 0128bf3128909299cb3519d4f8bee2233335cd3789fed6f7f5e302dba641fd72
                        • Instruction ID: 2051b8102cdb7284f4295703a1f6dc11b6d8ea2c9414acadc8371ae0b5d6d376
                        • Opcode Fuzzy Hash: 0128bf3128909299cb3519d4f8bee2233335cd3789fed6f7f5e302dba641fd72
                        • Instruction Fuzzy Hash: 61D05EB7504010ABD341DA04DD51F97B7AADBE8B10F05C80EB440A3300D762DC168AB2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 492ecc046f32c51e467554d12371a10b5d90d79ecafdb394a9bcbd20166231e9
                        • Instruction ID: 3f56f4ecd5e0b338079e9e5503994182205b8607c1b4f613695e86e7de1899d3
                        • Opcode Fuzzy Hash: 492ecc046f32c51e467554d12371a10b5d90d79ecafdb394a9bcbd20166231e9
                        • Instruction Fuzzy Hash: 34D05EB6214111ABE204CB04ED92F9BB7AADBD8724F14882EB400A3351C66ADC1397B2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9bca9d8a37b847c8587ce9fac789c95e78a7fc9523e73c9facdca9dfd06357fb
                        • Instruction ID: 10fc70f9056014fbf327296ab9700fe520650b3cedc03a3af73b2ff5dd0db147
                        • Opcode Fuzzy Hash: 9bca9d8a37b847c8587ce9fac789c95e78a7fc9523e73c9facdca9dfd06357fb
                        • Instruction Fuzzy Hash: 17D0A7711142116BF204EA04DC82EEBB76DFBD8724F14890EF80293300CB69DC038670
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 64b2ba2016b5002045c6a1c903f9ac64da018a0933748d9b260f3848d35e8e07
                        • Instruction ID: 64b96c1e6fb916d16e919505e50b2d72624302a48e37dde4591efc7bd9d4e957
                        • Opcode Fuzzy Hash: 64b2ba2016b5002045c6a1c903f9ac64da018a0933748d9b260f3848d35e8e07
                        • Instruction Fuzzy Hash: BAD09E762442106BD654D944CC82E97A769EBD9720F54C85AFC5093344C666EC0B9A70
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 37bc17c18e8dbad78fbe36a842ee6e8de1b73eab481aa15e419647a160673e50
                        • Instruction ID: 7dc5010191fe8db87700141b308feff887e8b89600fedb0d800281e29dd56017
                        • Opcode Fuzzy Hash: 37bc17c18e8dbad78fbe36a842ee6e8de1b73eab481aa15e419647a160673e50
                        • Instruction Fuzzy Hash: 83D05EB294010CBB8700DFA89811ADAB7F9DA04214B4005AB9508D3210FA329A0157A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 99248cff0cad7721676bef49d2439dd3e63bc95eaa7ff6d8f5a602382bcae59c
                        • Instruction ID: dae299489347a308a36bdb38eb148b195d8504b614953a3b94ade046eb4d2aec
                        • Opcode Fuzzy Hash: 99248cff0cad7721676bef49d2439dd3e63bc95eaa7ff6d8f5a602382bcae59c
                        • Instruction Fuzzy Hash: 4DD05E72108110AFD701CA04DD91DABB7B9DBDD614B09844FB840A3351C66AEC17CBB2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 5b96e5d7574b5c8a3c375a3c6a865e617fd024e0e72fe748bff03cb5f5575784
                        • Instruction ID: bc1ffc3c9289fb74bbf77c29c995a54ca548668b31326d8ce5f5046c808ad0ce
                        • Opcode Fuzzy Hash: 5b96e5d7574b5c8a3c375a3c6a865e617fd024e0e72fe748bff03cb5f5575784
                        • Instruction Fuzzy Hash: CDD02BB26C95800FC345E204F8A69DB7B65EBA961170C8047E801D7284CD149C05C3B1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 41a02e006f11ba2840915afc25367f5698af17b6a858e956fe2d56c1d1d59e1c
                        • Instruction ID: fb9d580e5f2e54a2e290ae5be09e39237d62cf8074d30957c880bbcfc056cac4
                        • Opcode Fuzzy Hash: 41a02e006f11ba2840915afc25367f5698af17b6a858e956fe2d56c1d1d59e1c
                        • Instruction Fuzzy Hash: 0CD05EB25082506BD280DA44C951AA6B769FBC5214F088C5FE85183301CB65EC0687A0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4d308d6f58d7f715206ffa4ba9009df8aa924008ecaf718519065a4bab9bb909
                        • Instruction ID: 01ff0c0f2e0600cc51d0cd896bcd17ccb7aa5a9a7bd3c9de0f19dc08d74acd6d
                        • Opcode Fuzzy Hash: 4d308d6f58d7f715206ffa4ba9009df8aa924008ecaf718519065a4bab9bb909
                        • Instruction Fuzzy Hash: 16D05EB21042116FD240D904CC81F9BB3ADEBC4620F08880AFC0097304CA66EC0BD670
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9f2d636fdcdef6291f6aa57130ae1ce03e57faebdc15e28fef3324ab8e6e5b98
                        • Instruction ID: 788c08e535e39be1084feb9f722140dd21973a4d305e61b9a649e5a766c8bfef
                        • Opcode Fuzzy Hash: 9f2d636fdcdef6291f6aa57130ae1ce03e57faebdc15e28fef3324ab8e6e5b98
                        • Instruction Fuzzy Hash: 82D09EB91043116BD244D944CC91FE6A369EBD4614F14885AFC6597352C766EC07E6B0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 8ab869af69afa5e3705abfa003fbeb05737d94153e11a484e1e7a4c73e3e153c
                        • Instruction ID: d8e6f52d84d0e9a7535ad6c92223e7db018a165c074aefbb2bfd7201b7f166f6
                        • Opcode Fuzzy Hash: 8ab869af69afa5e3705abfa003fbeb05737d94153e11a484e1e7a4c73e3e153c
                        • Instruction Fuzzy Hash: D3D05E322001187F8B00CE88DC00CA67BADEB89220B04C05AFD5887241CAB2ED22DBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4d3c7f4eb16192193c9630d0f67ce247fced761c16dc7ba2a4c91077c0e9e1c5
                        • Instruction ID: 0e272b7eadb985c83c92797a48508bdcaa4becdbc2c60a71d3b7a8a2d8e60a13
                        • Opcode Fuzzy Hash: 4d3c7f4eb16192193c9630d0f67ce247fced761c16dc7ba2a4c91077c0e9e1c5
                        • Instruction Fuzzy Hash: 8ED05E72158110AFE309DF04ED52EABBBE9DBC9B20F18894EB44097310C666DC17C772
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 324c5ed82e021c1b24f704a9226a2124fe7c20716f59d952c8de7c2962578fb1
                        • Instruction ID: 96d26662ea2a2e1f9db2d28aabdc75c63c27586d5a6ea30f347609f6b094cf3d
                        • Opcode Fuzzy Hash: 324c5ed82e021c1b24f704a9226a2124fe7c20716f59d952c8de7c2962578fb1
                        • Instruction Fuzzy Hash: 32D0A7B61042106BD200DA14DC81E97B39EFBC8314F04880EFC5193301CB6BEC0BD670
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 68cabf9874e8c728db2597e00efcfa9904ccd842c7671e87f184c45bc603a066
                        • Instruction ID: 879cc3bb08e9e9f4d10d5bf34f73f0dccaa811f47ef7e282001bf07f9b5fb543
                        • Opcode Fuzzy Hash: 68cabf9874e8c728db2597e00efcfa9904ccd842c7671e87f184c45bc603a066
                        • Instruction Fuzzy Hash: A1D0A7F62082106BD200D904DC91E97B75DEFC8224F09880EFC4093302CB66EC07C6B0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d9dafbc91fd61fb7dda5e2ccd4ca1d0d3d2008a5acc7278932e935f0fc46f32b
                        • Instruction ID: e2958ecf4390b43b2fef2e9f96b3f054b7a992621e42374f7aa964169e8b41cf
                        • Opcode Fuzzy Hash: d9dafbc91fd61fb7dda5e2ccd4ca1d0d3d2008a5acc7278932e935f0fc46f32b
                        • Instruction Fuzzy Hash: 30D017756042109FD348CA54C842E67B3A9FB89310F15C8AEEC1487310D6A2EC1A87A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9784e73e653d72511946cd66aaaf922483d3554054454414e6758e5d0330ba34
                        • Instruction ID: 30dde671864bd0cdb5737c40ecdb2eba1813594d2845df5015192b882696c4fd
                        • Opcode Fuzzy Hash: 9784e73e653d72511946cd66aaaf922483d3554054454414e6758e5d0330ba34
                        • Instruction Fuzzy Hash: 76C08CB920C1013BD28A8B04DC47B806760EB82324F08C19EA804DB292DB2EC8038220
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d91fb72f532271624e4b63ab608202f7becc5ba4e1a15958770cf365f98084ae
                        • Instruction ID: 10f84772d37deb8e831864f2e5695fe088a5eec24f07d57af4a3b96ad44c14e9
                        • Opcode Fuzzy Hash: d91fb72f532271624e4b63ab608202f7becc5ba4e1a15958770cf365f98084ae
                        • Instruction Fuzzy Hash: 19D05EB29182506FD340DA28CC50862B7A5EBE9600B1AC84BE44483341C662DC0A8660
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: f1ec721d32025762ee0ce10f77d41224b90c0b678124c54e2a3fab10cea1fdb0
                        • Instruction ID: f2c1b1a7f9087548996fd622a8f95126a9eb52e694f516d4b2c54ed005ad460c
                        • Opcode Fuzzy Hash: f1ec721d32025762ee0ce10f77d41224b90c0b678124c54e2a3fab10cea1fdb0
                        • Instruction Fuzzy Hash: B3D05E751083505FD740DA04CC90C62B779EBD5211B15885BEC5083341CB62DC0A8771
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 68cc80cd12b8468ae500a0a92ffa5d327593b84abf2d4c127d425ec345fbf6b7
                        • Instruction ID: 2a314d6d7d61f06d6a53f72eca3112c02da1e29b1b85a2bbfd8705222c03a857
                        • Opcode Fuzzy Hash: 68cc80cd12b8468ae500a0a92ffa5d327593b84abf2d4c127d425ec345fbf6b7
                        • Instruction Fuzzy Hash: 45D012B15082404FC306CF44E962855BBB2AF96504B15888AA9C197352D6628D17C772
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 737ff9e69d928d369deae335180d1aa7288d83d433ece93252b8caa3582d7846
                        • Instruction ID: 7db444d8e4bbb2a3803ca399e924c8cfb21f79214e85059f3fda8aab4ccb8e53
                        • Opcode Fuzzy Hash: 737ff9e69d928d369deae335180d1aa7288d83d433ece93252b8caa3582d7846
                        • Instruction Fuzzy Hash: C4D05E715081109BE641CE94EA90F47FB92DF84A18F08880DB88193355C622DC0BCB72
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: fd34cfeab3a125c14394df33300f95200bf1e2f2cb93bd21e3399e8dabc9cbad
                        • Instruction ID: f73555448fbd0a4252d7030ee4a59fb39f696e8bc3e5e423db8e228f09c95e3b
                        • Opcode Fuzzy Hash: fd34cfeab3a125c14394df33300f95200bf1e2f2cb93bd21e3399e8dabc9cbad
                        • Instruction Fuzzy Hash: 54D0A73180020CEFCB01DFA4D8018CFBBFDDB4924070008E5DA08D3300FA329B115B81
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 900bc0c204bed8e2e80016e0f3fb8a07c9c768743ec84ee12fb8acbb426885fd
                        • Instruction ID: 8d25c1ab5542fd90f2498621f7d7ed740981460508afb1193b0f08077a1133ed
                        • Opcode Fuzzy Hash: 900bc0c204bed8e2e80016e0f3fb8a07c9c768743ec84ee12fb8acbb426885fd
                        • Instruction Fuzzy Hash: 75D0227221000847E640C614DC427C0B322EB80204F0842CAAD2C4B320EB37E802CAA3
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 2ff52314973a5725ab93b91c01b5defdc280380e4ae8e7dc48bab6f548b96632
                        • Instruction ID: 38542810238503523b5cd5d21da3a77a9f2976fef3b128e3854c5cda86e9aa7e
                        • Opcode Fuzzy Hash: 2ff52314973a5725ab93b91c01b5defdc280380e4ae8e7dc48bab6f548b96632
                        • Instruction Fuzzy Hash: 40D0A7721442105FD240DA04CC81EA7B3ADEBD4221F04C80FBC5093340CB69EC07D770
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 1eb336f2c372931e6328133f4de101a9d5c5a76233d5a82a90682cfcd4db4565
                        • Instruction ID: c997219d88a7a58bc6f62eb491ae36405ac62dd444d88e40cbd637531ec0f46e
                        • Opcode Fuzzy Hash: 1eb336f2c372931e6328133f4de101a9d5c5a76233d5a82a90682cfcd4db4565
                        • Instruction Fuzzy Hash: BCD017311082119FD244CE44D911FA7F7E6EFC8704F20880EB88052200C7729C16DBB2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a3ff0591bd12dc940935b9a225d21ac8c21069ccd4af339444e3a98e5445c938
                        • Instruction ID: f00af5488a47054b77501e9bf72407c5f1a6f53bd7352acc1b0e823ab56b92b7
                        • Opcode Fuzzy Hash: a3ff0591bd12dc940935b9a225d21ac8c21069ccd4af339444e3a98e5445c938
                        • Instruction Fuzzy Hash: F7D05E325145118FC310EA58D84099AF3F5EFC9210F04C56FE449A7214EE71DC46C7A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: cba25e2916792093f431562b629f99f503625cdc9a2ca99c2613b4988c68558c
                        • Instruction ID: a5b64f2a78fb6fc41a50ad2b5d26f77a4da32af2973be2c711ae5aca24f88182
                        • Opcode Fuzzy Hash: cba25e2916792093f431562b629f99f503625cdc9a2ca99c2613b4988c68558c
                        • Instruction Fuzzy Hash: 33D0C9349983898FC702DBB4D4949547FA8AE4B7183540CDFD484CF2A2D96AA4548B21
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 36f3cfbd9ebcb13d2308cdbf4e5bd4adc4b47d9f9f3cc4c4fb009b5dc69d78ab
                        • Instruction ID: 2633be6d6f7d52a42bd671aa282fdbc8b0460734c9c7c4e872e4c3db5d23cc26
                        • Opcode Fuzzy Hash: 36f3cfbd9ebcb13d2308cdbf4e5bd4adc4b47d9f9f3cc4c4fb009b5dc69d78ab
                        • Instruction Fuzzy Hash: 24D017B120D3A15FC302CA18D810862BBA5EFC6200709C8AFF8918B352CAA29D16C7A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 888b0b17874b8ba2fcf149d37bab09d29e4351a9561a917030dec0eeaa2f9407
                        • Instruction ID: 944de1442827b01113dc485899fcd2178fa9b697e6244f1d88bb66417716eb71
                        • Opcode Fuzzy Hash: 888b0b17874b8ba2fcf149d37bab09d29e4351a9561a917030dec0eeaa2f9407
                        • Instruction Fuzzy Hash: 6BD01C30204311ABD280DE08C942BA3BBE6EFC8300F218C0EE880432058BA29C13DAA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9ef04ff41df3f32e9faf38250826eb1e33c13fe4550ed0505db236aca005f203
                        • Instruction ID: 5cc0f24fb010fed5eeccc9cc026df643d10440a87b38e0f329f77e3d9223d88c
                        • Opcode Fuzzy Hash: 9ef04ff41df3f32e9faf38250826eb1e33c13fe4550ed0505db236aca005f203
                        • Instruction Fuzzy Hash: 81D09E602092815FC346DB24CC91956BF759F8B11471DC0DAA998CB2A7DA26DC06C725
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d067663ba6232d9aa48632f097b364241f968410e4c9707b1c86d50c2711362b
                        • Instruction ID: 4d7164e0000d392910187900eb151af8ac840e42237c42aca93db6326b9b5833
                        • Opcode Fuzzy Hash: d067663ba6232d9aa48632f097b364241f968410e4c9707b1c86d50c2711362b
                        • Instruction Fuzzy Hash: F0D0C97290110CEB8B41DFA999005DEBBFDDB49200B5045EB9508D7210FA329B1097A2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c3037b028a90d3258492c427fd24ff3c725d9b152360a77267dd1729a1804f97
                        • Instruction ID: d5b843f15e4c527a0eaaf255b1e46653db4ff97549dc027f1c3be588ed986424
                        • Opcode Fuzzy Hash: c3037b028a90d3258492c427fd24ff3c725d9b152360a77267dd1729a1804f97
                        • Instruction Fuzzy Hash: 2FC080A117540457D340C638CD53B81A3D5E750214FD4C954D88CD7356D53DE80F4751
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 09f11ef8703df7aa7b4258d47ccab24d8a8c34e053436d38e0c70cc3b144b0ad
                        • Instruction ID: a59d6dc329e35f690909be001764c4b7739ddac3b6ab637e86a29e1b06e7bc94
                        • Opcode Fuzzy Hash: 09f11ef8703df7aa7b4258d47ccab24d8a8c34e053436d38e0c70cc3b144b0ad
                        • Instruction Fuzzy Hash: 40C012A216400017D244C724CD977957391E790235F58CB24943CD72D5D929D9038755
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 7c0fc5762910b04664bdae928f023b98ac47fc699c54c7a3a723a3e2c6e2ffe7
                        • Instruction ID: b42fb7f2bda1c02b0efed8ce4d17760479046d844e973923bc0a8ecd5e2530ee
                        • Opcode Fuzzy Hash: 7c0fc5762910b04664bdae928f023b98ac47fc699c54c7a3a723a3e2c6e2ffe7
                        • Instruction Fuzzy Hash: D3D0C97290110CEB8B01DFE999005DEBBF9DB49210B5045EB9508D7210FA329B1057A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: cbbf1c4a692e159ab35140395cbd9de21576914da1dfe07a86274252574aae78
                        • Instruction ID: f5a753bc5c4ba7ecd96b8bfdbdea501159e7b4bccc4a7db8c267c70c9aaa8905
                        • Opcode Fuzzy Hash: cbbf1c4a692e159ab35140395cbd9de21576914da1dfe07a86274252574aae78
                        • Instruction Fuzzy Hash: 29D05E7151C2408FC701CF44FA2081EBBA1AFC5A04F198C8EA884A7362C636DC2ACB63
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a9edfc61f4d354bd46813078c2d1224f4111a2517a545698d7a0217239a7141c
                        • Instruction ID: 8bec87df8ac1b564e004022118271befba907fc10d149143925fd996317041d2
                        • Opcode Fuzzy Hash: a9edfc61f4d354bd46813078c2d1224f4111a2517a545698d7a0217239a7141c
                        • Instruction Fuzzy Hash: 16D0C97290110CEB8B01EFE999005EEBBF9DB89200B5049EA9908D7210FA329B10A7A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 71123f12e3f2bc1bc571da0af872a25e8f3ff45786d365472cac3896133392c7
                        • Instruction ID: 915c2f0ab8acda5a4b3138ab59afa210533ebdeeed92456e82a5a65774a6f1ad
                        • Opcode Fuzzy Hash: 71123f12e3f2bc1bc571da0af872a25e8f3ff45786d365472cac3896133392c7
                        • Instruction Fuzzy Hash: 36D0C9752001006BD604C504DC91F93A3A9EB94219F14C029AD49D7750DA29E847D621
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b291d16ec0e40b59ac7760bb89da3e42e78d816cd10a4e4501fdb52253f5ef98
                        • Instruction ID: 0d86ff33fe36922b9b78a28c6bc8c0e2825f335e412d9df2d2d946b58a49f1c6
                        • Opcode Fuzzy Hash: b291d16ec0e40b59ac7760bb89da3e42e78d816cd10a4e4501fdb52253f5ef98
                        • Instruction Fuzzy Hash: 5CD0C97190110CEB8B41EFA999015DEBBF9DB49200B5045EA950CD7210FA329B1557A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3cebc390baa5b50728f4de9116727b92b8ed1af5486c67fdeba598e3adbe8f3a
                        • Instruction ID: e0dbd12dab7314f7785e1db1c48a8d1fc619f9e618121531039e1e2c2073fe47
                        • Opcode Fuzzy Hash: 3cebc390baa5b50728f4de9116727b92b8ed1af5486c67fdeba598e3adbe8f3a
                        • Instruction Fuzzy Hash: 9CD0C97190120CEF8B01DFA8D9008DEBBFDEB49250B1049E6DA09D3210EA729B119B91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 158c2c6a2915c8250e414be7427fa719551a5816af6d83f1bb33dec913699456
                        • Instruction ID: 6a60d334bcaca1e5c7f14684ac1dda052a000856eb1115da8af73e1c9ec8c34a
                        • Opcode Fuzzy Hash: 158c2c6a2915c8250e414be7427fa719551a5816af6d83f1bb33dec913699456
                        • Instruction Fuzzy Hash: 76D0C9713801006BD245C518CC86F93F399DB98215F24C029AC48C7754DA29E9039720
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: f51c0311f5a7f6f3895026bb59ff08106cfa75cca873d278e3fc127762bade13
                        • Instruction ID: f3be8624859a9de9e04916862d1ea0772979245b5a674dd6e16684d0e8add200
                        • Opcode Fuzzy Hash: f51c0311f5a7f6f3895026bb59ff08106cfa75cca873d278e3fc127762bade13
                        • Instruction Fuzzy Hash: B1C0122181F1A05FC25242158C654437F219D8345072940D6A8448B756D9255D16C2E2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d6fef0889c9aaa31941b92ec16846ecc9f7af8360d0856143d92989e4eb68895
                        • Instruction ID: 5e087576d3d8d25242cf86dc7daee72deb6eab295f273cafc38159f681e20c56
                        • Opcode Fuzzy Hash: d6fef0889c9aaa31941b92ec16846ecc9f7af8360d0856143d92989e4eb68895
                        • Instruction Fuzzy Hash: DDD0C97190110CEF8B01EFA999005DEBBF9DB49200B5045EA9508D7210FA329B10A7A2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4df2dbf168ed2e9ad701d317692f5a911fc9c59df525ca5d131a5022b2cec69d
                        • Instruction ID: 1d8800600c7b2ea446af6d53e4a1cdc3b380fd4e095776216b10304a2bd08290
                        • Opcode Fuzzy Hash: 4df2dbf168ed2e9ad701d317692f5a911fc9c59df525ca5d131a5022b2cec69d
                        • Instruction Fuzzy Hash: 79D0C97190110CEB8B01DFA999005DEBBF9DB49200B5049EA9508D7210FA329B1057A2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6415df7e2f24f401bf3e092e1b8d9c04fed46480486da383d81a22c2093a069e
                        • Instruction ID: 894079b56cc75d85cda731651f587ba475074b8a741a64c50055c44d73aa7e9d
                        • Opcode Fuzzy Hash: 6415df7e2f24f401bf3e092e1b8d9c04fed46480486da383d81a22c2093a069e
                        • Instruction Fuzzy Hash: 1ED0C97290110CEB8B41EFA999005DEBBF9DB89200B5045EB9508D7220FA329B155BA1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3de1711e9b1021ce8bceb7f02c17bbcdc8991cebff92fadd735be47f7f2d31eb
                        • Instruction ID: 9cecb634c290987eee2a01a7e53641501062697f687f53601e7eb6792d6338f9
                        • Opcode Fuzzy Hash: 3de1711e9b1021ce8bceb7f02c17bbcdc8991cebff92fadd735be47f7f2d31eb
                        • Instruction Fuzzy Hash: 84D0A7B92081005FC304C714CC51B12B7A1EFD9204F18C459E408CF361C635DC13C710
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 92262c173ceb3cdb7e9cdb423a51190744e9abeda8fa55c654cc5b3e0a5ee115
                        • Instruction ID: 456b690a9ec1d619bcdc16d7d107fb7852f3b5aace2aae3cf13f99d97cc106d6
                        • Opcode Fuzzy Hash: 92262c173ceb3cdb7e9cdb423a51190744e9abeda8fa55c654cc5b3e0a5ee115
                        • Instruction Fuzzy Hash: 06D0C9B66100006BE258CA04CC82B92F3A5EBA4354F24D02DA408C7351EA29DC038610
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 7d103ccc0816a5f366cbb8d8b1980c8751f081598994d0b2ede961849445318a
                        • Instruction ID: 9f6da2ee53ec3118a6f76cbf5686a73055dc9bb3eabc843e7d981d8991992619
                        • Opcode Fuzzy Hash: 7d103ccc0816a5f366cbb8d8b1980c8751f081598994d0b2ede961849445318a
                        • Instruction Fuzzy Hash: A8D0C971A0120CEF8B01DFA999015DEBBF9DB49200B5045EA9508D7210FA729B1057A2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 1637ca9c541b696ea038310d02c892de551e1d2c913786baeb8cfb21b11996ab
                        • Instruction ID: 0dd21ee5cd101c2de0403dc303d90733f7bc4f56974f4547be4d5f89ff7a20ba
                        • Opcode Fuzzy Hash: 1637ca9c541b696ea038310d02c892de551e1d2c913786baeb8cfb21b11996ab
                        • Instruction Fuzzy Hash: D4D05E605192805FD349C7208D16441BFE0AE82104319C5DA8048CB253C527990B8716
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: df07cce90da77658b7b42232a3a62e303793c4780657d37e8e8365f75ef58308
                        • Instruction ID: c84c1f2003033c5ed857059c7bdac02ae7072c0ba2a25d5253aea824d606af7f
                        • Opcode Fuzzy Hash: df07cce90da77658b7b42232a3a62e303793c4780657d37e8e8365f75ef58308
                        • Instruction Fuzzy Hash: 56D0C97694110CEB8B41DFA999005DEBBF9DB49200B5045EA9508D7210FA329B1497A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 11c390fc74fb81705ac5f18cf2b913f703e698b451eeef1d6d43d2c5e9f84606
                        • Instruction ID: 04773bc3c01afdcc297d66c8e6d004f673576d5b3446ef690cc1d9d4c1cfe6d0
                        • Opcode Fuzzy Hash: 11c390fc74fb81705ac5f18cf2b913f703e698b451eeef1d6d43d2c5e9f84606
                        • Instruction Fuzzy Hash: 00D0C9B5340000ABD748CA18CC82B96B7A9DBD8324F14C46D6408C7350EB3AD843CA10
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 791868b2b6d4904eca63423b42afb3773cf3bd7afed7f015f908fe64dc81cf6d
                        • Instruction ID: 1d2c5b51030abd186a83bee4b09449a282c16bbf154cb9b97365610c327b5c4c
                        • Opcode Fuzzy Hash: 791868b2b6d4904eca63423b42afb3773cf3bd7afed7f015f908fe64dc81cf6d
                        • Instruction Fuzzy Hash: B8D0C9712081219F9244CA48E950C6BB7E9DBC9A10B14884EB88493241CA62DC16CBB2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 50e88f8f1ab1261239be22e4f0073d42bd8a0c50fb0e864492094e9cb25175f4
                        • Instruction ID: 7de4d4a2bac3151a655fc3f596ff209eada959ced3ab415550dbea5c53551df6
                        • Opcode Fuzzy Hash: 50e88f8f1ab1261239be22e4f0073d42bd8a0c50fb0e864492094e9cb25175f4
                        • Instruction Fuzzy Hash: 76D0A77160C3814FC341DB54E810846BBA1BFC5210F148C8EEDA0C7352C665DC0BCB62
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 144331daa309386b67828044a79bb151136516cf130f9f4c6891e8fe6b0eb361
                        • Instruction ID: 7a1f6bdf85532e6a075333612baea0ce96a331f78f352e8448691f997d337f23
                        • Opcode Fuzzy Hash: 144331daa309386b67828044a79bb151136516cf130f9f4c6891e8fe6b0eb361
                        • Instruction Fuzzy Hash: 96C08CB21901109BD388C204EC92B74A3A4CBC0320F28807DE004CB300CB2AC8038520
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 8a61ee2da6890e8434c7afa9388e0e0d653b6aed5da164fcf33c5142df86cf07
                        • Instruction ID: 489f06053556b235f0a13c398783ff708b03ebcaeee54f606352d14bdcd41446
                        • Opcode Fuzzy Hash: 8a61ee2da6890e8434c7afa9388e0e0d653b6aed5da164fcf33c5142df86cf07
                        • Instruction Fuzzy Hash: 49C0806215510017D300C624CD93B87F7C5DB51554F18C46D9CC8C7755F736E50B9751
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 2bce915ad2aa5ee57c3ac7770fa3c7c3b7b307eb7715053062339803ec8b24ab
                        • Instruction ID: 1defb8daf6112f1b653e18278acc07a1d785bc42abf34ac509941d9795d1b54f
                        • Opcode Fuzzy Hash: 2bce915ad2aa5ee57c3ac7770fa3c7c3b7b307eb7715053062339803ec8b24ab
                        • Instruction Fuzzy Hash: 31C04C756951045BC244C504CC81B89A65ADB85258F2C945AAC04CB247CB2EE40795A0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a8ed87cf6c1cad34e84aa6f122020ee312765c16ea543d5b941e835435f616c5
                        • Instruction ID: bebfea9c06b69320d066ae5357bb99ba1957f1fb41fb7f81f553439b3a118aa0
                        • Opcode Fuzzy Hash: a8ed87cf6c1cad34e84aa6f122020ee312765c16ea543d5b941e835435f616c5
                        • Instruction Fuzzy Hash: 44D012714D83459FCB528BA094455E53FF0AF53325B0681EBD045CA567C77F4805CF11
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6ac409f5643691fe88f3a87f2c148643931a5ad0ebdf626d782f392bdb07614c
                        • Instruction ID: c91512017855b93ad11f0dea38f993e11351b9f97966f7e611f2726763997b37
                        • Opcode Fuzzy Hash: 6ac409f5643691fe88f3a87f2c148643931a5ad0ebdf626d782f392bdb07614c
                        • Instruction Fuzzy Hash: 8AD0C9305092909FC307DB348814809BBA19E8620571AC4FF9489CF693CB37C807C752
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3ae8d12149b9d8ff19e8609eb290eaf3e2144ec0bfccceb00540ecdc294370ca
                        • Instruction ID: d89756b4b45724fe93f5d8516303ccf2744f3622b5dddbe46408004576ff725b
                        • Opcode Fuzzy Hash: 3ae8d12149b9d8ff19e8609eb290eaf3e2144ec0bfccceb00540ecdc294370ca
                        • Instruction Fuzzy Hash: 22D0C9BA6082415BD254DE44EC41F96B752AB98210F148D09F45097345C626D807CA64
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 30780d21ac5626aebd4aa657eb5fbba2d2412d13310cabe5ca7c37d441a5fb43
                        • Instruction ID: 43989a70d3340258b21a4d90d5123ef353a5b244d34c7b37618f646846708847
                        • Opcode Fuzzy Hash: 30780d21ac5626aebd4aa657eb5fbba2d2412d13310cabe5ca7c37d441a5fb43
                        • Instruction Fuzzy Hash: E9C012B2B041005BC384CA19C862B22B3A5EBE8208F28C42DE5ACCB350EA32ED078644
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: e130d1ede131ea6de138ccf9e8314f810032ddccd8c5799b4040d4fd3cca25a2
                        • Instruction ID: ebd86e6d50ea094704f3368f51ad10403043b9da57f303359829cd7b3d43723b
                        • Opcode Fuzzy Hash: e130d1ede131ea6de138ccf9e8314f810032ddccd8c5799b4040d4fd3cca25a2
                        • Instruction Fuzzy Hash: 2CD0C9753486405FC349CA14CCA6D12BBB59F95211718C0AEA948CB3A2DA66DC02D761
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 5c914b4b09ef402df0a2d9cf769bda8d7be50f87410165fe56300a1b1c2179e6
                        • Instruction ID: a8dc85aeb6b863abffae702e21f46bb365975677ebcddcd1b586e7212a906562
                        • Opcode Fuzzy Hash: 5c914b4b09ef402df0a2d9cf769bda8d7be50f87410165fe56300a1b1c2179e6
                        • Instruction Fuzzy Hash: 9FD0C9B03042059FC704CE04C555B13F7E1AF94314F20C85DAE9887351EB329952DA40
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 517635a1627a4602057e2b9ac6f9875012f4c4e2c592dc20d3b277cb6bf359c5
                        • Instruction ID: 50c39ac22562e3aa9327a0351e6a9e6d235c2cc7acb5031cf7155017a12f161f
                        • Opcode Fuzzy Hash: 517635a1627a4602057e2b9ac6f9875012f4c4e2c592dc20d3b277cb6bf359c5
                        • Instruction Fuzzy Hash: 14D0C9B56083428BE249DA44E941F86FB95EF85314F188C4DE950A7341C76AD81BCA60
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9742d7865735c7252f6c48a7c294f1d1b4f483eb85901c8c33943e63f37f990d
                        • Instruction ID: 48e8204161933d4df9c7b41a33249025f43fd015cf28c75e97648b457401bf24
                        • Opcode Fuzzy Hash: 9742d7865735c7252f6c48a7c294f1d1b4f483eb85901c8c33943e63f37f990d
                        • Instruction Fuzzy Hash: 84D012752081119F9204CF44E940C6BF7E6EFC8B10B14C84EB84053310CA72DC17CBB2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9005c946775b7544fc68c2d5a08b3cc1d00c0dcfc7dd020b2a08f166c7dfcc18
                        • Instruction ID: 366cbf0ff603427b1f2a7544b220caffafaadb52ddd2e4d43ebc6f59fe17f64f
                        • Opcode Fuzzy Hash: 9005c946775b7544fc68c2d5a08b3cc1d00c0dcfc7dd020b2a08f166c7dfcc18
                        • Instruction Fuzzy Hash: 4CD012626199808FD311C320CD27552BFE1EFD2316758C49E8C59C7256D9299C1B8757
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9742d7865735c7252f6c48a7c294f1d1b4f483eb85901c8c33943e63f37f990d
                        • Instruction ID: 48e8204161933d4df9c7b41a33249025f43fd015cf28c75e97648b457401bf24
                        • Opcode Fuzzy Hash: 9742d7865735c7252f6c48a7c294f1d1b4f483eb85901c8c33943e63f37f990d
                        • Instruction Fuzzy Hash: 84D012752081119F9204CF44E940C6BF7E6EFC8B10B14C84EB84053310CA72DC17CBB2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 003a8d49fab3ef96cefc021d90ec13338187ea6bebeecb06c3661f2bca34366c
                        • Instruction ID: 3023557e29b03b597f5008196614d97b0d2b1d434437b0f4548b1f607c3babe5
                        • Opcode Fuzzy Hash: 003a8d49fab3ef96cefc021d90ec13338187ea6bebeecb06c3661f2bca34366c
                        • Instruction Fuzzy Hash: ACC08CB27148405BE300C214CE23B8AB7D2DB90202F58C429918CCB3A2EA2FD8078F54
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6fd5862abba9300e25b077a0ac4af4b5da7c8fab61ce18239a04dd38772a8edf
                        • Instruction ID: 805465856a0e97f1801a7b9e58a9ccc16fe6aa036e262aa7ced1ad80dc8590cd
                        • Opcode Fuzzy Hash: 6fd5862abba9300e25b077a0ac4af4b5da7c8fab61ce18239a04dd38772a8edf
                        • Instruction Fuzzy Hash: 59C012752142125BD254DA04C841D66B3A6FFC8314F14C86EE85083345CF76DC07C7A0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 48fd6629bc711f11b3701e9b83c9fc4c0b32c6ca0b5b210346616d23d1954a9f
                        • Instruction ID: f45822613c76b0a44925d2e38f2948006ed6842d151c2b98395044896fd2099c
                        • Opcode Fuzzy Hash: 48fd6629bc711f11b3701e9b83c9fc4c0b32c6ca0b5b210346616d23d1954a9f
                        • Instruction Fuzzy Hash: 24D0127615D8C00FD742CB288E36591BFB1DB62146718D496C0DCC7363D529DA13DF25
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c286b5b7d00a7a59485a9e8428405238f47bf39e8605897047ac5bf342f4bcfe
                        • Instruction ID: 016a94060a3184cd9e75da7a96e3e15d18ac40e0ba29fca689acb053c7499eac
                        • Opcode Fuzzy Hash: c286b5b7d00a7a59485a9e8428405238f47bf39e8605897047ac5bf342f4bcfe
                        • Instruction Fuzzy Hash: 2AC0127A1404006BC200DA40CC91F46F35ADB85215F18C4596D084A352CB3BE803E760
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c50758f6add578cda66f7859f5146ab4a7cf2d53f5b972ac3f00ee6f97bd2044
                        • Instruction ID: 2ed5b714505d6a866ca1b7313636a6f1c4d465cc1c6e32cd5579e86c2b8f38a8
                        • Opcode Fuzzy Hash: c50758f6add578cda66f7859f5146ab4a7cf2d53f5b972ac3f00ee6f97bd2044
                        • Instruction Fuzzy Hash: 68C002725992818FCB02CB64E4944C47FB1BE0322436519D6C081CF466C2666959DB12
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d6c10cc1f601b290de3fc80e3c0d3b5c6df3ed58571c15a48cb35284795fe3a9
                        • Instruction ID: 9b3b9f8bcdb9967aea4756bb9b14a8d15cd048d7db735a6931b91ed981269229
                        • Opcode Fuzzy Hash: d6c10cc1f601b290de3fc80e3c0d3b5c6df3ed58571c15a48cb35284795fe3a9
                        • Instruction Fuzzy Hash: 8FB0922609890C97C6A122A1EDABB827659C38069DF880411A25DD0280E98A901089DA
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4e31e6ba73d6f4f1c5cd9d65ba74e306a8f45ebe5a0872f7b07ad459322396a3
                        • Instruction ID: 0677fab2d2008ad029454bdf721bb5aeecc6da57759a7e3964652b99a3ca1c2a
                        • Opcode Fuzzy Hash: 4e31e6ba73d6f4f1c5cd9d65ba74e306a8f45ebe5a0872f7b07ad459322396a3
                        • Instruction Fuzzy Hash: BFD0C06112C9800FC300C328CD26500BFA0D7C2105748C59BC008C739BD625D807C709
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9742d7865735c7252f6c48a7c294f1d1b4f483eb85901c8c33943e63f37f990d
                        • Instruction ID: 48e8204161933d4df9c7b41a33249025f43fd015cf28c75e97648b457401bf24
                        • Opcode Fuzzy Hash: 9742d7865735c7252f6c48a7c294f1d1b4f483eb85901c8c33943e63f37f990d
                        • Instruction Fuzzy Hash: 84D012752081119F9204CF44E940C6BF7E6EFC8B10B14C84EB84053310CA72DC17CBB2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9742d7865735c7252f6c48a7c294f1d1b4f483eb85901c8c33943e63f37f990d
                        • Instruction ID: 48e8204161933d4df9c7b41a33249025f43fd015cf28c75e97648b457401bf24
                        • Opcode Fuzzy Hash: 9742d7865735c7252f6c48a7c294f1d1b4f483eb85901c8c33943e63f37f990d
                        • Instruction Fuzzy Hash: 84D012752081119F9204CF44E940C6BF7E6EFC8B10B14C84EB84053310CA72DC17CBB2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: fb42ab4dd06629ae54579f13deaff66fcf72e72c536d30d793511b7075db95d4
                        • Instruction ID: 2ec0d4bba9cf9f56250ff064777c9e4558b63e1fcd6bcf8178ec7b2615e78ca2
                        • Opcode Fuzzy Hash: fb42ab4dd06629ae54579f13deaff66fcf72e72c536d30d793511b7075db95d4
                        • Instruction Fuzzy Hash: C4D0C9302012019BC344CA18C546B96F7E5EF84340F24C81DECC887252EB72E953DB00
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: ecb07f04f41d83f2a192a221f96e4f0641c4d050b7a5f51d96f7b73211d41a0b
                        • Instruction ID: aea81ccb60d0660009953389cd789c58996962b7aa430bddbeda75f616325b36
                        • Opcode Fuzzy Hash: ecb07f04f41d83f2a192a221f96e4f0641c4d050b7a5f51d96f7b73211d41a0b
                        • Instruction Fuzzy Hash: 22C080E255944007E304D754CD53BC17BD1D791355F1CC45A8408CA35BD52DD5038715
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9742d7865735c7252f6c48a7c294f1d1b4f483eb85901c8c33943e63f37f990d
                        • Instruction ID: 48e8204161933d4df9c7b41a33249025f43fd015cf28c75e97648b457401bf24
                        • Opcode Fuzzy Hash: 9742d7865735c7252f6c48a7c294f1d1b4f483eb85901c8c33943e63f37f990d
                        • Instruction Fuzzy Hash: 84D012752081119F9204CF44E940C6BF7E6EFC8B10B14C84EB84053310CA72DC17CBB2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 95a9192547d5d4466bc5675efefc857791d5f8b92f455af173e0171a3985eda1
                        • Instruction ID: 28bd1ac3d0e40c2b6ee38a8a0a6dd547eece99bd306496029acec5937db91565
                        • Opcode Fuzzy Hash: 95a9192547d5d4466bc5675efefc857791d5f8b92f455af173e0171a3985eda1
                        • Instruction Fuzzy Hash: 19D0C9752041005BD344CA18C846B56B3A5DFD4314F18C42E6408C7355DA35D802CB10
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b42eb4a4237f3f300b34101a9c64c7a2a34653e472d88958374a96a308d26003
                        • Instruction ID: 0a79cfcc9f3950630def7aa8d5064f7db411a5ec17eeb1af5eeabda724e68817
                        • Opcode Fuzzy Hash: b42eb4a4237f3f300b34101a9c64c7a2a34653e472d88958374a96a308d26003
                        • Instruction Fuzzy Hash: 8EC012752082209F9244DA08C840C66B3AAFBC8210B14C84EE85083300CBA2EC07CBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b42eb4a4237f3f300b34101a9c64c7a2a34653e472d88958374a96a308d26003
                        • Instruction ID: 0a79cfcc9f3950630def7aa8d5064f7db411a5ec17eeb1af5eeabda724e68817
                        • Opcode Fuzzy Hash: b42eb4a4237f3f300b34101a9c64c7a2a34653e472d88958374a96a308d26003
                        • Instruction Fuzzy Hash: 8EC012752082209F9244DA08C840C66B3AAFBC8210B14C84EE85083300CBA2EC07CBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b42eb4a4237f3f300b34101a9c64c7a2a34653e472d88958374a96a308d26003
                        • Instruction ID: 0a79cfcc9f3950630def7aa8d5064f7db411a5ec17eeb1af5eeabda724e68817
                        • Opcode Fuzzy Hash: b42eb4a4237f3f300b34101a9c64c7a2a34653e472d88958374a96a308d26003
                        • Instruction Fuzzy Hash: 8EC012752082209F9244DA08C840C66B3AAFBC8210B14C84EE85083300CBA2EC07CBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: f9c05c2fcf9d6b8fe006144c6d44b65d2ac35fb5151cfac1c1645db62ac05c87
                        • Instruction ID: ceb22a65fbcef1104feb828abbad0c87ee589d44de14837dd1b7e527c20ecb28
                        • Opcode Fuzzy Hash: f9c05c2fcf9d6b8fe006144c6d44b65d2ac35fb5151cfac1c1645db62ac05c87
                        • Instruction Fuzzy Hash: E1C08C301085802FC742871CCDA05997F618B86549B08C0DBAC68CB313CB26A807EA20
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4ddd86420239c385e350810519e50d1f9066134e51f5cb8fdd640d37cb452926
                        • Instruction ID: 95a258553018e47bae065afdf0611572add843eb260617a5d55c0c00c023034a
                        • Opcode Fuzzy Hash: 4ddd86420239c385e350810519e50d1f9066134e51f5cb8fdd640d37cb452926
                        • Instruction Fuzzy Hash: C2C08CAAA091000FC302C635DC91741BB90AB8A204F2CC0AAC4C5CA316EA26CD038780
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: ac253ca3a7491959ee661a0617dbb4c260de3c20d617b406e6ad1ac18fa6dbe0
                        • Instruction ID: fce072dfab8e3f33850c76d2e45515058e1c89a97819f04693fc45fe1763d7a3
                        • Opcode Fuzzy Hash: ac253ca3a7491959ee661a0617dbb4c260de3c20d617b406e6ad1ac18fa6dbe0
                        • Instruction Fuzzy Hash: 46C09B715354005BC795C704CC9778BB791FF85615F5CC858A405C7745DB72D403458E
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a729a73c2c54459640a1fbe882adbf307a269fb367cb912f7f731aaaaefdc28f
                        • Instruction ID: b9ea458f600aac2ee37b0f84a0c28180d3fe5031b0468ab4b54fb808c22a54df
                        • Opcode Fuzzy Hash: a729a73c2c54459640a1fbe882adbf307a269fb367cb912f7f731aaaaefdc28f
                        • Instruction Fuzzy Hash: 9FD0123450E3A0AFC346AF24C8A1586BBB1AE8260432880CEB999CF153CB228D1AC751
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 816615b9cc424252631efaf26adb54655a41f2b7768f6144383eee85856304e8
                        • Instruction ID: d2e3e81d8a450f5f1d3084d0080cb6bc3436c68ac3b78128a395d948f1ad0235
                        • Opcode Fuzzy Hash: 816615b9cc424252631efaf26adb54655a41f2b7768f6144383eee85856304e8
                        • Instruction Fuzzy Hash: EEC0127250E1805FC7468B24CC90944BB31DE82105319C8DBA808CF25BCB369C078AA1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 0709b9e485c0c33ffc7363576b2f2bdccb5fb9a3765cea8a88c078916fedfc8d
                        • Instruction ID: b74d50899df04f6170752b75d2214b188be4734201595416dc4c9dec0128c1c3
                        • Opcode Fuzzy Hash: 0709b9e485c0c33ffc7363576b2f2bdccb5fb9a3765cea8a88c078916fedfc8d
                        • Instruction Fuzzy Hash: A4C08C7B1022008FC720CE54D98138DF3E0EF80314F20888DA89C87100CB329A429A10
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 104b4f93b23b0bd2ba8dbf5ac0c242e69de45780656e5f1d630701bb0a38c2f9
                        • Instruction ID: e66bde2b149eeda6f27e1ca04649765e8013a7e3877108b06316ee70f5a3c35a
                        • Opcode Fuzzy Hash: 104b4f93b23b0bd2ba8dbf5ac0c242e69de45780656e5f1d630701bb0a38c2f9
                        • Instruction Fuzzy Hash: 23D012301093808FC7034B10CC515827B709F4220031940CBA440CF163D7268D06C7A2
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6d76c7dc811be7bfd95bcdb4ca2aaf45acfcd36b47acdbb8cd907d20647c81e0
                        • Instruction ID: 30024a2c25b9c44bac1e8bc056628a2d2047c8e1d60d5deb4ae9dd84b29c17d4
                        • Opcode Fuzzy Hash: 6d76c7dc811be7bfd95bcdb4ca2aaf45acfcd36b47acdbb8cd907d20647c81e0
                        • Instruction Fuzzy Hash: 59C08C7010A3C09FC31B8B308D61892BF70ADC3204B2A81CAEDF8871A3C7124A27C792
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b42eb4a4237f3f300b34101a9c64c7a2a34653e472d88958374a96a308d26003
                        • Instruction ID: 0a79cfcc9f3950630def7aa8d5064f7db411a5ec17eeb1af5eeabda724e68817
                        • Opcode Fuzzy Hash: b42eb4a4237f3f300b34101a9c64c7a2a34653e472d88958374a96a308d26003
                        • Instruction Fuzzy Hash: 8EC012752082209F9244DA08C840C66B3AAFBC8210B14C84EE85083300CBA2EC07CBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 93135c2c0a5a95b9d575eade94d56e1bc0021bf281749c9e025cc2312f80d76b
                        • Instruction ID: 8a21aebf73b38ac8274aac47ed782952a1308ddfe51144eb35de9de64adacf8e
                        • Opcode Fuzzy Hash: 93135c2c0a5a95b9d575eade94d56e1bc0021bf281749c9e025cc2312f80d76b
                        • Instruction Fuzzy Hash: 24C04CB55541005BD24D9604DC92B85B355DBC9325F19859DA404DB649CB2ED843D550
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a3ad21c58062a252f219bd5beeb8d6fd70f6fb37f5597143cc35813322b6d78a
                        • Instruction ID: 41104b9eb152124162639d5ccf06008ceed630f4c65eacc5ef4e8db9806132a8
                        • Opcode Fuzzy Hash: a3ad21c58062a252f219bd5beeb8d6fd70f6fb37f5597143cc35813322b6d78a
                        • Instruction Fuzzy Hash: 20C04C793001019B8244C618CCD5D57F7EADBD9224714C46D6849C7355DF36EC03D660
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 55997e1a819ce5df6e086e32f9f33e1cc69333347ac22153bd3d2decdbcbd82f
                        • Instruction ID: 76f3a3f958337b15988ad78404043ec7ae9e365c19c11a023a5df1ac96d83512
                        • Opcode Fuzzy Hash: 55997e1a819ce5df6e086e32f9f33e1cc69333347ac22153bd3d2decdbcbd82f
                        • Instruction Fuzzy Hash: AEC09B6518000067C1408911DCD5BC5736CD7C4114F1884557C188A351F76FE71F5921
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: df7efe1677034bd216e9f680d3872fc1e8c2ea08f85c68627981a8fc0256be0b
                        • Instruction ID: cb3f870f9e4edd45e311af8aba4ad2923896ece08fe1e1e2b3f6b4c0682976b7
                        • Opcode Fuzzy Hash: df7efe1677034bd216e9f680d3872fc1e8c2ea08f85c68627981a8fc0256be0b
                        • Instruction Fuzzy Hash: CAC08C3020E3C00FC386C354CC9A405FF61AB86214308C0DFAD04CF2D3DA22A8068342
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 02ae3498f3795bc107cbcac4c7fe91dfd4412b820114791415adb220a0574150
                        • Instruction ID: 9db11f429996e84aeceacb4a50e5555df071fb2052fa22f93afeca813bfdf5a2
                        • Opcode Fuzzy Hash: 02ae3498f3795bc107cbcac4c7fe91dfd4412b820114791415adb220a0574150
                        • Instruction Fuzzy Hash: E9C09221120C0057EA9A8714CD9BBC7F361EB8222AFE8C099D8088A349DE22D8039789
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: fde3428991770966bb53feba0ccc799f992805dd5fc47cad29fc9f68b3684802
                        • Instruction ID: ee96e77bba28fe1bc1c85878bc0fb4dc418f8e3ffae8ef4ee6295fb0f809e045
                        • Opcode Fuzzy Hash: fde3428991770966bb53feba0ccc799f992805dd5fc47cad29fc9f68b3684802
                        • Instruction Fuzzy Hash: 98D012A12082C08FE302C76888A2852BF61CF5221A319C4FAD985CE157CA26D803CB60
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 325c4bf9171c3c309292bd07a9782050c03e919c9b8372a55e1c9555d87f8680
                        • Instruction ID: 27ac0ff663062924e77c048b8d15b462fb9e190848e3e359bff61b6993f0c554
                        • Opcode Fuzzy Hash: 325c4bf9171c3c309292bd07a9782050c03e919c9b8372a55e1c9555d87f8680
                        • Instruction Fuzzy Hash: B1C02B391028004BC344C600DCD2FC1B370EB84210F1CC459DC55C7740C766F803EE00
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: cfc31e02d3c7f1f62c294fd080c61c0be8a573c469fa50fbcf7afe7509a2c240
                        • Instruction ID: 7d784141e51900f910069fc53b2d9f605c17dd0de8fbbadbfc148ee27d95c9da
                        • Opcode Fuzzy Hash: cfc31e02d3c7f1f62c294fd080c61c0be8a573c469fa50fbcf7afe7509a2c240
                        • Instruction Fuzzy Hash: CFC09BA92910009FC1418500DCC1BC17368D7C0335F1C84556C0C86341C72EFD1F5920
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 7bb8431a79384acff877fd65d027070eb037a3372822c2755a786fe19539c12e
                        • Instruction ID: d621349956d647cede49999f38e9a54c7f5942f5fda929d9ec2ad5ce73786d97
                        • Opcode Fuzzy Hash: 7bb8431a79384acff877fd65d027070eb037a3372822c2755a786fe19539c12e
                        • Instruction Fuzzy Hash: D1C09BE594000057D7058500DDD2FC5F718D741255F39C954AC04B7741C71EE407A660
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 99555da6c4403c21c48f2e69c709780a254b99aa3882a6fccf620a548c5d6deb
                        • Instruction ID: 90c1bdf678404919281df3503753a41c3c156a1d2d5b23b0dacdc541b2ea208b
                        • Opcode Fuzzy Hash: 99555da6c4403c21c48f2e69c709780a254b99aa3882a6fccf620a548c5d6deb
                        • Instruction Fuzzy Hash: D0C092B3A5204057C3818A60E892798F720DB92624F69D99BD418DB351EB23DA039610
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 39eb49abe40af83b0a2214012213cd70c8c8ec71c3d866d892f0ec99ed23ca19
                        • Instruction ID: 823e92f00e852fe77de370bac2b6c42940074a60b8bc7c2992a0252c92a4b5ff
                        • Opcode Fuzzy Hash: 39eb49abe40af83b0a2214012213cd70c8c8ec71c3d866d892f0ec99ed23ca19
                        • Instruction Fuzzy Hash: 52C0123020A3808FC3028B10C852442BBB0AF4235032981CAA8848F163C7228A2AC7A1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 45d96db82241ace8b3404e8141ee972e44387ca5ed6ed36f89301c5e12e01fea
                        • Instruction ID: d695111cadc7e346bdea756288aa3acaf6df0b554b164397c3cbd02841404564
                        • Opcode Fuzzy Hash: 45d96db82241ace8b3404e8141ee972e44387ca5ed6ed36f89301c5e12e01fea
                        • Instruction Fuzzy Hash: A1C09B737544105BD344C744CC427547391D794315F59C15D7815D73C5DF26D5034544
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: e6beb3d9e345dbaf78c209d59b280eba9d85c354e919fb0ee7983f519964a762
                        • Instruction ID: 73f3f61fb31126242513e555b5c604516e98ffe607b15f1fa9799423150fb5e8
                        • Opcode Fuzzy Hash: e6beb3d9e345dbaf78c209d59b280eba9d85c354e919fb0ee7983f519964a762
                        • Instruction Fuzzy Hash: 94C04CB11044505BD3488B0CCD52B54A361EB85319F19C599A405CB257CF26D8138558
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: e36efc4efabc2ec9d42a5b7d5223a54fec5001f0f315609e4adcd7c6efa3a366
                        • Instruction ID: 27d711a2ff7ec875fffe58616eb8f3039e4dcd824a18d49c177e5a95d52a9100
                        • Opcode Fuzzy Hash: e36efc4efabc2ec9d42a5b7d5223a54fec5001f0f315609e4adcd7c6efa3a366
                        • Instruction Fuzzy Hash: DCC09B321054405BC3D58654CC51BD5BB91DFC5608F58C4EC6459C7345CF27E5079548
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: d93c6152a98feccdc1a18962936e7760c512e3f0122b1312954f2aa575612c0a
                        • Instruction ID: ab55e3124ebbba6a89b6ee70a0585b410c03907bb5030b02f026b7d363075aa6
                        • Opcode Fuzzy Hash: d93c6152a98feccdc1a18962936e7760c512e3f0122b1312954f2aa575612c0a
                        • Instruction Fuzzy Hash: A1C04C70606301ABC7548E18C551785F3E1EF85314F64985DECC48B54EDB72A953AA41
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c464d8eb1a5c59412cb3319d31b4ff4bd63126d4a2c4db5d5635d81be2ba9ca1
                        • Instruction ID: ebf0a177d16475f01e5aeb917df9eaa9aa9fb3f1032c0b54fa9aa5a27c6c9adb
                        • Opcode Fuzzy Hash: c464d8eb1a5c59412cb3319d31b4ff4bd63126d4a2c4db5d5635d81be2ba9ca1
                        • Instruction Fuzzy Hash: BFC09BD245D5819BE3554230DD9B9E27F219FD214471DC0E55494952D2E703D522C195
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction ID: 60a72056a403d9f31dd85fef4a7a76d12bb133d0d450fb6ef353260f5a4d9492
                        • Opcode Fuzzy Hash: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction Fuzzy Hash: 0BC09274300100AF8348CA18C895C26F7E6EFD8214B24C46DB84DC7365EF32EC03CA10
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction ID: 60a72056a403d9f31dd85fef4a7a76d12bb133d0d450fb6ef353260f5a4d9492
                        • Opcode Fuzzy Hash: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction Fuzzy Hash: 0BC09274300100AF8348CA18C895C26F7E6EFD8214B24C46DB84DC7365EF32EC03CA10
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction ID: 60a72056a403d9f31dd85fef4a7a76d12bb133d0d450fb6ef353260f5a4d9492
                        • Opcode Fuzzy Hash: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction Fuzzy Hash: 0BC09274300100AF8348CA18C895C26F7E6EFD8214B24C46DB84DC7365EF32EC03CA10
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction ID: 60a72056a403d9f31dd85fef4a7a76d12bb133d0d450fb6ef353260f5a4d9492
                        • Opcode Fuzzy Hash: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction Fuzzy Hash: 0BC09274300100AF8348CA18C895C26F7E6EFD8214B24C46DB84DC7365EF32EC03CA10
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a102d77546f2df4d2edd55d1b9b00ef17abcf4c311f95a02ed5d7cfddff4ea98
                        • Instruction ID: 34c93e32cd02a0196e070770ebf217c7af7756245eb91e2bfbce2830e0e6b68d
                        • Opcode Fuzzy Hash: a102d77546f2df4d2edd55d1b9b00ef17abcf4c311f95a02ed5d7cfddff4ea98
                        • Instruction Fuzzy Hash: 05C04C701002028FD7208E50C693781F7E0EF54215F248C8DED8446141EB3294939A40
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction ID: 60a72056a403d9f31dd85fef4a7a76d12bb133d0d450fb6ef353260f5a4d9492
                        • Opcode Fuzzy Hash: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction Fuzzy Hash: 0BC09274300100AF8348CA18C895C26F7E6EFD8214B24C46DB84DC7365EF32EC03CA10
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction ID: 60a72056a403d9f31dd85fef4a7a76d12bb133d0d450fb6ef353260f5a4d9492
                        • Opcode Fuzzy Hash: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction Fuzzy Hash: 0BC09274300100AF8348CA18C895C26F7E6EFD8214B24C46DB84DC7365EF32EC03CA10
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction ID: 60a72056a403d9f31dd85fef4a7a76d12bb133d0d450fb6ef353260f5a4d9492
                        • Opcode Fuzzy Hash: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction Fuzzy Hash: 0BC09274300100AF8348CA18C895C26F7E6EFD8214B24C46DB84DC7365EF32EC03CA10
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction ID: 60a72056a403d9f31dd85fef4a7a76d12bb133d0d450fb6ef353260f5a4d9492
                        • Opcode Fuzzy Hash: 16581dba91a5fda841cf47983153eb36e4fc24851952f78b75638f70de6cde10
                        • Instruction Fuzzy Hash: 0BC09274300100AF8348CA18C895C26F7E6EFD8214B24C46DB84DC7365EF32EC03CA10
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: cdfec89ecf4d227c2e3f2741df1fca2c4e7a0756e2f1ba050c9a008d3bdc9887
                        • Instruction ID: e80b9cbb32ce7aa80f269217a2acaa4f8c5de131eb2df65f765f3a476441bad2
                        • Opcode Fuzzy Hash: cdfec89ecf4d227c2e3f2741df1fca2c4e7a0756e2f1ba050c9a008d3bdc9887
                        • Instruction Fuzzy Hash: 3DB002747054005B8748D65DD951515A7D29BC9215728C4AD641DC7355DE22DD039644
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b71a5da1c60d140afc6cf8e6d021bb768f3c966add78e67da42fa19769b64692
                        • Instruction ID: 55e0d4cfd635fca78d9dcf3d3567556a6213a415045d97ab4434d8c06aed3da9
                        • Opcode Fuzzy Hash: b71a5da1c60d140afc6cf8e6d021bb768f3c966add78e67da42fa19769b64692
                        • Instruction Fuzzy Hash: 7CC02BD040C3C50FC30643309C71015BF315DD3111B2940DD8CE4420E3D7862A3ED342
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 2e912db415a949afbaac0b9107b2bfa406836db5208f5a4cab6a0cbbddc6d4da
                        • Instruction ID: dd29c0677780b55d050d016fa5ab422963c699e8c5d816372c22799f28c1956f
                        • Opcode Fuzzy Hash: 2e912db415a949afbaac0b9107b2bfa406836db5208f5a4cab6a0cbbddc6d4da
                        • Instruction Fuzzy Hash: ABB012BA1053034DCA310DD095023DDB2E0AF00250F10080D94E811440E72400A05540
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction ID: 424522431131923360a2424e5b60fcaca403654da384226d21dcd1d1d325544f
                        • Opcode Fuzzy Hash: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction Fuzzy Hash: B3A001746050109B8689DA58D991818B7A2ABC9219728C4ADA819CB25ACF33E9039A44
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction ID: 424522431131923360a2424e5b60fcaca403654da384226d21dcd1d1d325544f
                        • Opcode Fuzzy Hash: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction Fuzzy Hash: B3A001746050109B8689DA58D991818B7A2ABC9219728C4ADA819CB25ACF33E9039A44
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction ID: 424522431131923360a2424e5b60fcaca403654da384226d21dcd1d1d325544f
                        • Opcode Fuzzy Hash: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction Fuzzy Hash: B3A001746050109B8689DA58D991818B7A2ABC9219728C4ADA819CB25ACF33E9039A44
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction ID: 424522431131923360a2424e5b60fcaca403654da384226d21dcd1d1d325544f
                        • Opcode Fuzzy Hash: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction Fuzzy Hash: B3A001746050109B8689DA58D991818B7A2ABC9219728C4ADA819CB25ACF33E9039A44
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: eb22c093aa55a81c49811c66a9be499cfe8b8626d488fba47316ae9cb8c488ec
                        • Instruction ID: 9bef2f01831d1597c61823547e3bf0f165648d353712daa728a60441c20c5bc5
                        • Opcode Fuzzy Hash: eb22c093aa55a81c49811c66a9be499cfe8b8626d488fba47316ae9cb8c488ec
                        • Instruction Fuzzy Hash: 0290023244460D8B495027977449596B75C9544515B818061A54E819065AAB64104A96
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: fb1ffc57a43f4adf0fec6b8311eab2730d2eb1d339d5b74074dbc715bf5de821
                        • Instruction ID: a8e5549dfea84163f72d1236d283dc4bbedac5195c112faf63109aed907730ca
                        • Opcode Fuzzy Hash: fb1ffc57a43f4adf0fec6b8311eab2730d2eb1d339d5b74074dbc715bf5de821
                        • Instruction Fuzzy Hash: EB9022300C020C8B00002380B008800B3AC80800883880000E00C000000A0020200080
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction ID: 424522431131923360a2424e5b60fcaca403654da384226d21dcd1d1d325544f
                        • Opcode Fuzzy Hash: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction Fuzzy Hash: B3A001746050109B8689DA58D991818B7A2ABC9219728C4ADA819CB25ACF33E9039A44
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction ID: 424522431131923360a2424e5b60fcaca403654da384226d21dcd1d1d325544f
                        • Opcode Fuzzy Hash: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction Fuzzy Hash: B3A001746050109B8689DA58D991818B7A2ABC9219728C4ADA819CB25ACF33E9039A44
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction ID: 424522431131923360a2424e5b60fcaca403654da384226d21dcd1d1d325544f
                        • Opcode Fuzzy Hash: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction Fuzzy Hash: B3A001746050109B8689DA58D991818B7A2ABC9219728C4ADA819CB25ACF33E9039A44
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction ID: 424522431131923360a2424e5b60fcaca403654da384226d21dcd1d1d325544f
                        • Opcode Fuzzy Hash: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction Fuzzy Hash: B3A001746050109B8689DA58D991818B7A2ABC9219728C4ADA819CB25ACF33E9039A44
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction ID: 424522431131923360a2424e5b60fcaca403654da384226d21dcd1d1d325544f
                        • Opcode Fuzzy Hash: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction Fuzzy Hash: B3A001746050109B8689DA58D991818B7A2ABC9219728C4ADA819CB25ACF33E9039A44
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction ID: 424522431131923360a2424e5b60fcaca403654da384226d21dcd1d1d325544f
                        • Opcode Fuzzy Hash: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction Fuzzy Hash: B3A001746050109B8689DA58D991818B7A2ABC9219728C4ADA819CB25ACF33E9039A44
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction ID: 424522431131923360a2424e5b60fcaca403654da384226d21dcd1d1d325544f
                        • Opcode Fuzzy Hash: 848e7b2b3d1d7438aceb18ee9ce77d60f8a3148b9db338e3d364b5add5ce48b1
                        • Instruction Fuzzy Hash: B3A001746050109B8689DA58D991818B7A2ABC9219728C4ADA819CB25ACF33E9039A44
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 584a3913bed7d41f6751d29dc0af2e109adf5df94d8de11209de24b86f245c04
                        • Instruction ID: 2108930940694c1c8b8ad4272d9396267f2db374b9021a0985f6588530823504
                        • Opcode Fuzzy Hash: 584a3913bed7d41f6751d29dc0af2e109adf5df94d8de11209de24b86f245c04
                        • Instruction Fuzzy Hash: 6BA002742010009BC644DB54C991814F761EFC5219728C4DDA8198B256CF33ED03DA40
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 584a3913bed7d41f6751d29dc0af2e109adf5df94d8de11209de24b86f245c04
                        • Instruction ID: 2108930940694c1c8b8ad4272d9396267f2db374b9021a0985f6588530823504
                        • Opcode Fuzzy Hash: 584a3913bed7d41f6751d29dc0af2e109adf5df94d8de11209de24b86f245c04
                        • Instruction Fuzzy Hash: 6BA002742010009BC644DB54C991814F761EFC5219728C4DDA8198B256CF33ED03DA40
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: 1
                        • API String ID: 0-2212294583
                        • Opcode ID: f531b8d672514db18eef99ab24ee9496a27681c11d100c6b0f7cb5827328e72d
                        • Instruction ID: 0057575d9ae1db08904ab552f4a3046df6750c9f64b559ffc3237fb18335a036
                        • Opcode Fuzzy Hash: f531b8d672514db18eef99ab24ee9496a27681c11d100c6b0f7cb5827328e72d
                        • Instruction Fuzzy Hash: 59A1FF7A8633559FC74A8F74C8811803BF0FF17A2D32905EDD8A18E062E277695BDB52
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID: @
                        • API String ID: 0-2766056989
                        • Opcode ID: 298d2281b64b4901941079dea22314c1a2a2749aa69bcc1ba38342f07cbb4411
                        • Instruction ID: 9b7f6656c4b878a356d6c812d81bf58694097ebbbbbee459e70be5e5a33aa2f2
                        • Opcode Fuzzy Hash: 298d2281b64b4901941079dea22314c1a2a2749aa69bcc1ba38342f07cbb4411
                        • Instruction Fuzzy Hash: D3A14FB471160A8FE744EB24F5B5ABA33E6FBC8340B15457AD8068B758DF70AC41CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: f33108c26b273d60d6529631baf12d0fcdd3c67ed3c567ef8927c2b2eb4ab067
                        • Instruction ID: 5ff00fdb86934e5b88467c24938958390db745e367db3eaa61c2423cc3291acb
                        • Opcode Fuzzy Hash: f33108c26b273d60d6529631baf12d0fcdd3c67ed3c567ef8927c2b2eb4ab067
                        • Instruction Fuzzy Hash: 71725F747005099FD705EF64E4A5AFE7BF6FB88640F158129E506AB398DF34AD02CBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c192ebc0d965116608c936e2aa87df7795257d0f51b4ba1b10f26c279d46f825
                        • Instruction ID: 6fa09c931901f3496a0ea92c9da3574df05e6805e5e4960e3468888e6a4f6359
                        • Opcode Fuzzy Hash: c192ebc0d965116608c936e2aa87df7795257d0f51b4ba1b10f26c279d46f825
                        • Instruction Fuzzy Hash: 0D524D74B0061ACFDB14EF64D9A4AADB7B2FF89244F4045A9D50AA73A4DF30AD45CF80
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 0e3a524f464f3e376f2c6d106b9630d5094edcd7de656696acbd73f807c97d82
                        • Instruction ID: df5cf08de0677330003167fdd0545cb6643ce5622f0472e770b68897d7d74764
                        • Opcode Fuzzy Hash: 0e3a524f464f3e376f2c6d106b9630d5094edcd7de656696acbd73f807c97d82
                        • Instruction Fuzzy Hash: E7524D74B0061ACFDB14FF64E9A4AAD77B2FB89244F5045A9D40AA73A4DF30AD45CF80
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a19515462c02da1ab0a07e10ebc2cd095f9b1457c279a930381b76135efc953d
                        • Instruction ID: c3e6816005bf6af526727cff8b4a3459279a54db5f251752cad96a5e1e47c5d4
                        • Opcode Fuzzy Hash: a19515462c02da1ab0a07e10ebc2cd095f9b1457c279a930381b76135efc953d
                        • Instruction Fuzzy Hash: 06423C74B1061ACFDB14EF64D9A4AADB7B2FF89244F4045A9D40AA73A4DF30AD45CF80
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4b96cdf3c0f6670e60fb58cb1b5f37321111600788a7d24444c294a7002f7720
                        • Instruction ID: bd0dd118b8b9b402fe09d87d64e62d03b2f1229c24abc409dec8f87ddce80cc1
                        • Opcode Fuzzy Hash: 4b96cdf3c0f6670e60fb58cb1b5f37321111600788a7d24444c294a7002f7720
                        • Instruction Fuzzy Hash: 41423C74B0061ACFDB14FF64E9A4AAD77B2FB89244F5045A9D40AA73A4DF30AD45CF80
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 6a0ce665d1714a8665db4cfcd2dc7670535ee744bcb478f0b9164354c60b60ae
                        • Instruction ID: ac291e831b1fa3f0946eb294413c3a28c7510765b68e2f09a9721b5c1e97b9cb
                        • Opcode Fuzzy Hash: 6a0ce665d1714a8665db4cfcd2dc7670535ee744bcb478f0b9164354c60b60ae
                        • Instruction Fuzzy Hash: E8422274710609DFDB05EF64E8A5AAE77B3FB88340F149569E8069B398DF30AC41CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4cd20be5f4763be2c29dcde1c592b6dec31586f28e852de342dea832bb0d1a15
                        • Instruction ID: 4ddf70c9406fa336e78f0a5dbdd0cb656aec94867b06dc567a888782e78102c9
                        • Opcode Fuzzy Hash: 4cd20be5f4763be2c29dcde1c592b6dec31586f28e852de342dea832bb0d1a15
                        • Instruction Fuzzy Hash: 73028D70B012168FDB09CFA8C4A5A7FFBB2FB88310F108629D9569B345CB34A841CBD1
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 573b3795db8ec902a465024490ee2ba52d91e98fa16905af8b6401adf4c2ed0e
                        • Instruction ID: 652cd3275223a94a0aff273867792142222544d91d10fa9a1146fad80afa6c0e
                        • Opcode Fuzzy Hash: 573b3795db8ec902a465024490ee2ba52d91e98fa16905af8b6401adf4c2ed0e
                        • Instruction Fuzzy Hash: 84F1DE74B1061A9FDB05EFA4E9A4DAEB7B3FF89244F108119E805A7398DF71AC41CB50
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c670cf94f79052011ec3f9ebe70f7b0361018423fe805b15ce861e0437ca4563
                        • Instruction ID: 4a72a0d02b13013afd823c3fc5eba5fa0a4889b944d49d12b16d44494e5bf03b
                        • Opcode Fuzzy Hash: c670cf94f79052011ec3f9ebe70f7b0361018423fe805b15ce861e0437ca4563
                        • Instruction Fuzzy Hash: 3DF13B38B015198FDB05DFA8D598AAEBBF2FB88700F55D059E406AB385CF34DC428B90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 47b5ad4d76cef2c281afefbfb716ff4ad1ae1de26d99edc3c333c5203407245f
                        • Instruction ID: c6e819175faf744381235dc310ee6a115ae08258bb4055d5f76bf0d5adf2425d
                        • Opcode Fuzzy Hash: 47b5ad4d76cef2c281afefbfb716ff4ad1ae1de26d99edc3c333c5203407245f
                        • Instruction Fuzzy Hash: 61D1ED74B1051A9FDB04EBA4E9A4DAEB7B7FFC9254F108119E805A7398DF31AC41CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 00355a65d6ad7b936f9855cf6c669e088e9c1b7fc5a83809efa27e7a1259de12
                        • Instruction ID: a4843fdfe7a2e7553c3b6b681f7bcae9b7b0fa2543d22d4fae3609ea9229ef8a
                        • Opcode Fuzzy Hash: 00355a65d6ad7b936f9855cf6c669e088e9c1b7fc5a83809efa27e7a1259de12
                        • Instruction Fuzzy Hash: 94D1ED74B1061ADFDB04EBA4E9A4DAE77B7FF89254F108119E805A7398DF30AC41CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562697410.0000000005550000.00000040.00000800.00020000.00000000.sdmp, Offset: 05550000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5550000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a8de975451979101aa9e12e861f599266c67618f4ecb17c7280e12da58e0f6fc
                        • Instruction ID: b87f15ed8f1aa5dc1e8e4f4f981ea02f2ecbdc376983063f1c5ccf2613b1f946
                        • Opcode Fuzzy Hash: a8de975451979101aa9e12e861f599266c67618f4ecb17c7280e12da58e0f6fc
                        • Instruction Fuzzy Hash: 25D1DE74B1051ADFDB04EBA4E9A49AEB7B3FFC9254F108119E805A7398DF71AC41CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562535600.0000000005500000.00000040.00000800.00020000.00000000.sdmp, Offset: 05500000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5500000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c777b710cdc5536de40f3eb2f5487de8edf3030a6d6baa0a941db2aaf7ccf72a
                        • Instruction ID: 30a01bb166e80da446575e4305c5065a71fedab0e1e03e5e6a198a2abcf116e6
                        • Opcode Fuzzy Hash: c777b710cdc5536de40f3eb2f5487de8edf3030a6d6baa0a941db2aaf7ccf72a
                        • Instruction Fuzzy Hash: B4D1827070050A9FDB15EF24E4A5AEE77A2FF88344F559629E8069B394DF30ED42CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: fb80a15f76721d87e12d5a4bf7e3e700055bf077ea524bff111c19b80b2a7b73
                        • Instruction ID: 6055b08300ffcbfe076ac2b6821c39e61d380e430ad5b8fac764d7afc3603616
                        • Opcode Fuzzy Hash: fb80a15f76721d87e12d5a4bf7e3e700055bf077ea524bff111c19b80b2a7b73
                        • Instruction Fuzzy Hash: F0D15174B0021A8FD744EF28E5A4AAF77F2FB88740F1585B9940A9B754DF30AD42CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 40ca00ed75a5164f6d6180352162ca99dd8a79f9f432e63e916e82003a4e75cc
                        • Instruction ID: 6afc67c5d21de871f63d361f0df47e833ce0919e88b4d7c5199ea17ca03d3b31
                        • Opcode Fuzzy Hash: 40ca00ed75a5164f6d6180352162ca99dd8a79f9f432e63e916e82003a4e75cc
                        • Instruction Fuzzy Hash: 24D14174B0021A8FD744EF28E5A4AAE77F2FB88740F1585B9940A9B754DF30ED41CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a46501aabe3e54b60ca8e5a48999fcb22b992f746d3fc8241b0c99727567c724
                        • Instruction ID: ab8d41b3206505cbe2519fbe10c836a934c2a7bc1b65ee87c08be929834bbf06
                        • Opcode Fuzzy Hash: a46501aabe3e54b60ca8e5a48999fcb22b992f746d3fc8241b0c99727567c724
                        • Instruction Fuzzy Hash: EAB15971E005299FDB18CBA9C980AEEFBF1BB49300F54866AD455E7305D770ED46CBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562595484.0000000005520000.00000040.00000800.00020000.00000000.sdmp, Offset: 05520000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_5520000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 5e9b5c7effe923d5335a07bd2480d80c438ed578cb9adc44fadc2345ecb1654a
                        • Instruction ID: f03eebdb15feb0d6c0749353fe66ce7ac02a289c8ed2ddd9078e0e85feef2094
                        • Opcode Fuzzy Hash: 5e9b5c7effe923d5335a07bd2480d80c438ed578cb9adc44fadc2345ecb1654a
                        • Instruction Fuzzy Hash: 03A1407470160A9FDB05FB25E8A5A7E37B2FFC9250F508529E9055B3A8DF30AD11CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 2e01883d4347faa48a0a9656d8bb804fb5062bc9ed8cc54419d3565680b7423c
                        • Instruction ID: a047a69e8defaecbbd41dbd0de16358430835e343392ee0cf7483d7a4900982b
                        • Opcode Fuzzy Hash: 2e01883d4347faa48a0a9656d8bb804fb5062bc9ed8cc54419d3565680b7423c
                        • Instruction Fuzzy Hash: 45B18D71E0052A8FCF19CBA8C9806ADFBF1FB49304F288669D465E7606D334ED52CB94
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 05617124c204a3e9cf32a1e2d9acaaa6d05e929bbdd3147a6d2099c357cf33b6
                        • Instruction ID: 75f43b0f84b8b5ffb33a471dd41e5be64d6fcb94e0733194c3be04879792cffc
                        • Opcode Fuzzy Hash: 05617124c204a3e9cf32a1e2d9acaaa6d05e929bbdd3147a6d2099c357cf33b6
                        • Instruction Fuzzy Hash: 11A1B031E012298FCF09CFB8C9802ADBBF1FF49314B188269D465EB606E3349947CB90
                        Memory Dump Source
                        • Source File: 00000000.00000002.4563382084.0000000006950000.00000040.00000800.00020000.00000000.sdmp, Offset: 06950000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_6950000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: af60b7e7c24a5722ed753e41d0f56229a41c78f425e04b9698417a0aff0b43b9
                        • Instruction ID: 8e84a032ed820a7965d3371f55b9ff01538a5728df4a68230bdbc58a7f51af9e
                        • Opcode Fuzzy Hash: af60b7e7c24a5722ed753e41d0f56229a41c78f425e04b9698417a0aff0b43b9
                        • Instruction Fuzzy Hash: 4DB15F74B4021A8FD744EF28D5A8AAE77E2FB88740F1585B9940ADB744DF30AD42CB91
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3039982b44de1be31b7ebeb39a7fabfa9b737f7d23026dd2b4e04394755a7f30
                        • Instruction ID: 71118e9df8387dac6ad0de8fc11e43e1d9a1cea6df73bdd0986156c23924ea90
                        • Opcode Fuzzy Hash: 3039982b44de1be31b7ebeb39a7fabfa9b737f7d23026dd2b4e04394755a7f30
                        • Instruction Fuzzy Hash: 2781FE7A8623559FC74A8FB4C88109037A0FF17A2D32815EDD8A5CF062E277694BCB52
                        Memory Dump Source
                        • Source File: 00000000.00000002.4562385178.00000000054B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 054B0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_54b0000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9d0c774367dc903c9cf33ca1a77f5b3aad885bf4e941f382acdbd2c22afaa04f
                        • Instruction ID: b70521c31fad8470410bdd1d879970e3fe3f7b49d739cd963c9e784577710495
                        • Opcode Fuzzy Hash: 9d0c774367dc903c9cf33ca1a77f5b3aad885bf4e941f382acdbd2c22afaa04f
                        • Instruction Fuzzy Hash: BE713D71E005298FDB18CFA9C8806EEF7F1BB88310F54866AD415E7345D774E946CBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 886ae19792fb21ac9656c2de60322b837026e6bba1c22b6af0b32ee46ecb9823
                        • Instruction ID: a1e3a271483ebd69b348b92d6d79d4797044d35388a6fdd03b624c10dc9ddc44
                        • Opcode Fuzzy Hash: 886ae19792fb21ac9656c2de60322b837026e6bba1c22b6af0b32ee46ecb9823
                        • Instruction Fuzzy Hash: B2613171A0064A8FD71AEF7EE4906DABBE3BFC8300F14D13AC145DB26AEB7559058B50
                        Memory Dump Source
                        • Source File: 00000000.00000002.4558760738.0000000001190000.00000040.00000800.00020000.00000000.sdmp, Offset: 01190000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_1190000_LZUCldA1ro.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 24ce5196d4be36dce835afeb54155106b7f41bd4d4133fc0fc1deaf726a7c45c
                        • Instruction ID: 97c38d3eb796fd746b9043b50dc2013e9e9f8525b554c975347b23783578f52a
                        • Opcode Fuzzy Hash: 24ce5196d4be36dce835afeb54155106b7f41bd4d4133fc0fc1deaf726a7c45c
                        • Instruction Fuzzy Hash: 20513070A0064A8FD71AEF7EE4906DABBE3BFC8200F14D12AC145DB26AEF7559058B50